The regulatory context
Cyber attacks are no longer the preserve of large organisations. Ransomware, credential theft, business email compromise and attacks that arrive through suppliers regularly hit SMEs, often exploiting vulnerabilities that have been known for months and never fixed. The question the board should ask is not whether the company is exposed, but how exposed, from where and with what consequences.
Legislation has caught up with this reality. Article 32 of the GDPR requires security measures appropriate to the risk and expressly names, among those to be adopted where appropriate, a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. The NIS2 Directive, transposed into Italian law by Legislative Decree 138/2024, requires essential and important entities to adopt cyber security risk management measures and to assess their effectiveness (Article 24), with direct responsibilities for the management bodies (Article 23). Technical specifications and deadlines are set by the Agenzia per la Cybersicurezza Nazionale (ACN, the Italian national cyber security agency), which oversees implementation.
ISO/IEC 27001:2022 includes among its controls the management of technical vulnerabilities (A.8.8) and security testing in development and acceptance (A.8.29), both to be reviewed as part of the periodic monitoring of the system. In the financial sector, the DORA Regulation introduces a periodic programme of digital operational resilience testing.
Our approach
A security test is only as good as its preparation. That is why the first stage is always defining the scope: we establish with the company which systems genuinely matter to the business, which data must be protected and which activities cannot be interrupted. These choices determine the breadth of the testing, the type of test and the rules of engagement, which are formalised in a written authorisation and covered by a confidentiality agreement.
We keep the two exercises clearly distinct. The vulnerability assessment is a broad and repeatable picture: systematic scanning, manual verification of the results, classification with CVSS. The penetration test is an in-depth investigation: controlled exploitation of the vulnerabilities in order to measure the actual consequences of an attack, with a black, grey or white box approach depending on how much we know about the systems at the outset. We follow recognised methodologies (PTES, NIST SP 800-115, OSSTMM) and, for applications, the OWASP standards.
Beyond the areas described above, where the context calls for it we extend the testing to OT and IoT environments and, for more mature organisations, to red team exercises that put the whole detection and response capability to the test. The work does not end with the report: the retest and hands-on support with remediation are part of the engagement.
What sets our service apart
- Two levels of detail: an executive report that management can read and act on, and a technical report with instructions that IT can follow without ambiguity.
- Integration with compliance: we link the test findings to the requirements under the GDPR, NIS2 and ISO/IEC 27001, so that one exercise answers several obligations and leaves evidence that can be used in audits and certifications.
- Findings verified by hand: every vulnerability flagged by automated tools is confirmed manually, false positives are removed and what remains is documented with proof of concept and a CVSS score.
- Support through to closure: we do not stop at a list of problems; we stay alongside the technical teams until the vulnerabilities have been fixed and verified.