Cyber Security & NIS2

Cyber Security, Penetration Testing and Vulnerability Assessment

Technical security testing of networks, applications and infrastructure: we identify vulnerabilities, demonstrate their real impact and work alongside the company on remediation, with reports that management can read and IT can act on.

What we do

Our areas of work

Systematic vulnerability assessment

We run repeatable scans of the external perimeter, the internal network and the systems in scope, classify vulnerabilities by CVSS score and weed out false positives: an inventory of weak points that can be kept up to date over time.

Penetration testing of networks and infrastructure

We exploit vulnerabilities under controlled conditions to show what they would actually allow: access to data, privilege escalation, lateral movement. A black, grey or white box approach, depending on the objective and within the limits agreed in writing.

Web application, API and mobile security

We test web applications, APIs and mobile apps against the OWASP standards: authentication, session management, access control, input validation, data exposure and application logic.

Active Directory, cloud and wireless networks

We review configurations and privileges in Active Directory, cloud environment settings (identity, storage, networking) and the security of corporate Wi-Fi networks: the areas where many real-world attacks start.

Social engineering and simulated phishing

We measure how people react through agreed simulated phishing and social engineering campaigns, run in line with data protection and employment law. The aggregated results feed targeted training for the most exposed roles, with no disciplinary purpose.

Hardening and support for the security function

We translate the findings into safer configurations: hardening baselines for systems, networks and cloud, a review of privileges and authentication, guidance on monitoring. Where requested, we provide ongoing support to the people who oversee security within the organisation.

The regulatory context

Cyber attacks are no longer the preserve of large organisations. Ransomware, credential theft, business email compromise and attacks that arrive through suppliers regularly hit SMEs, often exploiting vulnerabilities that have been known for months and never fixed. The question the board should ask is not whether the company is exposed, but how exposed, from where and with what consequences.

Legislation has caught up with this reality. Article 32 of the GDPR requires security measures appropriate to the risk and expressly names, among those to be adopted where appropriate, a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. The NIS2 Directive, transposed into Italian law by Legislative Decree 138/2024, requires essential and important entities to adopt cyber security risk management measures and to assess their effectiveness (Article 24), with direct responsibilities for the management bodies (Article 23). Technical specifications and deadlines are set by the Agenzia per la Cybersicurezza Nazionale (ACN, the Italian national cyber security agency), which oversees implementation.

ISO/IEC 27001:2022 includes among its controls the management of technical vulnerabilities (A.8.8) and security testing in development and acceptance (A.8.29), both to be reviewed as part of the periodic monitoring of the system. In the financial sector, the DORA Regulation introduces a periodic programme of digital operational resilience testing.

Our approach

A security test is only as good as its preparation. That is why the first stage is always defining the scope: we establish with the company which systems genuinely matter to the business, which data must be protected and which activities cannot be interrupted. These choices determine the breadth of the testing, the type of test and the rules of engagement, which are formalised in a written authorisation and covered by a confidentiality agreement.

We keep the two exercises clearly distinct. The vulnerability assessment is a broad and repeatable picture: systematic scanning, manual verification of the results, classification with CVSS. The penetration test is an in-depth investigation: controlled exploitation of the vulnerabilities in order to measure the actual consequences of an attack, with a black, grey or white box approach depending on how much we know about the systems at the outset. We follow recognised methodologies (PTES, NIST SP 800-115, OSSTMM) and, for applications, the OWASP standards.

Beyond the areas described above, where the context calls for it we extend the testing to OT and IoT environments and, for more mature organisations, to red team exercises that put the whole detection and response capability to the test. The work does not end with the report: the retest and hands-on support with remediation are part of the engagement.

What sets our service apart

  • Two levels of detail: an executive report that management can read and act on, and a technical report with instructions that IT can follow without ambiguity.
  • Integration with compliance: we link the test findings to the requirements under the GDPR, NIS2 and ISO/IEC 27001, so that one exercise answers several obligations and leaves evidence that can be used in audits and certifications.
  • Findings verified by hand: every vulnerability flagged by automated tools is confirmed manually, false positives are removed and what remains is documented with proof of concept and a CVSS score.
  • Support through to closure: we do not stop at a list of problems; we stay alongside the technical teams until the vulnerabilities have been fixed and verified.

Our method

How we work

  1. Scope and rules of engagement

    Together with the company we define objectives, scope, exclusions, type of test, time windows and emergency contact channels. We then formalise the written authorisation, the confidentiality agreement and, where personal data are accessed, the data processing agreement under Article 28 of the GDPR.

  2. Information gathering and scanning

    We map the exposed attack surface, identify services and versions, run the vulnerability scans and check the results by hand to eliminate false positives.

  3. Controlled exploitation

    In a penetration test we attempt to exploit the vulnerabilities under the agreed rules, documenting every step with evidence and stopping the work if there is any risk to operations.

  4. Analysis and reporting

    We classify the findings with CVSS and set them in their business context. We deliver both the executive and the technical report, then present them to management and IT in a dedicated session.

  5. Remediation and retest

    We support the technical teams in fixing the issues, verify through a retest that the vulnerabilities have been closed and issue the final attestation. We also agree the frequency of future testing.

Benefits

What the business gains

  • A tested, evidence-based picture of the organisation’s exposure to attack, not paper estimates
  • Clear priorities for action: exploitable vulnerabilities with a business impact come first
  • Evidence that security measures are tested regularly, as the GDPR, NIS2 and ISO/IEC 27001 require
  • Credible answers for clients, parent companies and contracting authorities asking for recent security test attestations
  • More aware staff and better-prepared IT teams, thanks to findings that are explained and not merely listed

Deliverables

What we deliver

  • Engagement document setting out scope, rules and authorisation to test
  • Executive report for management with the overall risk level and priorities
  • Technical report with evidence, proof of concept and a CVSS score for each vulnerability
  • Remediation plan prioritised by risk, effort and ownership
  • Retest report with the closure status of every vulnerability
  • Attestation that the test has been carried out, for use in tenders, audits and client relations
  • Results of the simulated phishing campaigns with training recommendations
  • Hardening guidelines for the systems and configurations tested

Frequently asked questions

Answers to the questions we hear most often

Do we need a vulnerability assessment or a penetration test?

It depends on what the company needs to know. If the aim is a broad, repeatable picture of the weak points, to be refreshed periodically, a vulnerability assessment is enough. If the question is what an attacker would genuinely obtain from an exposed application, from remote access or from the internal network, or if a client asks for an attestation, a penetration test is needed. It often makes sense to start with the first and then go deeper with the second on the systems that matter most.

Can the tests cause disruption to production systems?

The risk is real, and that is precisely why it is managed before the work starts: we agree which systems to exclude or treat with particular care, set time windows, avoid destructive techniques and keep a direct line open to the company’s IT team so that the testing can be stopped at any moment.

How often should the tests be repeated?

We recommend at least one full test each year, plus a focused test after every significant change: new applications, cloud migrations, mergers, new sites. For internet-facing systems, a more frequent vulnerability assessment – quarterly, as PCI DSS requires of organisations handling card data – helps to catch newly published vulnerabilities. The frequency should be calibrated to the risk, not fixed once and for all.

Is a penetration test required by law?

No general rule imposes it under that name, although sector-specific rules such as DORA for financial firms and contractual standards such as PCI DSS do require it. Others require it in substance: the GDPR (Article 32), NIS2 and ISO/IEC 27001 all call for the effectiveness of security measures to be tested regularly and documented. An independent test is the most direct way to do that and to leave evidence of it.

Our IT provider already manages security: do we need an independent test?

Yes, for two reasons. Those who design and run the systems rarely see their weak points through an attacker’s eyes, and clients, auditors and authorities attach weight to the independence of the party carrying out the checks. We do not replace the company’s provider: we involve them, share the findings constructively and support them through remediation. An independent test is also a way of assessing the quality of the service the company receives.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.