Penetration Testing (Pentest)

Proactive IT protection for businesses and authorities

A penetration test (also called a pentest) is a simulated cyber attack on software or IT systems. The goal is to test the IT infrastructure of businesses and authorities for security gaps.

Illustration of a penetration test on a business application

What exactly are the goals of a pentesting exercise?

The main tasks of a penetration test include:

  • Identifying points of attack in the IT infrastructure
  • Detecting potential flaws
  • Increasing IT security in technical and organisational terms
What exactly are the goals of a pentesting exercise?
Pentest vs. cyber attack

Pentest vs. cyber attack

Unlike a cyber attack, penetration tests are authorised and carried out under strictly defined terms. This is also referred to as ethical hacking.

Have a pentest carried out now!

We proactively test IT systems and websites for vulnerabilities and security gaps. This reduces the cost of remediating security incidents and limits their impact.

Request a project

Why is a penetration test important?

Pentesting is a very valuable instrument for corporations, SMEs and authorities. The main arguments for carrying out penetration tests are:

Identify vulnerabilities in good time

A penetration test reveals current gaps in IT security and assesses the effectiveness of the protective measures in place. This makes it possible to take proactive steps to close these gaps.

Realistic risk assessment

Pentesting makes it possible to determine in detail which vulnerabilities in the IT system can actually be exploited. This also allows the potential extent of damage to be estimated.

Meeting compliance requirements

PCI DSS requires regular penetration tests, while ISO 27001 calls for vulnerability management and security testing, for which pentests serve as evidence. The BSI also describes penetration tests as an instrument for examining IT security.

Avoiding costs through pentests

Data loss, business interruption, reputational damage, penalties: the costs of threats such as malware attacks, social engineering or DDoS attacks can be immense. Proactive protection is the safest option.

Pentesting: our services

As an established software agency, our core business is the development and optimisation of software and web apps. Penetration tests can be booked optionally with us or commissioned independently of a software development project.

Our pentesting services include, among others:

Black-box tests

These pentests are carried out without any prior information about the target system. They simulate an external attack without inside knowledge.

White-box tests

This category covers tests with insider knowledge. Internals such as login data, the source code or architecture plans are used here. This in-depth analysis makes it possible to identify complex flaws.

Pentesting of applications

The targeted testing of software, apps and web applications makes it possible to find security gaps in ERP systems, CRM software or internal tools. In addition, we also offer the testing of customer portals or e-commerce platforms.

Cloud infrastructure security testing

As part of an IT penetration test, we thoroughly examine the configuration and security of cloud environments such as AWS, Azure or Google Cloud.

Network penetration testing

As networking increases, IT networks become more vulnerable to attacks. A network penetration test specifically identifies weaknesses in the corporate network and provides clear recommendations to effectively strengthen network security.

Vulnerability assessments

Our automated vulnerability scans are continuously adapted to current threats. They detect known security gaps in software and IT systems.

Documentation and reporting

We document identified points of attack and provide a comprehensive report including a risk assessment. On request, we develop a traceable proof of concept and give concrete recommendations for remediating the vulnerabilities.

Continuous penetration testing

Combined with a longer-term maintenance contract, regular pentests can be planned in from the start.

API penetration testing

APIs are interfaces for programming applications. They form the backbone of a modern IT infrastructure. We identify the security gaps in programming interfaces such as REST, SOAP or GraphQL.

FAQs

What is a penetration test? keyboard_arrow_down keyboard_arrow_up
A penetration test, or pentest for short, is a commissioned and controlled security assessment. Experts simulate real attacks on applications, networks and interfaces to uncover vulnerabilities before actual attackers exploit them. The result is a traceable report with prioritised recommendations for action.
How often should a penetration test be carried out? keyboard_arrow_down keyboard_arrow_up
As a guideline, at least once a year and after major changes to applications, infrastructure or interfaces. For operators of critical infrastructure and in cases of high protection needs, shorter intervals are advisable. TenMedia aligns the frequency with the specific risk and compliance requirements.
Is a penetration test dangerous during live operation? keyboard_arrow_down keyboard_arrow_up
No, when it is planned professionally. Scope, time window and approach are clearly agreed in advance and contractually defined. On request, tests can be carried out in test environments or during low-load time windows, so that the impact on live operation stays low.
Does a penetration test help with ISO 27001, BSI and NIS-2? keyboard_arrow_down keyboard_arrow_up
Yes. Penetration tests are a recognised building block for demonstrating requirements from ISO 27001, BSI baseline protection and NIS-2. The documented results serve as evidence for audits and support the continuous improvement process of information security. This is especially relevant for authorities and operators of critical infrastructure.

What we are proud of

Experience
14+ Years
Customers
30+
Lines of code
1+ Million
Projects
40+
In-house development
100%
Ventures
4+
Partner
partner
Certifications
ISO 9001: Quality Management
ISO 27001: Information Security

Customers who trust us

Logo Friedrich-Alexander-Universität Erlangen-Nürnberg
Logo Landwirtschaftskammer Nordrhein-Westfalen
Logo Land Berlin, Senatsverwaltung für Integration, Arbeit und Soziales
Logo KätheCare GmbH
Logo Stiftung Denkmal für die ermordeten Juden Europas
Logo involas Institut für berufliche Bildung, Arbeitsmarkt- und Sozialpolitik GmbH
Logo Bezirksregierung Köln
Logo Deutsches Kulturforum östliches Europa e.V.
Logo IfFP Institut für Finanzplanung AG
Logo SIGNUM Consulting GmbH / Marke DISA
Logo Zentrum für Qualität in der Pflege
Logo medienrettung
Logo advise research gmbh
Logo Berolina Bestattungsinstitut GmbH
Logo B&W Software GmbH
Logo Verein Deutscher Distanzreiter und -fahrer e.V.
Logo Aussteuerhaus Mannsdörfer GmbH
Logo CustomersX GmbH
Logo gigaaa International SA
favorite Contact & Feedback TenMedia
All contact requests are free of charge and non-binding, by phone, e-mail and in person. We are happy about every project and will get back to you as soon as possible.