Penetration Testing

Penetration Testing for Sustainable Cyber Resilience

With customized penetration tests, Oneconsult uncovers security vulnerabilities in networks, cloud environments, IT and OT systems, as well as AI systems and AI agents. You receive verified findings, a risk-based assessment, and specific remediation recommendations.

A penetration test (short: pentest) is a controlled, authorized security assessment in which our experts simulate the methods used by real attackers to specifically search for vulnerabilities in your systems. A pentest is suitable for companies of all sizes that need to secure applications, IT sys-tems, cloud and AI systems (e.g., AI agents), as well as IoT or OT systems. The result are summarized in a report that presents all identified security vulnerabilities, their associated risks, and specific remediation measures.

As a specialized penetration testing provider, Oneconsult relies on a team with recognized industry certifications, including OSCP, OSED, OSEP OSWE, and OSWP from OffSec, as well as Burp Suite Certified Practitioner (BSCP), Certified Red Team Operator (CRTO), and others. For more than 20 years, penetration testing has been our core competency. With our team of more than 30 pentesters, we complete several hundred projects each year and draw on extensive hands-on experience.

Our Penetration Testing services

Our penetration testing services cover the entire spectrum of connected systems, from (web) applications, IT infrastructures, and cloud environments to IoT devices, OT environments, AI systems, and AI agents. Each service is tailored to the specific attack vectors and risks associated with the respective technology.

AI Agent Security

Are there hidden risks in your AI systems? Our AI Agent Security Audit uncovers security gaps in chatbots, LLMs, RAG and agents and provides clarity for targeted protective measures.

Application Testing

Are your applications secure, or do they provide attackers with a point of entry? We thoroughly assess all types of applications, particularly web and mobile applications, using proven methodologies and real-world attack techniques.

Client- / Server Infrastructure Testing

How secure are your endpoints and servers really? We simulate targeted attacks against clients and servers and identify vulnerabilities before they can be exploited.

Cloud Security Testing

Can you trust the security of your cloud environment? Whether AWS, Azure, GCP, or hybrid set-ups – we analyze your cloud landscape, cloud services, and configurations for security weaknesses.

IoT & OT Security Testing

Are your smart devices and OT environments reliably secured? We examine IoT and OT systems – including firmware, interfaces, and communication protocols – and uncover hidden risks.

Network- / Security Infrastructure Testing

Is your network as secure as you think it is? We test networks from both internal and external perspectives, simulate realistic attacks, and deliver clear, actionable recommendations.

What Does a Penetration Test Look Like?

A penetration test at Oneconsult consists of three phases: from preparation through technical implementation to completion, including documentation and final discussion. Throughout the engagement, we keep you informed by means of regular status updates and transparent project management. Critical findings are reported immediately. We follow recognized standards such as OSSTMM, NIST, and OWASP to ensure a structured approach, reproducible results, and a high degree of comparability across different assessments.

1. Preparation

  • Scoping: During an initial, non-binding discussion, we work with you to define the overall scope of the assessment. We determine which systems, applications, or network segments should be tested, which methodology is most appropriate (e.g., black-box, gray-box, or white-box approach), as well as the timeline and required effort. Based on this information, we prepare a tailored and trans-parent proposal.
  • Kick-off meeting: Once you have decided to accept our proposal, the kick-off meeting serves as the official start of the project. Together, we define the detailed scope, the workflow, the deadlines, the framework conditions, and the testing requirements.

2. Execution of the Penetration Test

  • Information gathering: Depending on the agreed methodology, we use active and passive techniques to collect information about target systems and identify realistic attack surfaces and poten-tial entry points.
  • Vulnerability analysis and exploitation: The core of the test: We identify vulnerabilities, verify them manually, and exploit them in a controlled manner if necessary. Post-exploitation, lateral movement, and data exfiltration are generally not part of a standard penetration test. These ad-vanced attack scenarios are typically simulated as part of a red teaming exercise.

3. Completion

  • Documentation of results: The results of the penetration test are compiled into a detailed final report tailored to the needs of different stakeholder groups.
  • Final discussion (optional): Upon request, we present the findings and remediation recommendations in detail.
Oneconsult's Penetration Test Procedure
Oneconsult's Penetration Test Procedure

What Does the Final Report Include?

The final report contains the following items:

  • Management summary: executive-level overview of the key findings
  • Project objectives & scope: scope, methodology, and test depth of the penetration test
  • Findings: all identified vulnerabilities, including transparent risk ratings (e.g., based on CVSS)
  • Recommended measures: concrete, prioritized measures to address the security vulnerabilities

Methods & Possible Approaches for a Penetration Test

Every penetration test can be flexibly tailored to your objectives. The four key design dimensions include:

Authenticated/unauthenticated testing

You either provide our experts with valid login credentials (authenticated) or deliberately choose not to do so (unauthenticated). Authenticated testing enables us to conduct an assessment from an internal perspective, while unauthenticated testing simulates the approach of external attackers without login credentials.

Outside/inside

Testing is conducted either from the internet (outside) or from the internal network (inside). This allows for targeted testing of both externally exposed attack surfaces and risks within the organization’s own infrastructure.

Expert-led/AI-supported

The tests are conducted entirely by our experts (expert-led) or – where desired and appropriate – supplemented with AI support. The use of AI facilitates pattern recognition, identifying potential attack paths, and expanding the scope of the tests. In all cases, the results are validated by our experts and translated into reliable conclusions.

White-Box, Grey-Box, or Black-Box Testing

You provide our experts with extensive (white-box), limited (gray-box), or little to no information (black-box) about the test subject prior to the test. The less information our testers receive in advance, the more realistically the test reflects the approach of external attackers. More information allows for a more targeted and comprehensive assessment of the test subject.

The focus of a penetration test is on the technical evaluation of specific test objects. If you’d also like to assess your organization’s overall detection and response capabilities, it’s worth taking a look at the differences between penetration test and red teaming.

Your Benefits with Oneconsult’s Penetration Testing Services

More than 20 years of experience

Penetration testing has been our core competency for over two decades. Our well-coordinated team of more than 30 pentesters carries out several hundred projects each year.

Oneconsult holds multiple certifications

Oneconsult is ISO27001 certified, and our specialists hold recognized industry certifications, such as OSCP, OSED, OSEP OSWE, and OSWP from OffSec as well as BSCP, CRTO, and others.

Responsible use of AI

We use AI only where it is desired, permitted, and beneficial, in accordance with the principle of “hu-man-led, AI-assisted” – that is, used in a controlled manner, verified transparently, and always over-seen by experts.

Comprehensive testing capabilities

We test all types of networked components, ranging from traditional IT and cloud systems to IoT/OT and AI/LLM systems.

Clear recommendations for action

Our reports include an easy-to-understand management summary as well as specific recommendations for actions to sustainably enhance your cyber resilience.

Customized scoping & cost transparency

Before providing a quote, we work with you to define the exact scope of testing to ensure maximum relevance and full cost transparency.

Compliance & recognized standards

Our assessments support regulatory requirements (e.g., TLPT and DORA) and align with standards in-cluding OWASP, NIST, OSSTMM, and CIS Benchmarks.

Our statistics confirm this

Companies around the world rely on our expertise every day. This is confirmed not only by our long-standing customers but also by our statistics.
Cyber Security Projects
0 +
Incident Response Operations
0 +
Security Consulting Projects
0 +
Red Teaming Projects
0 +

Costs of Penetration Tests

It is not possible to provide a flatrate estimate for the costs of a penetration test. They depend on the specific scope of the test and are calculated transparently. The most important factors include:

  • Scope: Number and type of test objects (applications, systems, IP ranges, cloud accounts, etc.)
  • Test depth: From a simpler, focused assessment to an in-depth analysis, including exploitation of vulnerabilities
  • Methodology & approach: Black-box, gray-box, or white-box; authenticated or unauthenticated; from outside or inside
  • Complexity of the environment: Custom developments, specialized protocols, OT/IoT or AI systems
  • Additional services: Re-test to verify that vulnerabilities have been fixed, final debriefing, extended reporting according to client specifications

Since every company has a unique infrastructure, we work with you to define the scope of the project in advance during a scoping meeting. This enables us to provide you with a customized quote with no hidden costs.

Why Organizations Trust Oneconsult

  • More than 20 years of experience in penetration testing, offensive security, and cybersecurity consulting
  • Certified specialists with extensive practical experience and recognized certifications such as OSCP, OSWE, BSCP, or CRTO
  • Transparent results that clearly and comprehensibly show management as well as system and application administrators where action is needed and which measures will yield the greatest security gains.

FAQs

No. AI speeds up specific tasks, such as identifying known vulnerabilities, but it does not replace the creative, context-based analysis performed by an experienced penetration testing team. Complex attack chains, logic flaws, and manual verification remain core human competencies. AI serves as a tool in this context, but it is not a substitute.

To identify and address vulnerabilities before attackers can exploit them. A pentest provides a realistic assessment of your security level, helps ensure compliance with regulatory requirements (e.g., DORA, ISO 27001), and protects against financial and reputational damage.

A penetration test is typically conducted in three phases. As part of the preparation, a scoping meeting and a kick-off meeting are held together with the client. Afterward, the technical execution begins with gathering information about the target systems, followed by the identification, analysis, and controlled exploitation of vulnerabilities. Finally, you will receive a final report containing the results and recommended measures. Optionally, the results can be reviewed in a final discussion. Throughout the entire project, we keep you informed with regular status updates and report critical findings immediately. Our experts use the same methods and techniques as real attackers do in order to reliably identify and thoroughly assess vulnerabilities under real-world conditions.

A part of a network penetration test, network components – such as servers, firewalls, services, and configurations – are checked for exploitable vulnerabilities. The goal is to identify attack vectors within the network and secure it by providing clear recommendations for action.

A part of a network penetration test, network components – such as servers, firewalls, services, and configurations – are checked for exploitable vulnerabilities. The goal is to identify attack vectors within the network and secure it by providing clear recommendations for action.

about the test object in advance, such as its architecture, source code, or access credentials. This allows vulnerabilities to be identified particularly efficiently and comprehensively – including those that are barely detectable from the outside.

A vulnerability scan identifies and prioritizes known vulnerabilities, usually automatically, and reveals which vulnerabilities theoretically exist. A penetration test goes a step further: vulnerabilities are manually verified and, if necessary, exploited in a controlled manner to demonstrate the actual damage an attacker could cause. In addition, it also uncovers unknown and logical vulnerabilities – such as errors in business logic or attack vectors that arise only through the combination of several individual findings and are not detected by automated scans. In short: A vulnerability scan checks the breadth, while a penetration test checks the depth.

A penetration test identifies and validates vulnerabilities in a defined environment. In Red Teaming, a realis-tic cyberattack is simulated, and an attempt is made to achieve defined objectives using the best possible attack path. It also assesses the organization’s defense, detection, and response capabilities. Learn more about the differences in our blog post “The Differences Between Penetration Test and Red Teaming”.

The number of reported cyber incidents in Switzerland has remained high for years. In 2025 alone, the Federal Office for Cybersecurity (BACS) received more than 64,000 reports of cyber incidents. A key factor in the success of many attacks is technical vulnerabilities that were not detected prior to the attack. Penetration tests help identify these risks early on.

Get a Penetration Testing quote now







Oneconsult Insights

Browse through exciting articles, the latest news and helpful tips & tricks from our experts on all aspects of cyber security.

Your security is our top priority – our specialists provide you with professional support.

Availability Monday to Friday 8:00 a.m. – 6:00 p.m (exception: customers with SLA – please call the 24/7 IRR emergency number).

Private individuals please contact your trusted IT service provider or the local police station.

For more information about our DFIR services here:

Oneconsult CSIRT Incident Response Hotline Emergency Number
Add CSIRT to contacts

Don’t miss anything! Subscribe to our free newsletter.