
Penetration Testing.
Pen testing (aka Ethical Hacking) is all about identifying and fixing the vulnerabilities in your scheme's digital assets before the threat actors, or their AI agents,
spot and expoit them.

If your pen testing firm can identify critical vulnerabilities in your scheme's digital assets, so can a cyber threat actor.

Introduction
A penetration test is a simulated cyber attack on one or more of your scheme's digital assets, such as a web app (e.g. member portal or trustee portal), your Office365 environment, or any other physical or virtual IT asset that stores, processes or transmits your data.
​
Conducted by highly experienced and CREST-certified ethical hackers, these assessments seek to leverage the tools and techniques that a real cyber criminal has at their disposal, to work out which vulnerabilities exist in your scheme and how to exploit them.
​
Each pen test report describes the identified vulnerabilities, grades their severity (how easily they can be exploited), explains how exploitation can be achieved and makes remediation recommendations. Unsurprisingly, the information in these reports is regarded as gold dust by threat groups.
​
At Cyserri, we work with our award-winning UK-based pen testing partner to not only ensure that the scoping and planning of each assessment aligns with your risk appetite and objectives, but also to support pre-execution activities, ensure the report findings are adequately understood, and help you decide which remediation actions to take, who should take them, in which order and by when.

When you understand the mindset of a hacker, you'll realise that you've just become allergic to 'low-hanging fruit'.
Services we offer
The pen testing services that Cyserri offer include:​
​
-
Web app pen testing (e.g. member portal, trustee portal)
-
Mobile app pen testing (e.g. iOS app version of a portal)
-
Cloud Infrastructure pen testing (e.g. Azure and AWS)​
-
Office infrastructure pen testing (e.g. WiFi, printers, firewalls)
-
Mobile device pen testing (e.g. laptops and mobile phones)
-
Microsoft365 security review
-
Pen test support services
-
Annual pen test plan development
​
In short, though, if your scheme has an asset that a cyber threat actor can attack, we'll have a pen test to help mitigate those risks.


Make sure your pen test agreement includes a post-remediation re-test.
Without it, you won't know whether the remediation work has succeeded.

Benefits of our pen tests
Our pen tests:
​
-
are conducted by CHECK-certified ethical hackers
-
follow internationally respected pen testing frameworks
-
improve your cyber security and cyber compliance posture
-
provide assurance to trustee boards, sponsors, cyber insurance firms and other stakeholders that your scheme's most critical vulnerabilities are being identified and appropriately addressed
-
can offer support at every stage of the pen-test lifecycle, from requirements capture, scoping and access facilitation, all the way to remediation planning, implementation and re-testing
-
can reduce your cyber insurance premium and also increase the likelihood of a claim being successful

