Your situation

Penetration testing for applications, networks and infrastructure

An application is about to be released, a customer requires a penetration test or your infrastructure has changed. You want to know which vulnerabilities can be identified and how your team can fix them. We test the agreed applications and systems and give specific recommendations.

secuvera is a BSI-certified IT security service provider for penetration testing.

Free of charge and without obligation.

  • BSI-certified for IS penetration testing
  • BSI-certified IS penetration testers on the team
  • Co-author: TeleTrusT guideline on penetration testing
Two secuvera experts examining a navigation instrument together
Penetration testing with a trained eye: finding vulnerabilities before attackers do.

Your situation

You are planning a penetration test and looking for a qualified provider?

An application is about to go live. An auditor or client requires pentest evidence for ISO/IEC 27001, DORA, IATF 16949 or DiGA approval. Your infrastructure has changed fundamentally. Or you simply want to know how vulnerable your systems really are today.

By then there are often proposals on the table that are hard to compare: different test depths, unclear scope, reports that essentially consist of tool output. The decisive question remains open: which test actually answers your question? Our guide Choosing a penetration testing provider: 11 criteria (in German) summarises what to look for when comparing proposals.

This is where we start. In the free initial consultation, we work with you to derive the appropriate test methodology from your test objective. Some questions have dedicated tests: breach and attack simulation (BAS) for Active Directory and Entra ID, the AI pentest for LLM applications, DDoS simulation for load and availability, OSINT analysis for your public attack surface and red teaming if you want to test detection by your SOC. We have been carrying out penetration tests since 2000. Since 15 September 2013, secuvera has been certified by the BSI as an IT security service provider for IS penetration testing (BSI directory, in German).

Our work is based on our internal processes, which we have been improving for many years. We draw on publications, in particular the TeleTrusT guideline “Penetrationstests” (in German). secuvera is one of its main authors.

Testing portfolio

What we test: from web applications to AI chatbots

Put simply: everything except SAP security. As a BSI-certified IT security service provider for penetration testing, we offer these tests – individually or combined.

Types of testing

Penetration tests according to specific requirements

  • Penetration test for ISO/IEC 27001 audits
  • Penetration test for DORA audits
  • Medical devices according to IEC/TR 60601
  • Smart meter gateway administration according to BSI TR-03109-6
  • IT Security Ordinance for the Portal Network (ITSiV-PV) under Section 5 OZG
  • IATF 16949, Sanctioned Interpretations, section 6.1.2.3 “Contingency plans”
  • i-Kfz vehicle registration portals according to the minimum security requirements of the KBA (MSA-i-Kfz)
  • Video consultations according to Annex 31b BMV-Ä
  • Online elections according to BSI TR-03162, section 3.3
  • DiGA according to the DiGA guide – with a BSI-certified test centre, code review and white-box tests
  • DiPA according to the DiPA guide – with the same stricter requirements

Services & results

A good pentest starts with planning

You receive an individually written, twice-reviewed report with rated findings and recommendations on your web applications, interfaces, networks and infrastructure, in German or English, with a retest on request. Testing takes place within the agreed scope over the internet, via VPN or on site, carried out by a service provider certified by the BSI for IS penetration testing.

We do not simulate “a hacker” – there is no such thing as a defined benchmark. Instead, we apply attack methods in a targeted way to carry out a carefully planned project efficiently. The approach described here is our standard; if you have your own processes and requirements, we follow them.

Planning: finding the right test objective

Before any testing, we clarify together what the test should achieve for you: which question should it answer, which systems are included, what test depth makes sense? This way we test the right things and do not miss the actual objective. This planning – scoping – is a discipline of its own; we even run workshops on it.

This works best in the free initial consultation. On request, we can also prepare the proposal based on a questionnaire; it becomes more precise after a short conversation. Sometimes it turns out that a penetration test is not the right instrument at all. In that case, we tell you what fits better.

Your proposal

A proposal with an approach described specifically for your project, derived from your test objective.

Kick-off: defining test objective, access and schedule

Once the order is placed, your project lead contacts you promptly. In the kick-off meeting, we define the test objective precisely, along with all dates, the access routes – over the internet, via VPN or on site – and the user accounts required. We identify and mitigate critical factors using a checklist we have refined over many years.

Internally, each tester presents their own test plan, which the project lead reviews. It also forms the basis for the subsequent technical quality assurance.

Authorisation and project plan

The authorisation form records the test period, target systems and contacts on both sides; the project plan records all project steps.

Execution: tested manually, traceable in your logs

We carry out tests over the internet from an isolated network segment with fixed IP addresses – so you can trace every step in your firewall and server logs. For internal networks, you can use our pentest box instead of an on-site visit: connect power and network, and the connection to us runs over a secure VPN channel.

We supplement tools with manual testing, because many vulnerabilities cannot be found by any scanner. We disclose our methodology and tools to you. We report serious vulnerabilities immediately, not only in the report. Our work is based on our internal testing processes, which we have been improving for many years. We draw on publications, in particular the TeleTrusT guideline “Penetrationstests”, of which secuvera is one of the main authors, as well as:

  • BSI implementation concept for penetration tests
  • BSI practical guide to IS penetration testing
  • OWASP Web Security Testing Guide and OWASP Top 10
  • BSI practical guide to IS web checks

Report: individually written, reviewed twice

Our penetration testers write the report themselves – in German or English, using our template or yours, on request with negative reporting that discloses the complete test procedure. We rate vulnerabilities according to CVSS or your in-house standard and, on request, map them to requirements such as ISO/IEC 27001.

Every report goes through quality assurance according to our quality management manual (based on ISO/IEC 17025): technical review and spot-check verification by a member of the pentest team not involved in the project, followed by editing.

Your pentest report

No later than 5 working days after the end of testing: management summary (additionally in English on request), traceable findings with specific measures and all tool log files as XML/CSV and PDF – on request even the complete network traffic of the test.

Wrap-up and retest

In the final meeting – by phone or on site – we discuss the results and recommended countermeasures with your technical team, and on request also in a management presentation. After the review phase, you receive the finalised report within 5 working days at the latest.

On request, we retest fixed vulnerabilities in a targeted way and with little effort. Because planning and execution are documented, the same test with the same methodology produces comparable results.

Our expertise

We have been carrying out penetration tests since 2000 – exclusively with permanent employees, not freelancers. Because a certificate alone does not make a good pentest.

All new colleagues first go through an internal training phase. For each type of test, we make sure they have the necessary know-how in theory and practice: they master the methods, know the tools, know how a report is produced – and above all, how a penetration test works at secuvera.

Before their first project, they pass several internal examinations, which are themselves quality-assured. This ensures that the expertise is actually there.

Getting started

Preparing the penetration test with development and operations

Provide documents and access

Bring an overview of the test objects and your requirements to the initial consultation. Also tell us the date by which you need results. Before testing begins, we agree on the required system information and user accounts with the respective permissions.

Agree on test environment and authorisation

Together with the people responsible on your side, we define the test environment and the permitted test activities. In the authorisation form, we record target systems, test period and the contacts on both sides. You set up the agreed access. The project plan describes the individual steps and dates.

Clarify your pentest scope
The points of a pair of dividers resting on coloured sticky notes above a map
Scope precisely defined, so the test starts exactly where it matters.

What a penetration test tells you

A pentest is an examination within the agreed scope and time frame. Even a test without findings is no guarantee of complete security.

Questions about preparing and carrying out your penetration test

Can the penetration test take place on the production system?

We define the appropriate test environment with the people responsible for operations. For production systems, we pay particular attention to availability, permitted test activities and test windows. These arrangements are intended to limit the risks of testing. We cannot promise that there will be no disruption.

Do your experts need to be on site for the pentest?

Not for every test. Depending on the test object, access is over the internet, via VPN or on site. For internal networks, we can alternatively use our pentest box. It needs power and suitable network access; the connection to us is encrypted. We agree on the appropriate access route in advance.

Will we learn about critical vulnerabilities during the test?

Yes. We report serious security problems immediately to your designated contact. We discuss the next steps with the people responsible on your side. You do not have to wait for the final report.

Can we specify the language and template of the pentest report?

We write reports in German or English. You can provide your own report template or use ours. On request, we add an English management summary to a German report. We agree on these requirements at the start of the project.

Do you exploit the vulnerabilities you find?

Only where it is necessary for detection, for example with an SQL injection. Otherwise, exploitation is mainly a risk to your system and adds little insight – so as a rule we refrain from it.

Articles on this topic (in German)

All 80 articles on the topic (in German)

How can we support you with your penetration test?