Offer · Cybersecurity & Technical Security

Vulnerability assessment and penetration testing

Find the weaknesses before someone else does. Scanning, assessment and targeted tests of systems, networks and applications, with findings prioritised by risk and an action plan you can deliver.

Vulnerability scanningPenetration testingRisk prioritisationAction planAbout a week

Who it is for and when

Suits organisations that want a fact-based picture of their technical security, ahead of an audit, after a change or as a recurring check.

  • A customer, auditor or regulator asks when you last tested your security.
  • You have moved to the cloud, changed the network or introduced new systems and want to know it was done securely.
  • You have a feeling that the environment has weaknesses but no consolidated picture.
  • The Cybersecurity Act or ISO 27001 requires you to handle vulnerabilities systematically.

What we do

  1. Scope and rules. We agree which systems, networks and applications are included, test windows, contact persons and what must not be disturbed.
  2. Vulnerability scanning. Automated scanning of the systems in scope to find known vulnerabilities, misconfigurations and missing updates.
  3. Targeted tests. Manual tests where a tester tries to exploit weaknesses the way an attacker would, within agreed limits.
  4. Prioritisation by risk. Every finding is assessed by how serious it is and how easy it is to exploit, with a concrete remediation proposal.
  5. Walkthrough with IT. We go through the report with your IT team so that remediation can be planned directly.

You get

  • Report with findings prioritised by risk
  • Concrete remediation proposals per finding
  • Summary for management without technical jargon
  • Walkthrough with your IT team
  • Option of a retest when the actions are completed

Scope and price

A defined engagement that normally takes about a week including the report, depending on how many systems and applications are included and how deep you want the tests to go.

The price varies from engagement to engagement and is driven by the scope. You get a fixed price in the proposal. A retest after remediation is quoted separately.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

What is the difference between vulnerability scanning and penetration testing?

The scan is automated and finds known weaknesses in breadth. The penetration test is manual and targeted: a tester tries to exploit the weaknesses the way an attacker would. We usually do both, since they answer different questions.

Can the tests disrupt operations?

The risks are managed by agreeing scope, test windows and what must not be disturbed before we start. Tests against production systems are planned so that the impact is minimal.

How often should we test?

Scan regularly, for example monthly or quarterly. Penetration test after major changes and otherwise at a fixed interval, often annually, depending on requirements and risk profile.

Reviewed by Kristensson i Skåne AB. .

Sources: CIS Controls · OWASP Top 10 · NIST Cybersecurity Framework

Want to know where the weaknesses are?

Contact us