Capabilities
Penetration testing
External, internal, web application, and API testing by a senior offensive security operator. Manual testing with real exploitation attempts, not a scanner report with a cover page.
DELIVERED THROUGH
A Cloudsapio vCISO engagement
engagement levels
Advisor · Consultant · Leader
TYPICAL TIMELINE
1–3 weeks from scoping to report
tHE PROBLEM
A scan tells you what exists.
A pentest tells you what an attacker can do with it
Most companies buy their first pentest because an auditor or a customer asked for one, and most of what gets sold in that moment is a scanner run with a report template on top. It satisfies the checkbox. It tells you nothing.
The findings that matter are rarely single vulnerabilities. They are chains: a low-severity information disclosure, plus a permissive access rule, plus an assumption in your authorisation logic, which together let someone reach another tenant's data. No scanner will connect those three, because connecting them is judgement.
WHAT YOU GET
Deliverables
Manual testing across external, internal, web application, and API surfaces, delivered by a senior offensive security practitioner. Every engagement ends with a report, an exploitation narrative, and a working session with your engineers.
01
Scoping call and a rules-of-engagement document
02
Manual testing with exploitation attempts
03
Findings report with CVSS ratings, proof of concept, and remediation guidance
04
Exploitation narrative showing how findings chain into a real attack path
05
Executive summary your auditor, board, or customer can read
06
Remediation working session with your engineering team
fit
Who is this for
Companies preparing for SOC 2 or ISO 27001, responding to a customer security questionnaire, or launching a product that needs external validation before it goes live.

HOW IT WORKS
The engagement step-by-step
01
Discovery call (30 min)
Who asked for the test, what you are launching or defending, and the deadline you are working to.
02
Scoping
We agree the targets, the test window, what is in and out of bounds, and the escalation path if we find something critical mid-test. You get a fixed scope and price before anything starts.
03
Testing
Manual work against the agreed scope. If we find something critical, you hear about it immediately rather than in the report.
04
Reporting
Findings with proof of concept, an exploitation narrative explaining how they chain, and remediation guidance written for engineers.
05
Working sessions
We walk your team through the findings and answer questions. This is where most of the value lands — a report alone gets skimmed and shelved.
06
Retest
Once critical findings are fixed, we retest and confirm closure, so you have evidence rather than an assertion.
The questions that come up on every first call.
-
How is this different from vulnerability scanning?
Scanning is automated, broad, and recurring. It finds known vulnerabilities across your estate. A pentest is a person attempting to chain weaknesses into a working attack path against a defined target. Most frameworks expect continuous scanning and a pentest annually. Neither replaces the other.
-
Do we need one for SOC 2?
Not strictly. SOC 2 does not mandate a penetration test by name, but auditors commonly expect one as evidence for the relevant criteria, and customers ask for the report regardless. In practice, most companies pursuing SOC 2 end up doing one. ISO 27001 has a similar expectation.
-
How long does it take?
Most engagements run one to three weeks from scoping to report, depending on scope and the number of applications in play.
-
Will this disrupt production?
Most engagements run one to three weeks from scoping to report, depending on scope and the number of applications in play.
-
Can you test our AI features?
Yes, and it is worth scoping explicitly. Prompt injection, data leakage through model outputs, and authorisation gaps in agent tooling are not covered by standard application testing methodology.
RELATED CAPABILITIES
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.