Web application penetration testing
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
A standing team that tests every significant change and re-examines the perimeter on a schedule, instead of one report a year.
Programs and assurance
An annual penetration test describes the system as it was during two weeks of the year. A product that ships every week is a different system by the time the report is read. Vulnerabilities introduced in the following release wait for the next test, or for someone else to find them.
Continuous testing follows the release cycle. The same specialists stay with your product, learn how it is built and test what has changed, when it changes. Findings arrive in your tracker when they are confirmed, not at the end of a reporting period. Automation watches the perimeter between releases; every result it produces is verified by a person before it reaches you.
01Scope
02Approach
The engagement starts with a full assessment of the scope. It establishes the state of the system and the knowledge of the team.
You notify us of releases, or give read access to the change log. We select the changes that affect security and plan the testing.
Changes are tested by hand. Between releases, automated discovery watches the perimeter and a specialist verifies what it reports.
A confirmed finding becomes a ticket in your tracker with evidence and a fix. The retest is triggered by the status of the ticket.
03
04
05Standards
Test cases for web applications and APIs.
OWASP Foundation
Requirements an application is verified against.
OWASP Foundation
The most critical risks of APIs.
OWASP Foundation
Severity score and vector of every finding.
FIRST
Probability that a known vulnerability is exploited; used for prioritisation.
FIRST
06Questions
No. Automation is used for discovery and for regression. Testing of changes is manual, and nothing is reported to you that a specialist has not verified.
It includes it. The baseline and the periodic in-depth assessments produce the report that frameworks such as PCI DSS ask for, and the letter states the period covered.
As a monthly number of testing days, agreed in advance. Days that are not used in a quiet month carry over within the quarter.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.