Engagements are scoped to what actually matters for your business — you don’t need all six, and we’ll help you figure out where the real risk is before quoting anything.
🌐
External
Testing what the internet can see and reach: your firewall edge, exposed services, VPN, and internet-facing servers. This is usually the first engagement for a business that’s never been tested — it answers "what could a stranger on the internet actually get to?"
🖥️
Web Application
Your website or web app: login flows, forms, file uploads, session handling, and the logic behind them. This is where customer data and payment flows usually live, so it's a common starting point for businesses that take orders or store accounts online.
🏢
Internal
What happens if a laptop, an email account, or a single workstation is already compromised — how far could an attacker move inside your network from there? Internal testing checks lateral movement, shared drives, and internal privilege boundaries.
📶
Wireless
Your Wi-Fi posture: encryption strength, guest-network isolation, rogue access points, and whether a device in the parking lot could reach your internal network. A weak Wi-Fi setup is one of the most common ways an "external" attacker becomes an "internal" one.
📧
Phishing Simulation
Authorized staff-awareness testing — carefully controlled simulated phishing emails sent to your team with your sign-off, measuring who clicks and who reports it. The goal is a training opportunity, not a gotcha; results are used to improve awareness, not to punish anyone.
🎥
Camera / IoT
Review of cameras, smart devices, and other internet-connected hardware for default credentials, exposed management ports, and firmware that's fallen out of date — the same class of device many small businesses never think to test.