Penetration testing

Penetration testing

A penetration test simulates a real-world cyberattack to identify security vulnerabilities before attackers can exploit them. Our certified ethical hackers test web applications, APIs, mobile applications, cloud environments, AI systems, and network infrastructure under realistic attack conditions.

Using the same techniques as real-world attackers, we uncover security risks and provide clear, actionable recommendations to help you remediate them.

Request a Penetration Test

Penetration testing

We are trusted by Fortune 500 companies worldwide

kpmg
erste
csob
dell
ing
jablotron
doxx bet
fortuna
kb
eon
kpmg
erste
csob
dell
ing
jablotron
doxx bet
fortuna
kb
eon
kpmg
erste
csob
dell
ing
jablotron
doxx bet
fortuna
kb
eon
kpmg
erste
csob
dell
ing
jablotron
doxx bet
fortuna
kb
eon

What is penetration testing

Penetration testing is a controlled simulation of a real cyber attack. Our team of highly skilled ethical hackers will test your cyber security. They behave like real attackers in your systems and search for vulnerabilities in your infrastructure, web and mobile applications, or even the cloud. Penetration tests are usually performed manually by our experts using tools and techniques used by real attackers. To enhance efficiency and broaden test coverage, we use our own AI-powered tools during the reconnaissance and analysis phases. However, the final assessment and validation are always performed by an experienced ethical hacker.

This process provides you with key information about security gaps and helps you prepare for real attacks and minimise risks. Penetration tests enable organisations to strengthen their cyber defences and protect their data, customers and reputation.

However, our goal is not to cause damage, but to uncover risks and weaknesses that could be exploited by a real attacker. Penetration tests not only identify vulnerabilities in a company's IT, but also demonstrate how they could be exploited in practice. They include attempts to gain access to company systems, escalate privileges, or exfiltrate data.

A real hacker attack can lead to data loss, disruption of operations, leakage of confidential information or damage to reputation.

Investing in regular penetration testing is a key step in ensuring the security and trustworthiness of your organisation.

What You Gain from a Penetration Test

Identify Vulnerabilities and Assess Risks

A penetration test provides a detailed assessment of vulnerabilities across your applications, infrastructure, and cloud environments. You gain a clear understanding of which weaknesses attackers could exploit and the level of risk they pose to your organization.

Strengthen the Security of Data and Systems

Every finding includes practical remediation recommendations. This enables you to improve your cybersecurity posture, reduce the risk of security incidents, and better protect sensitive data, business systems, and customer information.

Support Risk Management and Compliance

Penetration testing provides valuable input for cyber risk management and helps meet the requirements of regulations and standards such as NIS2, DORA, ISO/IEC 27001, PCI DSS, and GDPR. Each report includes both technical findings and a management summary.

Understand How Attackers Exploit Weaknesses

We deliver more than a list of vulnerabilities. Our experts demonstrate how attackers could exploit each weakness, explain its potential business impact, and provide clear recommendations to reduce the associated security risks.

Penetration Testing vs. Automated Vulnerability Scanning

Automated vulnerability scanning and penetration testing complement each other. Each approach has its place in the cybersecurity risk management process.

Automated vulnerability scanning can regularly identify known vulnerabilities, missing updates, or misconfigurations across large environments. It is suitable for continuously monitoring an organization’s security posture.

Penetration testing goes a step further. Experienced ethical hackers manually verify whether identified vulnerabilities can actually be exploited, assess the potential impact of a successful attack, and uncover logic flaws or complex attack scenarios that automated tools may not detect.

When Should You Choose Penetration Testing?

If you need to determine whether specific vulnerabilities can actually be exploited and what impact a successful attack could have on your systems or data, penetration testing provides significantly deeper insight than automated scanning alone.

Automated Vulnerability Scanning Penetration Testing
Automatically identifies known vulnerabilities. Manually verifies whether they can actually be exploited.
Suitable for regular monitoring of the environment. Simulates real-world attack scenarios.
Quickly analyzes a large number of systems. Provides an in-depth analysis of a selected application or infrastructure.
May produce false positives that need to be verified. Every finding is manually verified by an ethical hacker.
Provides an overview of identified vulnerabilities. Provides evidence of exploitability and recommendations for remediation.

What You Receive After a Penetration Test

Penetration testing does not end with the identification of vulnerabilities. Once the test is complete, you receive all the information you need to understand the identified risks, prioritize remediation, and implement effective security measures. Our experts help you interpret the results, recommend the most appropriate remediation measures, and support you in reducing cybersecurity risks and meeting regulatory requirements such as NIS2 and DORA.

01

Technical Report

After the penetration test, you receive a detailed report containing all identified vulnerabilities, their severity, evidence of exploitability (Proof of Concept), and specific recommendations for remediation. Every finding is manually verified by our ethical hackers and accompanied by recommended steps to minimize the risk.

02

Executive Summary

The report also includes an executive summary prepared for company management. It provides an overview of the most significant risks, their potential impact on the organization, and recommended remediation priorities. The summary supports decision-making, risk management, and communication of the results during internal or external audits.

03

Results Consultation

We review the penetration testing results with you during a dedicated consultation. We explain each finding in detail, how it could potentially be exploited, and its impact on your environment. We answer your questions and recommend the most appropriate approach to implementing the proposed security measures.

04

ReTest

Penetration testing should not end once the identified vulnerabilities have been remediated. That is why we recommend a ReTest to every client. We verify that all identified vulnerabilities have been properly fixed and can no longer be exploited. This gives you confidence that the implemented security measures are effective and that your environment is better prepared to withstand real-world attacks.

Penetration testing has been our core expertise for more than 14 years. Our team of 47 certified security experts holds internationally recognized certifications, including OSCP, OSEP, OSWE, CRTO, PNPT, CISSP, and many others. Every year, we perform more than 600 penetration tests for organizations of all sizes. In 2025 alone, we identified 3,293+ vulnerabilities as part of penetration tests for clients. We discovered 20+ CVEs, actively contributing to the global cybersecurity community.

We work with Fortune 500 companies as well as organizations in banking, finance, automotive, telecommunications, media, the public sector, crypto, energy, and many other industries. We test web applications, APIs, mobile applications, cloud environments, internal infrastructure, and AI systems using internationally recognized methodologies. Every finding is manually verified by experienced ethical hackers.

Our recommendations are based on real-world penetration testing experience, not theory. Every year, we analyze the results of hundreds of security assessments and publish our findings in the Ethical Hacking Report, providing practical insights into the latest vulnerabilities, attack trends, and cybersecurity risks.

Our Certifications

OSCP  Professional certification in offensive security
OSWE  Advanced certification for web application security testing
OSEP  Advanced certification  for experienced penetration testers
OSED Advanced certification for security exploit development
OSCE³ Highest OffSec certification in offensive security
CISSP  Globally recognized certification for security professionals
OSCP+  Renewable three-year version of the OSCP certification
ISA/IEC  Advanced certification for industrial cybersecurity professionals specializing in OT/ICS systems
CEH  Certification covering key techniques in ethical hacking
BSCP Official certification proving expertise in web security
Certified Red Team Operator (CRTO)
Certified Red Team Expert (CRTE)
 Certified by Altered Security Red Team Professional for Azure (CARTP)
Offensive AWS Security Professional
Certified Penetration Testing Specialist (CPTS)
AWS Certified Security – Specialty
Advanced Infrastructure Hacking badge
OSCP  Professional certification in offensive security
OSWE  Advanced certification for web application security testing
OSEP  Advanced certification  for experienced penetration testers
OSED Advanced certification for security exploit development
OSCE³ Highest OffSec certification in offensive security
CISSP  Globally recognized certification for security professionals
OSCP+  Renewable three-year version of the OSCP certification
ISA/IEC  Advanced certification for industrial cybersecurity professionals specializing in OT/ICS systems
CEH  Certification covering key techniques in ethical hacking
BSCP Official certification proving expertise in web security
Certified Red Team Operator (CRTO)
Certified Red Team Expert (CRTE)
 Certified by Altered Security Red Team Professional for Azure (CARTP)
Offensive AWS Security Professional
Certified Penetration Testing Specialist (CPTS)
AWS Certified Security – Specialty
Advanced Infrastructure Hacking badge

How does penetration testing work?

01

Test planning

Together, we define the objectives, scope, and methodology of the penetration test. We identify the systems to be tested, establish the rules of engagement, and prepare attack scenarios that accurately simulate real-world threats.

02

Information gathering

We collect information about the target environment, applications, infrastructure, and exposed services. This phase helps identify potential attack vectors and prepares realistic penetration testing scenarios.

03

Vulnerability scanning and analysis

Using automated tools and manual analysis, we identify security weaknesses and review system configurations. We verify known vulnerabilities and prepare them for practical validation.

04

Attack Simulation

Our ethical hackers safely exploit identified vulnerabilities using the same techniques as real-world attackers. This validates their actual impact and uncovers risks that automated scanners often miss.

05

Final report

You receive a detailed report describing the identified vulnerabilities, their risk levels, and practical remediation recommendations. It also includes an executive summary to support cyber risk management and compliance with NIS2 and DORA.

Citadelo Company Logo

Are you interested in improving your company’s security?

Book a free 15-minute consultation with us and find out how we can help.

Book now

What Do We Test?

Web Applications

We test web applications against attacks such as SQL Injection, Cross-Site Scripting (XSS), authentication flaws, and privilege escalation. Our web application penetration testing follows the OWASP Web Security Testing Guide and OWASP Top 10, with every finding manually verified.

Learn more

Mobile Applications

Mobile application penetration testing for Android and iOS assesses the security of sensitive data, APIs, server communication, local storage, and the application's resilience against reverse engineering, rooting, jailbreaking, and other attack techniques.

Learn more

AI a LLM systémy

We test the security of AI applications, chatbots, AI agents, and RAG systems. AI penetration testing assesses resilience against prompt injection, jailbreak attacks, sensitive data leakage, model manipulation, and abuse of external tools based on the OWASP Top 10 for LLM Applications.

Learn more

Network Infrastructure and Internal Systems

We simulate attacks against internal and external infrastructure, including firewalls, VPNs, Active Directory, servers, and databases. Network penetration testing assesses network configuration, segmentation, privilege escalation, and an attacker's ability to move laterally across the environment.

Learn more

Cloud Environments

We assess the security of AWS, Microsoft Azure, and Google Cloud Platform (GCP) environments by simulating real-world attacks. Cloud penetration testing covers IAM, cloud storage, Kubernetes, network rules, and exposed services.

Learn more

APIs and Microservices

API and microservices penetration testing assesses the security of REST, GraphQL, and other APIs, including communication between microservices. We test OAuth, JWT, API gateways, authorization, input validation, and API resilience based on the OWASP API Security Top 10.

Learn more

Penetration Testing Tailored to Your Infrastructure

Discuss Your Penetration Testing Scope

Every organization uses different technologies, which is why penetration testing does not have to be limited to web applications, mobile applications, or cloud environments. Our ethical hackers perform pentests tailored to your specific environment, architecture, and organizational goals.

In addition to standard penetration tests, we also test other technologies, including:

  • IoT devices
  • Wi-Fi networks
  • OT/ICS environments
  • Thick Client and desktop applications
  • VPN solutions
  • Specialized industrial systems
  • Other technologies based on individual requirements

Not sure which type of penetration testing is right for you? We will be happy to help you define the optimal testing scope.

Why Is Regular Penetration Testing Important?

Security is not a one-time state. New versions of applications, cloud services, APIs, and network infrastructure can introduce new vulnerabilities. Regular penetration testing helps organizations continuously validate their security posture, reduce cybersecurity risks, and prepare for evolving threats and regulatory requirements.

01

Continuous Security Validation

Cyber threats are constantly evolving, so simply implementing security measures is not enough. Regular penetration testing verifies whether your applications, APIs, infrastructure, and cloud environments can withstand current attack techniques and provides confidence that new changes have not introduced additional security risks.

02

NIS2, DORA and Security Standards

Penetration testing supports cybersecurity risk management and helps organizations meet the requirements of NIS2, DORA, and security standards such as ISO 27001 and PCI DSS. Regular testing provides evidence that security measures are working as intended and delivers valuable documentation for internal and external security audits.

03

Data and Reputation Protection

A successful cyberattack can result in sensitive data leakage, disruption of critical services, financial losses, and damage to an organization’s reputation. Penetration testing helps identify vulnerabilities before they are exploited, reduces the risk of security incidents, and contributes to protecting corporate systems, sensitive data, and customer trust.

04

Secure Technology Adoption

Cloud services, AI applications, APIs, mobile applications, and IoT devices create new business opportunities, but also introduce new security risks. Penetration testing helps identify vulnerabilities and configuration weaknesses before new technologies are deployed into production, reducing the risk of security incidents after their implementation.

05

Better Prioritization

Penetration testing identifies vulnerabilities based on their actual exploitability and potential impact on the organization. This helps security teams distinguish critical risks from less significant findings, prioritize remediation effectively, and focus resources where needed most. The results provide valuable insights for planning future security measures and making informed decisions about cybersecurity investments.

Types of Penetration Testing by Access Level

Not every penetration test is performed the same way. The amount of information available to an ethical hacker before testing begins has a significant impact on the testing methodology, attack scenarios, and the overall scope of the security assessment. Choosing the right type of penetration test depends on your objectives, the required level of coverage, and the complexity of your environment. Our experts will help you select the most appropriate approach for your infrastructure, applications, and security requirements. The results also provide valuable input for cyber risk management and support compliance with regulations and standards such as NIS2, DORA, PCI DSS, and ISO/IEC 27001.

icon

Black Box Testing

The ethical hacker has no prior knowledge of the target system. This approach simulates an external attacker attempting to identify and exploit publicly accessible vulnerabilities.

icon

Gray Box Testing

The tester is provided with limited information or standard user access. This approach simulates attacks by a regular user, business partner, or an attacker with partial access to the environment.

icon

White Box Testing

The tester has access to detailed information such as system architecture, source code, configurations, or user permissions. White Box Penetration Testing provides the most comprehensive security assessment and uncovers vulnerabilities that may remain undetected during an external test.

AI Accelerates Testing. Humans Make the Decisions.

See How We Use AI in Penetration Testing

We use artificial intelligence to accelerate analysis, generate test scenarios, and correlate large volumes of security data. Every finding is manually verified by an experienced ethical hacker.

This allows us to cover a broader testing scope, identify more vulnerabilities, and maintain the high quality and accuracy of every penetration test.

Free Report

More than half of the tested projects contained a critical or high-risk vulnerability

Discover what 628 penetration tests revealed. Download the free Ethical Hacking Report 2025, based on the results of real-world security assessments conducted by Citadelo and the analysis of 3,293 identified vulnerabilities.

Data from 628 real-world penetration tests
Vulnerability trends compared to 2024
Analysis of web applications, infrastructure, cloud, APIs, Red Teaming, and AI
Practical insights and recommendations from Citadelo experts
Download the Free Report

How much does penetration testing cost?

Book a Free Consultation

The cost of a penetration test depends on the project scope, the complexity of your environment, and the chosen testing approach. Basic web application penetration tests start at approximately €800, while comprehensive manual assessments of infrastructure, cloud environments, or Red Teaming engagements can cost €10,000 or more.

We will provide a tailored quote after an initial consultation and an assessment of your requirements.

Citadelo

Experienced Ethical Hackers Behind Every Penetration Test

Our experience comes from hundreds of penetration tests covering web applications, mobile applications, cloud environments, APIs, and AI systems. As a result, we uncover vulnerabilities that automated scanners often fail to detect.

Book a Free Consultation

What Our Clients Say

ComAp_reference

"We started working with Citadelo in 2015. They opened up broad horizons in the field of cybersecurity for us, and we showed them the hidden corners of industrial automation. Since then, we have successfully collaborated on several joint projects, including auditing our devices, which are mostly based on proprietary solutions. The Citadelo team helped us identify a number of specific measures that, even in the often tight conditions of industrial automation, allowed us to elevate the cybersecurity of our products to a new level. Citadelo also taught us to think in a slightly different way than before."

ComAp a.s.

Jan Tomandl | Chief Product Analyst

Dr.Max, a.s.

"At Dr.Max pharmacies, we emphasize professional services in all aspects - whether it’s our brick-and-mortar pharmacies or our website. Penetration tests conducted by Citadelo have helped us set the security level of our online store’s environment to a professional standard. Citadelo responded to all situations flexibly, dynamically, and with a high level of expertise."

Dr.Max, a.s., Slovensko

Slavomír Záborský | Head of IT

Lidl reference

"At Lidl, we take IT security seriously. We believe that it is essential to constantly improve it, which is why we chose Citadelo to test our device and application. We have been very impressed with their work, cooperation, and results."

Lidl a.s.

Petra Zorvanová | ISO & Team Coordinator

realpad_reference

"We appreciate your client-oriented approach, professionalism, excellent communication, and willingness to help."

Realpad, s.r.o.

Matěj Vitásek | Chief Technical Office

Trustpay_reference

"We consider Citadelo to be a trustworthy partner in developing both the process and technical aspects of information security. We appreciate their expertise, professional approach, and the results of their work."

TrustPay a.s.

Ivan Poliačik

unionpoistovna_reference

"The penetration testing report provided us with an objective view of the security of our applications. We were satisfied with the terms and the execution of the service."

Union zdravotná poisťovňa, a. s.

Martin Spišák | Head of IT

logo innovatrivs

"During a major customer engagement, we were required to provide independent proof that our identity verification solution is resilient against injection attacks. We selected Citadelo for their expertise, reputation, and ability to meet the customer's demanding timeline. Their rigorous assessment provided valuable independent validation and reinforced confidence in the robustness of our technology."

Innovatrics, s.r.o.

Viktor Bielko | IDV Toolkit Product Manager

costlocker_reference

"Collaboration with the Citadelo team was extremely smooth. The guys knew exactly what to do, true professionals through and through. If you have an application, e-shop, or any online platform dealing with sensitive data, they are the best you can find."

Costlocker a.s.

Tomáš Wojcik | CEO & Co-founder

Penta_reference

"Our collaboration in the field of information security is long-term. During this period, I have repeatedly been convinced of both their professional and personal qualities."

PENTA INVESTMENTS LIMITED o. z.

Michal Prónay | Head of IT

YOUPLUS

"Citadelo's expertise is backed by the experience we've gained through our joint projects. Their professionalism and flexibility in identifying vulnerabilities within the paperless insurance environment are essential to us. Our mutual trust is built on their strong ethical standards and unwavering reliability in protecting our clients' sensitive data. They are a partner that keeps pace with the realities of today's cyber threats.!

YOUPLUS Životná poisťovňa

Vlastimil Šmihula | CIO

orange_reference

"Choosing Citadelo as a security supplier was absolutely the right choice. Thanks to their expertise, high-quality reports, and excellent communication, we have implemented many important security improvements which have allowed us to take the data security of our company several steps further."

Orange Slovensko a.s.

Henrich Snajder | Information Security Manager

What else do you ask us

Questions we hear most often about penetration testing

Because attackers are already trying. A penetration test shows you which weaknesses in your IT systems hackers could exploit. It gives you a clear list of vulnerabilities, the specific business impact they could cause, and most importantly, a concrete roadmap for fixing them.

It depends on the scope. A simple web application test can be completed in a few days. A full-scale infrastructure assessment may take several weeks. At the very beginning, we provide you with a clear schedule—and we stick to it.

Best practice is at least once a year. In addition, you should repeat the test whenever you deploy a new critical application or make major changes to your IT infrastructure. Regular testing is the only way to be sure new changes haven’t introduced new vulnerabilities.

The report is a practical guide, not shelfware. It includes identified vulnerabilities ranked by risk, descriptions of their impact and possible exploitation paths, as well as our concrete remediation recommendations. There’s also an executive summary in language your management will understand. The exact structure of the report depends on what and how we test. Once we know more about your environment, we can share a sample report so you see exactly what’s included.

Yes. If you are deploying artificial intelligence, large language models (LLMs), or AI agents, we test them with the same level of rigor as your other systems.

We focus on AI-specific vulnerabilities, including:

  • Prompt injection
  • Model and context data leakage
  • Jailbreak attacks and guardrail bypasses
  • Abuse of connected tools and integrations
  • Adversarial attacks

We also help you prepare for compliance with the EU AI Act.

We plan penetration testing to minimize any impact on your organization’s operations. Before testing begins, we agree on the scope, rules of engagement, and suitable testing schedule. For critical systems, we recommend testing outside peak hours or during planned maintenance windows.

We recommend a ReTest to every client. Once the identified vulnerabilities have been remediated, we perform a ReTest to verify that the security issues have been properly fixed and can no longer be exploited. This gives you confidence that the implemented measures are effective.

Automated vulnerability scanning can quickly identify known vulnerabilities across a large environment. Penetration testing goes further. Experienced ethical hackers manually verify whether vulnerabilities can actually be exploited, assess the potential impact of a successful attack, and uncover more complex scenarios that automated tools may not detect. The two services complement each other.

The price depends on the scope of testing, the complexity of the environment, and the type of systems being tested. Simple web application penetration tests start at approximately €800, while extensive infrastructure or cloud environment assessments and Red Teaming projects can cost €10,000 or more. We provide an exact quote after an initial consultation.

We test web applications, mobile applications, APIs, cloud environments, internal and external infrastructure, Wi-Fi networks, AI systems, LLM applications, AI agents, and other technologies. The testing scope is always tailored to your infrastructure and business objectives.

logo

Sign up for our newsletter for all the important cybersecurity and ethical hacking news.

© 2024 citadelo AG. All rights reserved.

facebooklinkedinxyoutube