Manual Penetration Tests

Professional penetration testing - performed by hand, tailored to your application

Manual penetration tests performed by certified pentesters. Simulation of a real attack tailored to the specifics of your application – we determine the scope and model of testing individually during a kick-off meeting. Full report with evidence and CVSS categorization.

Individual pricing

Price depends on the scope of testing, number of applications, pentester time and depth of testing. Pricing in 48 hours from the form.

or 399 PLN net/msc

– continuous monitoring of people

PROCESS

The problem - why it matters

Automated scanners detect a significant number of common vulnerabilities – configuration errors, known CVEs, obvious vulnerabilities – and are a valuable, everyday security management tool. Manual pentest complements them where deeper analysis is needed: evaluation of application business logic, verification of authorization errors visible only after login, attack chains combining several vulnerabilities into one scenario. These are two different layers of protection, not competing services.
Manual penetration tests are the industry standard for mission-critical, financial, medical, e-commerce and any application that processes sensitive data. They are a prerequisite for ISO 27001, PCI DSS and SOC 2 certification. If your company is serious about cyber security, at some point manual pentesting will become a necessity.

PROCESS

How we work

Each pentest begins with a scoping arrangement (kick-off meeting), during which we jointly determine: what systems are in scope for testing, what model we want to address them in, what hours are allowed for testing, and the channel for emergency communication. We describe the specific methodology and tools used in a given project in the final report itself, with reference to recognized industry standards (OWASP, OSSTMM, PTES, among others).

Models of access to the system under test (to be agreed during the kick-off)

Each project is individual – we can test from the perspective of an external user, from the perspective of an authenticated account, or in a variant with access to documentation and code. The choice affects the scope of findings and the time of work. We agree on a specific model after analyzing your goals and limitations.

Typical scope of web application testing

OWASP Top 10 Class Vulnerability Categories

Injection, Broken Authentication, Sensitive Data Exposure and more.

Business logic of the application

Authorization errors between roles, parameter manipulation, race conditions

APIs and integrations

REST/GraphQL, token authentication, input validation

Configuration of servers and infrastructure supporting the application

Security mechanisms

Encryption, session management, password recovery mechanisms

solution

What you get

Each pentest ends with two separate reports – one for management and one for the technical team. This is the same standard we use for all our services, tailored to the specifics of manual testing.

Executive Summary Report (management, CTO)
A brief business summary of the test results. Number of critical, high, medium and low vulnerabilities found, top 3 business risks with PLN conversion, overall security maturity rating of the tested system.
Pentester's technical report (security team, developers)
Full description of each vulnerability found: context, reproduction steps (with payload fragments, if applicable), technical and business impact, direction of fix. Each finding classified according to CVSS 3.1 with justification. Format according to industry standards – ready to be handed over to the development team.
Demonstration of critical findings
For critical vulnerabilities, the report will include a proof of concept (PoC) – a brief description of how an attacker would exploit the vulnerability. We determine the format of the PoC individually with the customer during the kick-off – from a short description to a sanitized payload, depending on the maturity of the team receiving the report.
Re-test after repair (included in the price)
After the patches are deployed, we perform a re-test of critical and high findings – whether they have been successfully patched or have introduced new vulnerabilities. The re-test is a standard part of every test and is included in the pricing.
“As a user with the Editor role doing a URL modification from /api/posts/123 to /api/admin/users I can get the full list of database users. Criticality: High. Direction of fix: role verification on each API endpoint.”

How does it work?

Process in 5 steps

01

Pricing (48 hours)

You fill out the form, describe the application, specify the type of testing you want and your preferred date. You receive a quote in 48 business hours with a specific turnaround time.

02

Kick-off meeting (one-hour meeting)

Online with our lead pentester. We agree on the exact scope of testing, hours allowed for testing (if the application is sensitive to interruptions), emergency contact in case of an incident, requirements for test accounts.

03

Tests (5-15 working days depending on the scope)

Pentester works on a test environment (preferably staging – production only with explicit permission and strict limits). Daily communication via channel of choice (email, Slack), immediate reporting of critical findings.

04

Report + discussion of results
You receive a full report plus, depending on the option chosen, a written discussion of the findings or a video meeting with the person responsible for the project from our side. The form of the discussion is determined during the kick-off meeting, tailored to the client’s needs.

05

Re-test after repair (up to 30 days)
After implementing the recommendations, you report that you are ready for re-testing. Pentester verifies the effectiveness of the fixes – critical and high vulnerabilities are re-tested free of charge. You receive a short closing report with status confirmation.
solution

Individual pricing - what does it depend on?

Manual penetration tests are priced by the pentester’s time. The main factors affecting pricing:

Type of application
Web, mobile, API, web, combination
Functional complexity
Number of modules, roles, types of rights, integrations
Agreed access model and depth of testing
Certification verification requirements (if applicable)
Some standards require extended documentation
Require pentester availability during off-hours (e.g., for 24/7 applications)

You will receive a specific quote with a proposed schedule after completing the inquiry form. In response, we also offer a kick-off meeting, where we clarify the scope together before starting the work.

Manual penetration testing is performed by our CISO and a trusted third-party vendor (certified pentester with OSCP/OSCE). Each test is personally supervised by our CISO; the customer always receives a single, unified report signed by Ragnar Shield.

Who this service is for

Manual penetration testing is essential for business-critical, financial, medical, e-commerce applications above a certain scale, and any application that processes sensitive or personal data. Standardly required by ISO 27001, PCI DSS, SOC 2 verifications, and increasingly by large corporate customers as a condition of signing a contract.

Recommended to perform the pentest once a year and after any significant application change (new module, integration with a partner, architectural migration). For advanced security teams – also after major infrastructure changes or after a security incident, as verification that the vulnerability has been successfully patched.

Frequently Asked Questions (FAQ)

Can testing harm my application?

Normally, we perform testing on a staging or test environment that is separate from production. If for some reason it is necessary to test on production (rarely), we agree on strict limits – hours allowed, load limits, emergency contact on both sides. A manual pentest is much more careful than an automated scan – the pentester understands where verification ends and the risk of data destruction begins.

We have a procedure to follow: the pentester immediately withdraws, documents the situation without tampering with the evidence, contacts our CISO and you. Together we decide on the next steps (report to CERT, to the supervisory authority, etc.). The pentester is immediately suspended for clarification.

Yes. Our CISO holds CISSP-ISSMP, CISM, CISA certifications, and ISO 27001 and ISO 42001 verification. The third-party pentester working with us has an OSCP (Offensive Security Certified Professional) and years of experience in enterprise application testing.

Yes. We prepare reports in accordance with the requirements and expectations of certification verifiers. The format includes all required elements: test scope, methodology, CVSS classification, evidence, recommendations, re-test status. The report can be an attachment to the verification documentation.

Ragnar Shield diagnoses and reports, but does not provide implementation services – this principle also applies to pentests. This ensures that the report is unbiased: we have no interest in artificially increasing the number of findings. If you need a partner to fix vulnerabilities found, we will recommend a trusted entity from our network.

Limitations of the service (disclaimer)

A manual pentest, while much deeper than an automated scan, does not guarantee detection of all vulnerabilities – by nature, each testing method has its limitations. The test covers only the scope agreed upon before it is started; vulnerabilities outside the scope are not detected. Each test is performed on the basis of written permission from the infrastructure owner – the customer declares that he has the authority to order the tests. Full scope of limitations in the Terms and Conditions.
offer

Packages and related services

Manual penetration tests are most often ordered together with:
Cyber Monitoring & Scanning

249,00 

Comprehensive diagnosis: technology + people

Verification of Regulatory Compliance

499,00 

Checks the company’s obligations as a result of detected leaks

Application Code Security

Static code analysis complements testing of a running application

Let's test your application together

Quote in 48 hours. Re-test after repair included.

Verification-compliant report.

Pricing of Manual Penetration Tests - we respond in 48 hours

Each pentest is individual – pricing depends on the type of system to be tested, the scope and the chosen methodology. Fill out the form and within 48 hours you will receive a specific offer with price and completion date. We sign an NDA on request before any exchange of details.

Pricing of Manual Penetration Tests - we respond in 48 hours

Each pentest is individual – pricing depends on the type of system to be tested, the scope and the chosen methodology. Fill out the form and within 48 hours you will receive a specific offer with price and completion date. We sign an NDA on request before any exchange of details.