Vigilant Cybersecurity
Resources

How we test, and what you get.

Buying a penetration test is hard to evaluate if you have never bought one. This page shows the methodology and the deliverable before you commit to anything.

Methodology

Six phases, aligned to PTES and OWASP.

The same structure runs across every practice area. What changes is the tooling and the specialist doing the work.

Phase 01

Reconnaissance

We map what is publicly knowable about you before touching anything: exposed infrastructure, leaked credentials, subdomains, third-party surface, and employee footprint. Attackers start here, so we do too.

Phase 02

Enumeration & mapping

Active discovery against the agreed scope. Services, versions, endpoints, roles, and trust relationships get catalogued into a working model of the environment, the thing a scanner never builds.

Phase 03

Exploitation

We validate by hand what is genuinely exploitable, and discard what only looks dangerous in a scanner. Anything critical is reported to you the day we find it, not held for the report.

Phase 04

Post-exploitation

The part that determines real business impact: how far does the initial foothold go? We escalate privileges, move laterally, and establish what data would actually be reachable.

Phase 05

Reporting

Findings are written up with reproduction steps, evidence, a severity rating grounded in your context rather than raw CVSS, and remediation guidance specific enough for your engineers to act on.

Phase 06

Remediation & retest

We support your team through fixes, then retest every finding to confirm closure. You receive a clean retest report and an attestation letter for customers and auditors.

The deliverable

What actually lands in your inbox.

A pentest report is only useful if two very different audiences can act on it: the engineer who has to fix the bug, and the executive deciding whether to fund the fix.

Findings by severityn = 34
  • Critical
  • High
  • Medium
  • Low

Illustrative distribution. Real counts vary by scope.

01

Executive summary

Written for people who do not work in security. Business risk, what it would cost you, and the three things to do first.

02

Technical findings

Every issue with reproduction steps, evidence, affected assets, and a severity rating set against your environment rather than a generic score.

03

Remediation guidance

Specific, actionable fixes across configuration, code, and architecture, prioritized by risk reduction per unit of effort.

04

Attack narrative

The chained path from initial access to impact, so leadership can see how three medium findings became one critical outcome.

05

Retest report

Verification that each finding is genuinely closed, issued after your team completes remediation. Included, not billed.

06

Attestation letter

A shareable summary confirming the assessment took place and its scope, for customers, prospects, and auditors.

We've got you covered

Frequently asked questions.

Still unsure whether you need a test, or which one? The scoping call is free and we will tell you if you do not need us.

Ask us directly

A penetration test is an authorized simulated attack on your systems, performed by people using the same techniques as real adversaries. Unlike a scan, which reports what might be wrong, a pentest proves what an attacker could actually do: which systems they would reach, which data they would take, and how far they would get before anyone noticed. Most organizations need one because a customer, insurer, or regulator is asking for it. The reason to want one is that it is far cheaper to find these problems than to have them found for you.

Test your defenses

Don't wait for a breach.

Discover your weaknesses before an attacker does. Scoping calls are free, take about thirty minutes, and end with fixed pricing.