SMEs & Critical Infrastructure

Penetration Testing for SMEs and Critical Infrastructure

30 tests for 19 clients since 2023, from ECUs to web applications

Rear of an SUV with visualized parking sensors in front of a bollard
30tests for 19 clients since 2023

Project

SMEs & Critical Infrastructure · Cyber & Compliance

  • 19 companies from energy, aviation, mechanical engineering, software, healthcare billing and telecommunications
  • Recon, black box, gray box, white box; web, infrastructure, Active Directory, ECUs and hardware
  • Own pentesters and partners under Emposo leadership, permission to attack as a contract annex
  • 23 orders since 09/2023, €4,000 to €26,000 per test
  • fixed price since 2024
  • Report and retest

Challenge

  • Regular testing with a reliable report, but no in-house offensive security team
  • ECUs and hardware need different methods than web applications
  • Results must be prioritized and verifiable in the retest

Solution

  • Scoping per environment, type of test by question
  • Own pentesters, with partners specialized in ECUs and hardware under Emposo leadership
  • Report with prioritized measures and explanations, evidence deleted after 90 days
  • Retest after remediation, annually for repeat clients

Result

  • 30 orders for 19 clients in three years, three repeat clients
  • ECU pentest for a mechanical engineering group, critical infrastructure tests in energy and aviation
  • Fixed-scope contract clients commission the pentests in addition

Cyber & Compliance

Your next step

Get in touch now!

Whether you have a concrete project, need initial guidance or have other questions: tell us briefly what it is about.

Discuss your project