Penetration Testing (Pentest) for Businesses

    Art:

    Type:

    Basis:

    Check. Secure. Create trust.

    Cyber attacks today often hit companies unexpectedly – and with serious consequences. Missing tests, outdated systems or undetected vulnerabilities open the door to attackers. The result: data loss, business interruptions and reputational damage.

    A penetration test from SAVECALL shows where your company is actually vulnerable. Our certified ethical hackers simulate real attack scenarios, check systems, applications and networks and provide specific recommendations for action. This allows you to identify risks before they are exploited – and at the same time meet regulatory and legal requirements.

    Awards for Outstanding Performance

    Vodafone Business Partner Platin
    Vodafone Business Partner Gold
    Versatel championsfly award
    Plusnet loyalty award
    Placetel gold partner
    MNet platin partner
    Ecotel rising star
    Ecotel partner of the year
    Ecotel diamond partner
    Colt international partner advisory board
    Colt innovation award
    Colt european partner of the year
    Colt arr performance award
    Avaya Cloud Partner Award
    Ecotel loyalty award

    Explained by experts:

    Features of a pentest

    Vendor Overview

    Voiceworks, carrier partner of SAVECALL Telecommunications Consulting
    Vodafone, carrier partner of SAVECALL Telecommunications Consulting
    Verizon, carrier partner of SAVECALL Telecommunications Consulting
    Tata Communications, carrier partner of SAVECALL Telecommunications Consulting
    Arelion, carrier partner of SAVECALL Telecommunications Consulting
    becom, carrier partner of SAVECALL Telecommunications Consulting
    byon, carrier partner of SAVECALL Telecommunications Consulting
    Lumen, carrier partner of SAVECALL Telecommunications Consulting
    MetTel, carrier partner of SAVECALL Telecommunications Consulting
    expereo, carrier partner of SAVECALL Telecommunications Consulting
    Epsilon, carrier partner of SAVECALL Telecommunications Consulting
    ecotel, carrier partner of SAVECALL Telecommunications Consulting
    CrowdStrike, technology partner of SAVECALL Telecommunications Consulting
    NFON, carrier partner of SAVECALL Telecommunications Consulting
    Nitel, carrier partner of SAVECALL Telecommunications Consulting
    NorthC, carrier partner of SAVECALL Telecommunications Consulting
    Telefónica, carrier partner of SAVECALL Telecommunications Consulting
    Sprint, carrier partner of SAVECALL Telecommunications Consulting
    Deutsche Telekom, carrier partner of SAVECALL Telecommunications Consulting
    Telstra, carrier partner of SAVECALL Telecommunications Consulting
    BT Group, carrier partner of SAVECALL Telecommunications Consulting
    Avaya, technology partner of SAVECALL Telecommunications Consulting
    AudioCodes, technology partner of SAVECALL Telecommunications Consulting
    Aryaka, technology partner of SAVECALL Telecommunications Consulting
    1&1 Versatel, carrier partner of SAVECALL Telecommunications Consulting
    Zscaler, technology partner of SAVECALL Telecommunications Consulting
    TPX, carrier partner of SAVECALL Telecommunications Consulting
    China Telecom, carrier partner of SAVECALL Telecommunications Consulting
    Cisco, technology partner of SAVECALL Telecommunications Consulting
    Colt, carrier partner of SAVECALL Telecommunications Consulting
    Dacoso, technology partner of SAVECALL Telecommunications Consulting
    Deutsche Telefon, carrier partner of SAVECALL Telecommunications Consulting
    Equinix, carrier partner of SAVECALL Telecommunications Consulting
    Magenta Business, carrier partner of SAVECALL Telecommunications Consulting
    hypercore, carrier partner of SAVECALL Telecommunications Consulting
    GTT, carrier partner of SAVECALL Telecommunications Consulting
    GasLINE, carrier partner of SAVECALL Telecommunications Consulting
    Fuze, technology partner of SAVECALL Telecommunications Consulting
    euNetworks, carrier partner of SAVECALL Telecommunications Consulting
    Masergy, carrier partner of SAVECALL Telecommunications Consulting
    Microsoft, technology partner of SAVECALL Telecommunications Consulting
    M-net, carrier partner of SAVECALL Telecommunications Consulting
    NGN, carrier partner of SAVECALL Telecommunications Consulting
    noris network, carrier partner of SAVECALL Telecommunications Consulting
    NorthC, carrier partner of SAVECALL Telecommunications Consulting
    NTT, carrier partner of SAVECALL Telecommunications Consulting
    Riedl, carrier partner of SAVECALL Telecommunications Consulting
    RETN, carrier partner of SAVECALL Telecommunications Consulting
    Plusnet, carrier partner of SAVECALL Telecommunications Consulting
    Placetel, carrier partner of SAVECALL Telecommunications Consulting
    Pan Dacom, technology partner of SAVECALL Telecommunications Consulting
    Orange, carrier partner of SAVECALL Telecommunications Consulting
    Scaltel arbeitet mit SAVECALL als Partner für IT- und Netzwerklösungen.
    Seebauer ist Partner von SAVECALL im Bereich Business Solutions und Netzwerktechnologien.

    Delighted customers

    Scope and selection

    A pentest protects your company, fulfills regulatory and legal requirements and provides reliable evidence.

    Many companies are subject to requirements, such as those of BaFin, and process personal data in compliance with the GDPR. A pentest is essential for this. The earlier vulnerabilities are identified and remedied, the lower the probability of a successful attack. You decide whether white box, black box or grey box is appropriate. The process includes target definition, information exchange, exact framework conditions, implementation with or without time coordination as well as evaluation and presentation of the results. After closing the gaps, a further test is recommended.

    Customers

    ZVEI e.V. – German Electro and Digital Industry Association, customer of SAVECALL Telecommunications Consulting
    TotalEnergies, customer of SAVECALL Telecommunications Consulting
    TELUS, customer of SAVECALL Telecommunications Consulting
    Social Chain, customer of SAVECALL Telecommunications Consulting
    smava, customer of SAVECALL Telecommunications Consulting
    Sivantos, customer of SAVECALL Telecommunications Consulting
    Sanacorp, customer of SAVECALL Telecommunications Consulting
    Nippon Seiki, customer of SAVECALL Telecommunications Consulting
    MWB, customer of SAVECALL Telecommunications Consulting
    MSC, customer of SAVECALL Telecommunications Consulting
    Kraftanlagen München, customer of SAVECALL Telecommunications Consulting
    McDermott, customer of SAVECALL Telecommunications Consulting
    Magna, customer of SAVECALL Telecommunications Consulting
    LV 1871, customer of SAVECALL Telecommunications Consulting
    Lebenswege, customer of SAVECALL Telecommunications Consulting
    Korian, customer of SAVECALL Telecommunications Consulting
    Kekst CNC, customer of SAVECALL Telecommunications Consulting
    Käuferportal, customer of SAVECALL Telecommunications Consulting
    item, customer of SAVECALL Telecommunications Consulting
    Ingram, customer of SAVECALL Telecommunications Consulting
    ILF Consulting Engineers, customer of SAVECALL Telecommunications Consulting
    Hyatt, customer of SAVECALL Telecommunications Consulting
    Heinrich-Böll-Stiftung, customer of SAVECALL Telecommunications Consulting
    Fressnapf, customer of SAVECALL Telecommunications Consulting
    Financial.com, customer of SAVECALL Telecommunications Consulting
    Contora, customer of SAVECALL Telecommunications Consulting
    Cognizant, customer of SAVECALL Telecommunications Consulting
    Bitmarck, customer of SAVECALL Telecommunications Consulting
    AVIA, customer of SAVECALL Telecommunications Consulting
    Aurelius, customer of SAVECALL Telecommunications Consulting
    Almeda, customer of SAVECALL Telecommunications Consulting
    Allianz Handwerker Services, customer of SAVECALL Telecommunications Consulting
    Allianz Global Assistance, customer of SAVECALL Telecommunications Consulting
    Allianz, customer of SAVECALL Telecommunications Consulting
    Advantest, customer of SAVECALL Telecommunications Consulting
    Satellite Office, customer of SAVECALL Telecommunications Consulting
    Börsen AG, customer of SAVECALL

    Penetration test for companies

    Ethical hacker in front of several monitors with security data - symbolic image for professional penetration tests in companies.

    Why carry out a penetration test?

    A pentest is essential to protect your company against attacks and to meet regulatory and legal requirements.

    How does a pentest work?

    The aim is to attack your IT systems externally in an organized, targeted and approved manner. The workshop will determine in advance exactly what is to be checked and the extent of the attack.

    There are three types

    • White box with complete information and close coordination.
    • Black box without prior information, particularly realistic and meaningful.
    • Grey Box with only necessary basic data such as domain or IP address space, very efficient.

    How does the pentest work?

    Definition of objectives and framework conditions, exchange of relevant information, implementation, evaluation and presentation with proposed solutions. After closing the gaps, a retest is useful. A pentest shows the current status and should be repeated cyclically.

    Security areas

    Why

    Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

    What drives you forward – & what drives

    Book a free expert consultation

    Pentest – FAQs

    What is a penetration test and how does it differ from a vulnerability scan?

    A penetration test (pentest) is an authorised, simulated cyber attack on a company’s IT infrastructure to uncover real vulnerabilities before actual attackers exploit them. An automated vulnerability scan lists known weaknesses based on signatures without actively exploiting them. A penetration test goes further: ethical hackers combine multiple vulnerabilities into an attack path, test security measures under real conditions and deliver concrete attack demos as proof. For NIS2 and ISO 27001, a pentest is often mandatory and a scan alone is insufficient.

    Which types of penetration tests exist for businesses?

    There are four main types. Network pentest checks external and internal network infrastructure for vulnerabilities in firewalls, switches and servers. Web application pentest analyses web applications for OWASP Top 10 vulnerabilities such as SQL injection, cross-site scripting and authentication flaws. Cloud security assessment checks cloud configurations on AWS, Azure or Google Cloud for misconfigurations and access risks. Social engineering test simulates phishing attacks and checks how many employees fall for fake emails. SAVECALL recommends the right pentest type based on your risk profile

    When do businesses need a penetration test?

    A penetration test is necessary before launching new critical applications or IT systems, after major infrastructure changes such as cloud migration or SD-WAN rollout, to meet compliance requirements under NIS2, ISO 27001, GDPR or TISAX, after a security incident for root cause analysis, and as a regular security review (recommended annually or semi-annually). Companies that have never had a pentest typically have critical vulnerabilities they are unaware of. Ignorance does not protect against liability under NIS2.

    What does a penetration test cost for businesses?

    Costs depend on scope, depth and test target. A network pentest for a mid-sized company with up to 50 systems costs 3,000 to 8,000 euros. A web application pentest for a complex application ranges from 4,000 to 12,000 euros. A comprehensive red team assessment with social engineering, physical access and multi-day attack scenario costs 15,000 to 40,000 euros. Annual vulnerability assessments as a more affordable complement start at 1,500 euros. SAVECALL coordinates certified pentest partners (OSCP, CREST) and manages the entire procurement process.

    How does a penetration test work in practice?

    A professional penetration test follows five phases. Scoping and engagement (1 to 2 weeks): definition of targets, test scope, time window and legal authorisation by the client. Reconnaissance (passive and active): information gathering about the target system without direct attack. Exploitation: active exploitation of found vulnerabilities under controlled conditions. Post-exploitation: testing how far an attacker can advance after initial access. Reporting: detailed report with executive summary, technical findings by criticality and concrete recommendations. SAVECALL supports from scoping through to remediation of findings.

    What happens after the penetration test with the vulnerabilities found?

    After the pentest you receive a detailed report with all findings prioritised by criticality (critical, high, medium, low), proof screenshots or exploit demos, CVSS scores and concrete remediation recommendations per vulnerability. SAVECALL supports prioritisation and coordinates remediation with your IT teams or service providers. After remediation, we recommend a retest that specifically re-checks the fixed vulnerabilities. For compliance documentation (NIS2, ISO 27001), we provide pentest-compliant reporting.