A scope agreed before anything is touched
What is in, what is out, when it happens and who gets called if something breaks. In writing, signed by both sides.
A pentest is an authorised attack on your own systems: we try to break in using the techniques somebody would use for real, with your written permission and an agreed scope, and we write down what worked.
There are nine kinds, and the only thing that changes between them is what gets attacked. Pick by what you want tested, not by what it is called.
How we run oneProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
The person who would run the test will reply within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















A penetration test, or pentest, is a controlled attack against a system you own, agreed in advance and carried out with written permission. The aim is not a list of theoretical weaknesses: it is to find out which ones a real attacker could chain together, and prove it.
Scanners are part of it, but only the starting point. Broken authorisation, business logic that can be walked around and chains that only work in the right order are found by a person.
The Spanish name is "test de intrusión", and the two mean the same thing.
Nine kinds of pentest. They are listed by what each one attacks, because that is the question you can actually answer today.
Not sure which one, or it is more than one? That is normal, and it is what the introductory meeting is for.
You do not have to arrive knowing the name of the test. These three questions get you to the right one, and they are the same three we ask on the call.
Very often the answer is two: a mobile app comes with the APIs behind it, and an internal test pairs with the external one. That is normal, and it is decided before anyone quotes anything.
/api/orders/4813
This is one real class of flaw, taken from web testing: a user changes a number in a request and the server hands over somebody else's order. No scanner signature fires, because every request is well formed and correctly authenticated. Each of the nine services has its own demo on its own page; this one is here so you can see the shape of the thing.
Whichever of the nine you buy, the method is the same one: the seven phases of the PTES. What changes between them is the target, not the process.
What is in, what is out, when it happens and who gets called if something breaks. In writing, signed by both sides.
Scanners run too, but they are the floor. What is worth paying for is the finding somebody had to think of.
Every finding with the steps to reproduce it, the evidence that it worked and what closing it would take, ordered by what it costs your business.
Once you have fixed things, we test the same findings again. A vulnerability is not closed because a ticket says so.
A customer, an auditor or an insurer asks for a penetration test report before signing.
You are about to ship something new and nobody outside the team has tried to break it.
A certification or a regulation needs evidence that somebody tested it.
Something already happened and you want to know what else is open.
Findings do not arrive as a PDF three weeks later. They land in the platform as they are confirmed, each with its evidence, its severity and its closure status, so your team can start on the first one before the test has finished.
The recorded walkthrough is not published yet. Until it is, the platform is shown live on the introductory meeting.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
A pentest is one of five families. These are the others, in case what you actually need is one of them.
What is pentesting?
An authorised attack on your own systems, carried out with the techniques a real attacker would use, to find out what somebody could actually do and prove it. The Spanish term is "test de intrusión".
Is it the same as ethical hacking?
Ethical hacking is the general term and a penetration test is the specific engagement: an agreed scope, a time window, manual testing and a report.
Which of the nine do we need?
It depends on what you want tested, and quite often it is more than one: a mobile app usually comes with the APIs behind it, and an internal test pairs with the external one. We work that out in the introductory meeting before anyone quotes anything.
How long does it take?
It depends on the scope, and that is what the kick-off meeting settles. Any number given before knowing what is in scope would be made up.
Do you do pentesting for SMEs?
Yes. The type of test is the same and what changes is the scope: a small company usually starts with the external perimeter or with its web application, which is where almost everything it exposes lives.
What do you need from us to start?
Somebody who can authorise the test, the list of what is in scope and a window to do it in. Everything else is closed in the kick-off.
Two lines about what the system is and what it is used for are enough for us to say which of the nine fits and what scoping it would take.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We will reply within one business day with which of the nine fits and what it would take to scope it.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
A pentest is one of five families. These are the others, in case what you actually need is one of them.
See every servicePick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.