Cloud, Security & Operations
Penetration Testing
Manual, intelligence-led attacks on your applications, networks and cloud accounts by testers who chain weaknesses together to show what a real attacker could reach.
Capability overview
What penetration testing involves
Penetration testing goes beyond scanner output. Testers work through an application or network the way an attacker would, combining small weaknesses, such as a verbose error message and a weak password policy, into a path to sensitive data or administrative control.
Tests follow published methods, the OWASP Web Security Testing Guide for applications and the Penetration Testing Execution Standard for infrastructure, and every finding includes reproduction steps and evidence. Rules of engagement are signed before any testing starts.

What is included
Types of penetration test
Web application testing
Authentication, session handling, access control, business logic and injection testing across user roles, including tests an automated scanner cannot perform.
API testing
REST and GraphQL endpoints tested against the OWASP API Security Top 10, with particular focus on broken object level authorisation.
External and internal network testing
Perimeter services and internal Active Directory environments tested for paths to domain administrator.
Cloud configuration testing
AWS, Azure or Google Cloud accounts reviewed for over-permissive roles, exposed storage and privilege escalation paths.
How we work
How we deliver penetration testing
Scoping call
Targets, test accounts, exclusions and testing windows agreed, and a black, grey or white box approach chosen.
Reconnaissance
Public information, subdomains, technology fingerprints and exposed documentation mapped before active testing begins.
Active testing
Manual exploitation attempts supported by tools such as Burp Suite, with critical findings reported the same day rather than at the end.
Reporting
An executive summary for leadership and a technical report with CVSS ratings, evidence and specific fixes for developers.
Retest
Fixed issues retested within the agreed period and a closure letter issued for customers or auditors who ask for proof.
Related capabilities
Related capabilities in Cybersecurity
Web Application Security
Protection for live websites and web applications: hardened configuration, a tuned web application firewall, bot and abuse controls, and fixes for OWASP Top 10 weaknesses in production.
Application Security
Security built into how your software is designed, coded and released: threat modelling, secure code review, SAST and dependency scanning in the pipeline, and developer training.
API Security
Discovery, testing and protection of the APIs behind your mobile apps, partner integrations and microservices, focused on the authorisation flaws attackers exploit most.
Cloud Security
Security posture management for AWS, Azure and Google Cloud: identity and permissions, network exposure, logging, encryption and guardrails that stop misconfigurations before they reach production.
Explore further
Explore connected pages
Related services
Related solutions
Cloud Transformation Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Cybersecurity Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Managed Technology Solutions
Quality, infrastructure, managed services and dedicated team solutions. Acmez shapes managed…
Where this applies
Healthcare & Life Sciences
Technology systems for regulated environments where privacy, auditability and continuity…
Manufacturing & Industrial
Connected operations, asset, field, supply chain and industrial platforms for complex operating…
Banking, Financial Services & Insurance
Technology systems for regulated environments where privacy, auditability and continuity…
E-Commerce
Digital platforms for customer experience, operations, commerce, content, marketing and service…
Questions & answers
Questions about Penetration Testing
Cannot find what you need? Our team responds to technical and commercial questions within one business day.
Ask a questionA single web application with a few user roles usually needs five to ten testing days. An internal network test for a mid-sized office typically takes one to two weeks, plus reporting time.
Testing is designed to avoid disruption. Denial of service attacks are excluded by default, risky tests are agreed in advance and a named contact is available throughout the test window.
Each test is quoted as a fixed price based on the number of testing days required for the agreed scope. The retest of fixed findings is included in that price.
Yes. Alongside the full technical report we can issue a shorter attestation letter that confirms scope, dates and remediation status without exposing exploit details, which suits customer security questionnaires.
Next step
Discuss penetration testing with Acmez
Share what you need to change, build, integrate or support. We will map the practical next step.