Penetration testing

Penetration testing and vulnerability assessment.

OBS discovers internet-facing assets, scans for known vulnerabilities and verifies findings through controlled manual penetration testing.

Why test

Manual testingvalidates identifiedvulnerabilities.

Automated scanning identifies known vulnerabilities across internet-available access points, web servers, applications and infrastructure.

OBS verifies scan findings through in-depth manual penetration testing using credentialed and non-credentialed attack techniques, then provides remediation guidance for confirmed vulnerabilities.

Assessment scope

Penetration testing scope.

The test scope is agreed against the target systems, network environment, applications and authorised testing methods.

  1. 01

    External and internal penetration testing

  2. 02

    Web application and website penetration testing

  3. 03

    Manual verification of identified vulnerabilities

  4. 04

    Intrusion detection and prevention system testing

  5. 05

    Password service strength testing

  6. 06

    Email security and VoIP testing

  7. 07

    Firewall, router, VPN and DMZ architecture review

  8. 08

    Server, database and application configuration review

  9. 09

    Data centre and third-party interconnection assessment

  10. 10

    Social engineering assessment using realistic scenarios

Engagement flow

Discovery, scanning, manual testing and remediation.

Rules of engagement, authorised targets, test methods, evidence handling and reporting are agreed before testing begins.

01

Discover

Identify internet-facing assets and potential entry points visible to a threat actor.

02

Test

Scan relevant access points, applications and infrastructure for known weaknesses.

03

Validate

Use manual, controlled attack techniques to confirm exploitability and business impact.

04

Strengthen

Deliver informed remediation guidance, priorities and a path to verification.

What you receive

Verified findings and remediation guidance.

01

Validated findings

Clear evidence of verified vulnerabilities, affected assets and relevant attack paths.

02

Risk and impact assessment

Technical severity considered alongside exposure, criticality and realistic operational consequence.

03

Prioritised remediation guidance

Practical, prioritised guidance to reduce risk and support verification after fixes are made.

Contact OBS

Request a penetration test or vulnerability assessment.

Provide the authorised target environment, systems in scope and required testing period.

Contact OBS