Clients who trust us
Why organisations choose CommSec first
Manual, CREST-accredited testing you can stand behind
A penetration test is a controlled simulation of a cyber attack against your systems, applications, or network, designed to uncover the vulnerabilities caused by misconfigurations, software flaws, or gaps in your processes and controls.
At CommSec, our CREST-certified penetration testers bring over a decade of experience to every engagement. We go beyond automated vulnerability scanning, testing your environment the way a real attacker would, then giving you clear, actionable findings that support your wider security strategy, not just your compliance checklist.
Many organisations discover too late that not all pen tests are the same. You need a testing partner who delivers depth and value, not a compliance tick-box exercise or just a vulnerability scan.
Get a Quick Quote
Penetration Testing Types
We offer a full range of penetration testing service for your organisation. Contact us for a full list of security testing services.
Pen Testing Service Methodology
Our methodology follows a six-step process that helps us ensure a thorough and effective evaluation of a client’s security posture.
- The first step is Pre-engagement & scoping, where we define the scope and objectives of the engagement, identify the assets to be tested, and agree on the testing methodology. This helps ensure that the engagement stays on track and the client’s expectations are met.
- Next is Intelligence Gathering, where we gather as much information as possible about the target network or application. This includes information about the technology used, the employees who have access to it, and any potential vulnerabilities.
- The third step is Vulnerability Analysis, where we use automated tools and manual techniques to identify vulnerabilities that could be exploited by attackers. We then prioritize these vulnerabilities based on their severity and the risk they pose to the client’s business.
- Once vulnerabilities are identified, we move on to the fourth step, Exploitation, where we attempt to exploit these vulnerabilities to gain unauthorized access to the target system. This helps us determine if the vulnerabilities can be exploited in a real-world scenario.
- The fifth step is Post Exploitation, where we assess the level of access we were able to obtain and explore the target system further to identify any additional vulnerabilities or weaknesses.
- Finally, we provide a comprehensive report in the Reporting step that includes our findings, recommendations for remediation, and a detailed breakdown of our testing methodology. This report helps the client understand their security posture and provides them with actionable steps to improve it.
Recent Client Feedback
Pen Testing Certifications
Our experienced team possesses the skills and experience to identify the latest threats. The teams certifications include:
- CREST (Globally recognised as the best certification for penetration testing)
- OSCP (Penetration Testing with Kali Linux) & OWSP (Foundational Wireless Network Attacks)
- GWAPT (Web app – SANS)
- CISSP (Certified Information Systems Security Professional -ISC2)
- CEH (Certified Ethical Hacker – EC Council)
Not sure where to start?
Download our guide to penetration testing for compliance ebook
No form fill required.
Penetration Testing for Your Compliance Requirement
Different frameworks ask for different proof. Find your requirement below to see what it demands and how a CommSec penetration test satisfies it.
ISO 2700
ISO 27001 requires evidence that your technical controls are tested regularly as part of your Information Security Management System. A CommSec penetration test gives your auditor independent evidence for Annex A control testing, not a self-assessment. See ISO 27001 Assessment
SOC 2
Clients and auditors increasingly expect SOC 2 vendors to show regular, independent security testing under the Security trust principle. Our penetration test report gives you that evidence, ready to include in your audit pack.
PCI DSS
PCI DSS requires an annual penetration test of your cardholder data environment, plus a retest after any significant change. We scope and run PCI-aligned tests, with reporting suited to QSA review.
DORA
Financial entities in scope for DORA must run digital operational resilience testing, and penetration testing is one of the core methods named in the regulation. Our DORA page sets out what is in scope and when testing is required.
NIS2
Organisations newly in scope for NIS2 must demonstrate that their risk management measures actually work. Penetration testing is a direct, evidenced way to show this. Our NIS2 page explains the current implementation timeline.
CyFun
Ireland’s CyberFundamentals framework requires organisations to validate their assurance level through independent testing appropriate to their tier. We scope our tests to match your Basic, Important, or Essential CyFun level. See Cyfun Assessment
Watch the Video
The Difference Between Penetration Testing and Vulnerability Scanning
FAQ's
What is Penetration Tesing?
Penetration testing, also known as pen testing, is a process of assessing the security of a system, network, or application by simulating real-world cyber-attacks to identify vulnerabilities that could be exploited by malicious actors.
Why is Penetration Testing so important?
Penetration testing is important as it helps organisations to identify and mitigate security vulnerabilities before attackers exploit them. It can also help organisations to comply with regulatory compliance requirements, cyber insurane prequalification, or meet industry standards.
Who should conduct penetration testing?
Penetration testing should be conducted by trained and experienced professionals who have the necessary knowledge and skills to identify and exploit security vulnerabilities.
How often should a penetration test be conducted?
The frequency of penetration testing depends on various factors such as the size of the organisation, the complexity of the systems and networks, and the industry regulations. In general, organizations should conduct penetration testing at least once a year or after significant changes to the systems and networks.
What types of penetration testing are there?
There are various types of penetration testing, including external network penetration testing, internal network penetration testing, web application penetration testing, wireless penetration testing, phishing penetration testing, IT health check, and ethical hacking.
What are the steps involved in a penetration testing process?
The penetration testing process typically involves five stages: reconnaissance, scanning, gaining access, maintaining access, and covering tracks.
Will penetration testing disrupt normal business operations?
Penetration testing may cause some disruption to normal business operations, especially during the initial stages of the testing process. However, professional penetration testing services should be conducted with minimal disruption to normal business operations.
What is the difference between a vulnerability assessment and penetration testing?
A vulnerability assessment is a process of identifying and documenting potential security vulnerabilities in a system, network, or application. Penetration testing goes a step further and attempts to exploit the identified vulnerabilities to determine their impact on the system or network.
What happens after a penetration test is conducted?
After a penetration test is conducted, the results are documented in a report that outlines the vulnerabilities that were identified and the recommended remediation measures. The organisation can then use this report to prioritise and address the identified vulnerabilities.
How can organisations ensure the effectiveness of penetration testing?
Organisations can ensure the effectiveness of penetration testing by selecting a reputable and experienced testing provider, defining clear testing objectives, establishing a clear scope of work, and monitoring the testing process to ensure that it is conducted in a safe and controlled manner.
