Why you need penetration testing

  • Identifying weak points
    • You’ll find out about vulnerabilities before an attacker exploits them.
  • Compliance with NIS2 and the Cybersecurity Act
    • Penetration testing is one of the key measures required of companies by regulation.
  • Protecting your customer’s data
    • You’ll prevent data leaks, fines, and reputational damage.
  • A basis for decision-making
    • A clear report with risk prioritization, not just a technical listing.

Cyber attacks have increased by 50%.

What is a penetration test

The goal of an automated penetration test is to verify the effectiveness and resilience of the security mechanisms that protect your data, systems, and services against unauthorized access, misuse, or damage.

We don’t just look for theoretical weaknesses – we try to actually exploit them, to find out how easy (or difficult) it would be for an attacker to break through your defenses.

After the test, you’ll know the answers to the key questions:

  • Where are your system’s weak points?
  • How likely are they to be exploited?
  • What risk do they pose to you?
  • How can the risk be reduced or eliminated?

We test both manually and in an automated way – also with the help of AI

01
02

01

Automated testing

Fast, repeatable scanning of large-scale infrastructure using state-of-the-art tools enhanced with AI, which helps evaluate and prioritize discovered vulnerabilities more quickly.

02

Manual testing by specialists

Certified ethical hackers simulate a real attack, verify findings, and uncover vulnerabilities that automated tools and AI alone would miss.

Internal vs. external testing

Both tests examine a different attack scenario. The external test simulates an attacker without access from outside, while the internal test shows what an attacker could achieve if already inside the network. For a comprehensive overview of your security, we recommend combining both tests. Choosing only one on its own makes sense only if you’re interested in a specific scenario (e.g. just resilience against attacks from outside).

Internal test

Simulates an attack carried out from inside the company network, for example from an employee’s computer or a device connected to the internal or guest Wi-Fi.

External test

Simulates an attacker from the internet, without access to your internal network.

How much do we know about you in advance?

Depending on how much information we give the tester in advance, we choose the approach that best matches what you want to find out – from a realistic simulation of an unknown attacker to an in-depth review with full knowledge of the system.

Black-box

We test blind, without any prior information. We simulate the perspective of an outside attacker.

Grey-box

We have access to the information that a user in the tested role (e.g. an employee) would normally have. We simulate an insider threat.

White-box

We have maximum information about the system (topology, configuration, HW/SW). We can focus fully on finding vulnerabilities instead of spending time gathering information.

What we test

Network and infrastructure

Wi-Fi and network elements (firewall, router…)
Endpoint devices (desktop, mobile)
Server infrastructure
Active Directory (Domain controllers, GPO, users)

Applications

Web applications
Mobile applications
Thick client
(desktop applications)

We combine AI tools for rapid scanning with manual verification by certified specialists.

How the test works (6 phases)

Automation with AI – set up once, then runs 24/7

For automated testing we use Pentera, among other tools.

01

Scope definition

Manually by a specialist

We define the scope and goals of the testing – done once, manually.

02

AI-assisted scanning

Automated / AI

Automated scanning of the infrastructure and services using Pentera and AI.

03

AI-assisted prioritization of findings

Automated / AI

AI evaluates the vulnerabilities found and ranks them by severity and risk.

04

AI-assisted verification of findings

Automated / AI

Automated verification that the vulnerabilities found are genuinely exploitable.

05

AI-assisted report / dashboard

Automated / AI

A clear report and dashboard of findings generated with AI.

06

Continuous re-scan

Automated / AI

Continuous automated re-scanning of the infrastructure 24/7.

Continuous cycle

Automated/AI
Manually by a specialist

Automated with AI and Pentera – set up once, then runs 24/7

A specialist performs all 6 phases manually

01

Planning and scope

Manually by a specialist

We define the test scope, goals, and rules of engagement.

02

Reconnaissance and information gathering

Manually by a specialist

We manually map the available systems, services, and information about the target.

03

Manual vulnerability identification

Manually by a specialist

A specialist manually looks for weak points and misconfigurations.

04

Exploitation / penetration testing

Manually by a specialist

We attempt to actually exploit the vulnerabilities found, just as an attacker would.

05

Post-exploitation and privilege escalation

Manually by a specialist

We verify how far an attacker would get and what they could obtain.

06

Final report

Manually by a specialist

We summarize the findings, rate the risks, and propose concrete measures.

Iteration / re-test

Manually by a specialist

Methodology based on OWASP / OSSTMM

What affects the scope and price of the test

  • Scope of the tested system (number of IP addresses, applications, devices)
  • Amount of information available to us in advance (Black/Grey/White-box)
  • Whether the test takes place in a production or test environment
  • Scope and depth of the final report

Send us a few basic details about your infrastructure and we’ll prepare a non-binding quote within a few business days.

Request a penetration test with no obligation

The cost of the test is just a fraction of the possible damage

The price of the test with us starts at 100,000 CZK and increases according to the scope of the test and the size of the company

The possible damage from an attack is usually 6× to 60× higher

6 mil. CZK
4 mil. CZK
2 mil. CZK
0 CZK
600,000 CZK

Lower damage
(for half of companies)

3 mil. CZK

Medium damage
(for a quarter of companies)

6 mil. CZK

High damage
(for 3 % of companies)

Price of the penetration test
Damage from an attack (by severity)

The damage after an attack is usually many times higher than the price of a penetration test.

What you will receive

Final report

At the end of the penetration testing, you will receive a clear report that includes:

01
Summary
A clear overview of risks without technical jargon, suitable for presenting to management or an auditor.
02
Technical section for the IT team
A detailed description of the vulnerabilities found, how they can be exploited, and recommended remediation.
03
Risk prioritization
What to fix immediately and what can wait.

Automated network monitoring –
detect weaknesses before an attacker does.



Methodology and tools

We test according to our own methodology based on the recognized OWASP and OSSTMM standards, supplemented with current practices for testing APIs and cloud environments.

We use a combination of automated tools (Nessus, OpenVAS, Nmap…) and specialized techniques (Burp Suite, Metasploit, sqlmap, and others), depending on which technologies you actually use in your infrastructure.

OWASP
OSSTMM

Most common website vulnerabilities

Broken access control
20.15 %
Insecure design
11.33 %
Security misconfiguration
3 %

Share of tested applications with the given vulnerability (%) · OWASP Top 10:2025

Why XEVOS

01
OWASP & OSSTMM
We follow internationally recognized methodologies, which make the test thorough, consistent, and comparable with industry practice.
02
Certified specialists
Our team consists of experts with internationally recognized certifications in penetration testing.
03
Cyber security
We operate our own Cyber Security Center (SOC), which continuously monitors threats and responds to security incidents.
04
A reliable partner
Years of experience, certified specialists, and references across industries. We work with our clients long-term, not just on a one-off test.

FAQ

Will the test affect our company’s operations?

Testing is generally carried out in a way that doesn’t disrupt normal business operations, and we consult on any risky steps in advance. If needed, the test can be scheduled outside business hours or during less busy periods.

How long does a penetration test take?

The duration depends on the scope of the system being tested, typically ranging from a few days to two weeks. You’ll receive a precise estimate after the initial consultation and scope definition.

How often should we repeat the test?

We recommend repeating the test at least once a year or after any significant change to the system (a new release, infrastructure change). For critical systems or per regulatory requirements, a higher frequency may be appropriate.

What happens if you find a critical vulnerability right at the start?

In that case, we notify you immediately, even before the entire test is completed, to ensure a fast response. You don’t have to wait for the final report if there’s an immediate risk.

Is a penetration test mandatory under NIS2?

NIS2 doesn’t directly require a penetration test as a specific obligation, but it does require companies to ensure an adequate level of cybersecurity and risk management. A penetration test is one of the most effective tools for fulfilling and demonstrating that obligation.

What’s the difference between a penetration test and a security audit?

A penetration test actively simulates an attack to verify whether and how vulnerabilities can actually be exploited. A security audit, on the other hand, evaluates processes, policies, and compliance with norms or standards, without an actual attempt to breach the system.

Fill in the form

We'll prepare a no-obligation quote for you

    By submitting this form you acknowledge that XEVOS Solutions s.r.o. will process your personal data for the purpose of handling your enquiry. More in the Privacy Policy.