Cybersecurity › Security Testing
Security Tests

Someone is testing your IT.
You'd better decide who.

We simulate attacks on your systems under controlled conditions, using the same methods as real attackers. The result is not a scan report, but a plan prioritized by urgency.

Manual testing instead of just scans

The Problem

Most vulnerabilities aren't noticed un
until someone has exploited them.

Until then, an attacker often has access for weeks. A test conducted under controlled conditions reveals in advance where you are vulnerable.

Scanners only see what they're familiar with

Automated tools can identify gaps for which an entry already exists. Only a human can identify attack vectors that arise only through the combination of several small errors.

Reports in no particular order

A list of sixty findings doesn't help anyone. What matters is determining what needs to be addressed first and what can wait.


's Journey Through the Front Door

A firewall doesn't prevent someone from walking into the office and plugging in a USB drive. Physical security is the most commonly overlooked area.

Penetration Tests

Search systematically, sort by urgency at
.

We use the same methods that attackers employ. No automated runs—instead, our testers combine techniques and follow up wherever a vulnerability is found.

Network

From the outside and the inside, including the firewall, VPN, and accessible services.

Web and Interfaces

Applications and programming interfaces, including errors in business logic.

Cloud

Microsoft 365, Azure, AWS, and Google Cloud, including permissions and access rights.

Active Directory

Expansion of Permissions, Registration Process, and Paths from User to Administrator.

Preparation
  • Jointly Define the Scope and Objectives
  • Written Authorization Before the Test Begins
  • Emergency Contact for Immediate Reports
Implementation
  • Manual testing based on recognized process models
  • Critical findings are reported immediately
  • Every step is thoroughly documented
Result
  • Report with supporting documentation for each finding
  • Measures Sorted by Risk and Effort
  • Follow-up test included
Scanners and People

What a tool finds,
, and what a tester actually sees.

Area
Automatic Scan
Manual Test
Known Vulnerabilities
reliably identifies published vulnerabilities
also examines whether they can be exploited in the specific case
Chaining
evaluates each find on its own merits
combines several minor flaws into a single attack vector
Business Logic
does not detect any technical errors
finds ways to access third-party data without exploiting a vulnerability
Expansion of Rights
reports unusual configurations
Does it actually go all the way to the administrator account?
Rating
Points According to the Catalog
Assessment of what this means for your company

It's easy to know the gap.
But it's not easy to know which one comes first.

Each finding is accompanied by information on the level of risk and the extent of the work required to resolve it. This determines which issues are addressed first.

Procedure

What happens and when.

From the initial assignment to the follow-up test. You'll know exactly what we're working on and what's coming next at every step of the way.

Scope and Engagement

Together, we determine what will be tested, which methods will be used, and over what time frame. Written approval is required before testing begins.

1–2 days

Research and Analysis

We gather information, assess the attack surface, and identify initial points of entry.

1–3 days

Utilization and Expansion

Any vulnerabilities we find are manually exploited and investigated further. We report critical findings immediately, without waiting for the report.

2–5 days

Report and Discussion

You will receive the report, which includes detailed findings for each item and an action plan, along with a personal discussion of the results.

2–3 days

Retest

Once the issue has been resolved, we'll check to see if the measures are actually effective. This is part of the service, not an additional assignment.

including
Red Teaming

Don't just audit one system—
—but the entire company.

Red teaming goes beyond a penetration test. It focuses on a specific target rather than a list of systems, and it also tests whether anyone would notice the attack.

Penetration Test

Estimated duration: one to two weeks

Specified systems are systematically checked for technical vulnerabilities. Your IT department is aware of this.

  • Designated area, previously defined
  • Identifies technical vulnerabilities and attack vectors
  • The result is an action plan
Red Teaming

Open-ended duration, several weeks

We are working toward a goal and combining technical, human, and physical approaches. Only management and one contact person are aware of this.

  • A combination of phishing, exploits, and physical access
  • Also check how quickly your team responds
  • The goal is a concrete system, not a list
Physical Security


's blind spot is usually on the ground floor.

We test how far an unauthorized person can get: into the building, into the server room, to an available network port. This service can also be booked individually.

Additions

Entrance, reception area, side entrances, underground parking garage, and secure areas.

On-site presence

Whether you're a technician, a vendor, or a new colleague: How far can a plausible story take you?

Prepared Devices

Media that have been laid out, along with an analysis of how often they were infected.

Behavior Inside the House

Reactions to strangers, open screens, documents on desks.

Why ITanic

Tested, fixed,
tested again.

A test that only generates a report is not complete. We follow up until the issue has been verified as resolved.

Follow-up test always included

Once the issue has been resolved, we'll check again—without any additional budget and without a new order.

Every finding with supporting evidence

A risk assessment, clear documentation, and a specific recommendation. Not just a list of identifiers.

Results remain in Austria

Medical findings, login credentials, and system information are transmitted in encrypted form and stored exclusively in Austria.

Suitable for audits

The reports are structured in such a way that they can be used to provide evidence to auditors and insurance companies.

Frequently Asked Questions

What should be clarified beforehand.

What is the difference between a penetration test and a vulnerability scan?

A scan automatically lists known vulnerabilities. During a penetration test, our testers attempt to actually exploit these vulnerabilities, chain them together, and go further. This reveals attack paths that no tool can detect.

How long does a test take?

That depends on the scope. A web application test typically takes three to five days, while an internal infrastructure test takes five to ten days. Red Teaming takes four to eight weeks. We’ll determine the exact timeframe together in advance.

Is the follow-up test really included?

Yes. After the issue is resolved, we'll check to see if the measures are effective. That's an integral part of the service.

Could our systems be damaged by the test?

We agree in advance exactly which actions are permitted. Destructive tests, such as deleting data, are never part of the scope. If anything is unclear, we pause and ask for clarification.

Does our IT department know about red teaming?

That's up to you. Typically, only management and a single contact are aware of this, so that the detection can be tested under realistic conditions.

Can I request an on-site test separately?

Yes, it can be booked separately. Many customers even start with this option because this area is checked the least often, and the results are often surprising.

How often should we test?

Once a year as a general rule, and additionally following major changes such as the implementation of new systems, a move to the cloud, or an acquisition, as well as before upcoming audits.

Where are test data and reports stored?

Exclusively in Austria, encrypted, and without any U.S. providers. Upon request, we will delete all data completely upon project completion.

Gaps found. And who will notice the next attempt?

A test is a snapshot. Detection requires someone who pays close attention over the long term.

View Detection & Response

Ready for a controlled
attack on your systems?

In thirty minutes, we'll determine which test is appropriate for your situation and what it entails.

Free and with no obligation30 minutes, focusedA specific offer will follow