Penetration Testing
We’ll test your IT infrastructure the way a real attacker would – before they get the chance.
A penetration test uncovers weak points in your network, applications, and staff before someone else finds them. We’ll identify where you’re vulnerable, how easily security mechanisms can be bypassed, and what risk that represents for you – along with concrete recommendations for eliminating it.
Cyber attack attempts per week on an organization
1,984
Cyber incidents in the Czech Republic
268
Time to detect a data breach
241 days
Why you need penetration testing
- Identifying weak points
- You’ll find out about vulnerabilities before an attacker exploits them.
- Compliance with NIS2 and the Cybersecurity Act
- Penetration testing is one of the key measures required of companies by regulation.
- Protecting your customer’s data
- You’ll prevent data leaks, fines, and reputational damage.
- A basis for decision-making
- A clear report with risk prioritization, not just a technical listing.
What is a penetration test
The goal of an automated penetration test is to verify the effectiveness and resilience of the security mechanisms that protect your data, systems, and services against unauthorized access, misuse, or damage.
We don’t just look for theoretical weaknesses – we try to actually exploit them, to find out how easy (or difficult) it would be for an attacker to break through your defenses.
After the test, you’ll know the answers to the key questions:
- Where are your system’s weak points?
- How likely are they to be exploited?
- What risk do they pose to you?
- How can the risk be reduced or eliminated?
We test both manually and in an automated way – also with the help of AI
01
02
01
Automated testing
Fast, repeatable scanning of large-scale infrastructure using state-of-the-art tools enhanced with AI, which helps evaluate and prioritize discovered vulnerabilities more quickly.
02
Manual testing by specialists
Certified ethical hackers simulate a real attack, verify findings, and uncover vulnerabilities that automated tools and AI alone would miss.
Internal vs. external testing
Both tests examine a different attack scenario. The external test simulates an attacker without access from outside, while the internal test shows what an attacker could achieve if already inside the network. For a comprehensive overview of your security, we recommend combining both tests. Choosing only one on its own makes sense only if you’re interested in a specific scenario (e.g. just resilience against attacks from outside).
Internal test
Simulates an attack carried out from inside the company network, for example from an employee’s computer or a device connected to the internal or guest Wi-Fi.
External test
Simulates an attacker from the internet, without access to your internal network.
How much do we know about you in advance?
Depending on how much information we give the tester in advance, we choose the approach that best matches what you want to find out – from a realistic simulation of an unknown attacker to an in-depth review with full knowledge of the system.
Black-box
We test blind, without any prior information. We simulate the perspective of an outside attacker.
Grey-box
We have access to the information that a user in the tested role (e.g. an employee) would normally have. We simulate an insider threat.
White-box
We have maximum information about the system (topology, configuration, HW/SW). We can focus fully on finding vulnerabilities instead of spending time gathering information.
What we test
Network and infrastructure
Applications
We combine AI tools for rapid scanning with manual verification by certified specialists.
How the test works (6 phases)
Automation with AI – set up once, then runs 24/7
For automated testing we use Pentera, among other tools.
01
Scope definition
Manually by a specialistWe define the scope and goals of the testing – done once, manually.
02
AI-assisted scanning
Automated / AIAutomated scanning of the infrastructure and services using Pentera and AI.
03
AI-assisted prioritization of findings
Automated / AIAI evaluates the vulnerabilities found and ranks them by severity and risk.
04
AI-assisted verification of findings
Automated / AIAutomated verification that the vulnerabilities found are genuinely exploitable.
05
AI-assisted report / dashboard
Automated / AIA clear report and dashboard of findings generated with AI.
06
Continuous re-scan
Automated / AIContinuous automated re-scanning of the infrastructure 24/7.
Continuous cycle
Automated with AI and Pentera – set up once, then runs 24/7
A specialist performs all 6 phases manually
01
Planning and scope
Manually by a specialistWe define the test scope, goals, and rules of engagement.
02
Reconnaissance and information gathering
Manually by a specialistWe manually map the available systems, services, and information about the target.
03
Manual vulnerability identification
Manually by a specialistA specialist manually looks for weak points and misconfigurations.
04
Exploitation / penetration testing
Manually by a specialistWe attempt to actually exploit the vulnerabilities found, just as an attacker would.
05
Post-exploitation and privilege escalation
Manually by a specialistWe verify how far an attacker would get and what they could obtain.
06
Final report
Manually by a specialistWe summarize the findings, rate the risks, and propose concrete measures.
Iteration / re-test
Methodology based on OWASP / OSSTMM
What affects the scope and price of the test
- Scope of the tested system (number of IP addresses, applications, devices)
- Amount of information available to us in advance (Black/Grey/White-box)
- Whether the test takes place in a production or test environment
- Scope and depth of the final report
Send us a few basic details about your infrastructure and we’ll prepare a non-binding quote within a few business days.
The cost of the test is just a fraction of the possible damage
The price of the test with us starts at 100,000 CZK and increases according to the scope of the test and the size of the company
The possible damage from an attack is usually 6× to 60× higher
The damage after an attack is usually many times higher than the price of a penetration test.
What you will receive
Final report
At the end of the penetration testing, you will receive a clear report that includes:
Methodology and tools
We test according to our own methodology based on the recognized OWASP and OSSTMM standards, supplemented with current practices for testing APIs and cloud environments.
We use a combination of automated tools (Nessus, OpenVAS, Nmap…) and specialized techniques (Burp Suite, Metasploit, sqlmap, and others), depending on which technologies you actually use in your infrastructure.
OSSTMM
Most common website vulnerabilities
Share of tested applications with the given vulnerability (%) · OWASP Top 10:2025
Why XEVOS
FAQ
Will the test affect our company’s operations?
Testing is generally carried out in a way that doesn’t disrupt normal business operations, and we consult on any risky steps in advance. If needed, the test can be scheduled outside business hours or during less busy periods.
How long does a penetration test take?
The duration depends on the scope of the system being tested, typically ranging from a few days to two weeks. You’ll receive a precise estimate after the initial consultation and scope definition.
How often should we repeat the test?
We recommend repeating the test at least once a year or after any significant change to the system (a new release, infrastructure change). For critical systems or per regulatory requirements, a higher frequency may be appropriate.
What happens if you find a critical vulnerability right at the start?
In that case, we notify you immediately, even before the entire test is completed, to ensure a fast response. You don’t have to wait for the final report if there’s an immediate risk.
Is a penetration test mandatory under NIS2?
NIS2 doesn’t directly require a penetration test as a specific obligation, but it does require companies to ensure an adequate level of cybersecurity and risk management. A penetration test is one of the most effective tools for fulfilling and demonstrating that obligation.
What’s the difference between a penetration test and a security audit?
A penetration test actively simulates an attack to verify whether and how vulnerabilities can actually be exploited. A security audit, on the other hand, evaluates processes, policies, and compliance with norms or standards, without an actual attempt to breach the system.