Cyber Key Security

Authorised · Scoped · Reported · Retested

Penetration testing

Prove what a skilled, authorised tester can do — then fix it.

A penetration test is a time-boxed, written-authorisation engagement. We agree objectives and rules of engagement, test within them, and deliver executive and technical reports. We do not publish methods that help anyone attack a system.

Why buyers and auditors ask for this

SOC 2, ISO 27001, PCI DSS, and many cyber-insurance applications expect independent testing beyond automated scanning. A pentest answers a different question: given this scope, what can a professional actually achieve, and how should leadership respond?

What CKS delivers

Clear rules of engagement

In-scope assets, off-limits systems, testing windows, emergency contacts, and how we handle a live incident if we stumble into one.

Agreed test stance

Black, grey, or white box — how much information we start with. The choice is yours and is written down before work starts.

Two-layer reporting

An executive brief for risk and budget. A technical annex for engineers: affected assets, impact, and remediation direction — without weaponised detail.

Remediation validation

When you say a finding is closed, we re-test that finding. Auditors care about closure, not theatre.

How we run the work

Professional testing is a project, not a weekend hobby. We follow a repeatable lifecycle so results are comparable year on year.

Scoping workshop

Business objectives, crown-jewel data, and what “success” means for this test — phishing in or out, apps in or out, segmentation in or out.

Authorised testing window

Work happens in the agreed period against the agreed targets. No surprise scanning of third parties you do not control.

Debrief

A conversation before the PDF goes to the board. Context matters more than a colour chart.

Evidence for GRC

The report is written so it can sit next to SOC 2, ISO, or PCI files without a translator.

Engagement shape

  1. 1. Scope and authorise

    Legal go-ahead, contacts, constraints, and success criteria.

  2. 2. Test

    Time-boxed work inside the rules. Daily check-ins if you want them.

  3. 3. Report

    Executive and technical documents, ranked findings, remediation guidance.

  4. 4. Validate

    Retest of agreed closures. Optional follow-on assessment next cycle.

What you can take to leadership

  • A defensible answer to “have we been independently tested?”
  • Prioritised work that engineering can schedule
  • A retest trail for auditors and insurers
  • A cleaner story for customers who ask for a summary letter

FAQ

Will you share exploit code or attack playbooks?
No. Reports describe impact and how to fix. We do not ship payloads, proof-of-concept exploits, or step-by-step attack procedures.
Can you test without disrupting production?
We plan for it: windows, rate limits, and a kill switch. Some checks still carry residual risk — we say so in the rules of engagement.
Internal, external, or both?
Whatever the scope says. External answers “from the internet.” Internal answers “from a foothold you asked us to assume.” Both are common in a yearly programme.
Is this legal?
Only with written authorisation from someone who can grant it. We will not start without that document.

Talk to an expert today

+359 895 155 438
info@cyberks.com

Call now

Talk to an expert today

Prove what a skilled, authorised tester can do — then fix it.

Call nowFree consultation