
We start each test with a scoping meeting where we agree on goals, environment and approach together with you. Then we build a plan based on proven standards that OSSTMM, OWASP, NIST, PTES, and ISSAF, combined with our own offensive methodology and real-world assault experience.
When the plan is ready, we go to attack. We identify, test and exploit weaknesses throughout the allotted time, with full focus on finding the real security gaps. Throughout the test, you will receive ongoing status updates. If we find something critical, we report it right away so you can act right away.
Once the work is complete, we deliver a clear, prioritised and action-focused report that gives you full visibility into the gaps and exactly how to close them.
Here's how it goes
About pentester

Cyloq pentester
It doesn't matter how strong your internal team is or how good your current security provider is. When you work with your own systems on a daily basis, you become homesick. Small flaws, odd configurations and old vulnerabilities often hide right in front of the eyes of those who work closest to them.
Bringing in an independent agent to call your systems is one of the smartest moves you can make to spot weaknesses that might otherwise go under the radar. Cyloq does just that. We don't settle for a quick sweep across the surface. We are zealous, persistent and methodical, and we investigate your systems at a level that few others can.
Our focus isn't to confirm that everything looks good -- it's to find what can bring you down, before someone else does. And unless we find some gaps, rest assured no one else will either.
Range
Svara på fem korta frågor så får ni en skräddarsydd rekommendation – rätt tjänst, rätt metod och rätt takt.
Tar ungefär 1 minut · Inga personuppgifter sparas
FAQ
A vulnerability scan is automated and identifies known security gaps. A penetration test is a manual test where we actually try to break in, just like a real attacker would.
It depends on what's being tested. We always define the timeline together in the scoping meeting. We adapt to your environment and scope, not to a standard package.
Not much. We host a scoping meeting where we go through objectives and boundaries, then you give us the right accesses, and we take it from there. Your own teams don't normally need to be available during the test.
A prioritized report you can act on immediately. It shows what we found, how we got in, and exactly what you need to do to close the gaps. If we find anything critical during the test, we'll contact you right away, without waiting for the final report.
We align on that in the scoping meeting. We discuss whether the test should run against a production or test environment and adapt our methodology accordingly. We regularly test in environments where operational disruption isn't an option — banks and municipalities are examples of clients we work with on an ongoing basis.
It varies depending on what's being tested and how complex the environment is. Use our pricing calculator for an initial estimate, or book a scoping meeting and we'll give you a concrete quote based on your actual conditions.
Contact Us
We'll find what threat actors hope you've missed.