Skip to content
English

Frequently Asked Questions

n this page, you’ll find answers to common questions about our services. If you don't find what you're looking for, feel free to reach out to us.

Tip: Check out our buyer's guide to cybersecurity for practical insights to help you make informed decisions.

Penetration Testing & Testing Projects

Why should the test environment be frozen during testing?

It is recommended not to make changes to the environment during testing so that findings can be reliably identified and the test results remain comparable. This also prevents situations where changes affect test quality or cause false observations.

Can changes be made to the system during testing?

Changes should be avoided during testing. If changes are necessary, they should be agreed upon in advance with the testers so that their impact on the testing can be taken into account.

Is the client's technical team required to join the testing project?

Involving the technical team speeds up the project and helps ensure that the target and scope of the testing are correctly understood. However, they do not need to actively participate in the actual execution of the testing.

Does a technical expert or product owner need to attend the kick-off meeting?

We strongly recommend having at least one person present who is familiar with the technical implementation or business goals of the system. This allows any questions and scope boundaries to be handled efficiently right at the start of the project.

What happens in the testing kick-off meeting?

In the kick-off meeting, we review the testing objectives, confirm the target scope, schedule, contact persons, potential risks, and practical procedures. This ensures that all parties share a common understanding of the project.

How should we prepare for security testing?

Usually, defining the target of the testing, identifying the necessary contact persons, and granting any required access permissions is sufficient. We will review all preparations in the kick-off meeting and help you collect the necessary information.

How quickly can we start the project?

The project start date depends on the nature of the service and resource availability. In most cases, we can agree on a start date within 1 to 3 weeks of the initial contact.

How long does a testing project take?

The duration of the project depends on the size of the target and the scope of the testing. Typically, a testing project takes anywhere from a few days to a few weeks, including planning, testing, reporting, and reviewing the findings.

How does penetration testing benefit the business?

Penetration testing helps identify security risks before they can be exploited in real-world attacks. It supports risk management, improves customer trust, helps meet compliance requirements, and reduces the costs caused by security incidents.

Will we receive concrete remediation recommendations after testing?

Yes. Every finding includes a description of the observed risk, its impact, and practical remediation recommendations. If needed, we will review the findings together with your technical team.

Will we receive concrete remediation recommendations after testing?

Yes. Every finding includes a description of the observed risk, its impact, and practical remediation recommendations. If needed, we will review the findings together with the client’s technical team.

Security Awareness Training

Who is the security training suitable for?

The training is suitable for all personnel regardless of their role. The content can be tailored, for example, for specialists, managers, executives, or customer service staff.

How large a group can the security training be organized for?

The training can be delivered for small teams or organizations with hundreds of participants. The delivery method is planned based on the number of participants and objectives.

Does the security training include practical exercises?

Yes. Trainings can include, for example, identification exercises, discussions, group work, phishing examples, and practical scenarios related to the organization's own operating environment.

Can the security training be customized for our organization?

Absolutely. We customize the training according to your organization's industry, risks, practices, and target audience to make the content as relevant as possible for participants.

How often should security training be conducted?

Developing security awareness is an ongoing process. We recommend annual training at a minimum, alongside regular brief updates or awareness campaigns throughout the year.

Security Training for Software Developers

How technically proficient do participants need to be for developer training?

Skill requirements depend on the topic of the training. Generally, participants are expected to have a basic understanding of software development.

What is the maximum group size for developer security trainings?

Training can be organized for small development teams as well as larger groups, up to a maximum of about 25 participants per group. For trainings that include practical exercises, we generally recommend a limited group size to ensure the best learning experience.

Do developer trainings include hands-on exercises?

Yes. Practical application is a key component of our training, and every participant gets to work on hands-on exercises during the day.

Do participants get access to the exercise materials?

Yes. Participants receive the materials used in the training and any exercise instructions for future reference.

 

General Questions

How do we prepare for security testing?

Usually, defining the target of the testing, identifying the necessary contact persons, and granting any required access permissions is sufficient. We will review all preparations in the kick-off meeting and help you collect the necessary information.

How quickly can we start the project?

The project start date depends on the nature of the service and resource availability. In most cases, we can agree on a start date within 1 to 3 weeks of the initial contact.

Do you offer support for fixing the findings?

Yes. We can assist with analyzing, prioritizing, and planning the remediation of findings, as well as verifying the implemented fixes with re-testing.