Penetration testing

Penetration Testing

Baldur Security is a Danish, research-driven offensive security company. We find the vulnerabilities others miss, in software like Chrome, Fortinet, Mitel and PRTG, and in your own systems. This page covers what a penetration test is, how it works with us, and what you get.

33CVEs published
100+penetration tests delivered
300+bug bounty reports
OSCE / OSCPcertified
Book a scoping call

What is a penetration test?

A penetration test is a controlled attack on your systems, run by security people with permission. The goal is to find the vulnerabilities a real attacker would use, and prove they can be exploited, before anyone with bad intent does. A good test does not stop at a list of possible problems; it shows the concrete way in, what can be reached from there, and what it takes to close it.

Penetration testing goes by many names: pentest, security test, assessment, red team. It is the same thing: a manual, targeted assessment where a human actively tries to break in.

Penetration test vs. vulnerability scan

A vulnerability scan is automated. It compares your systems against a list of known flaws and reports what matches. That is useful, but a scanner does not understand your business logic and cannot reason its way to an attack. It finds the known; it misses the access-control and logic flaws, exactly the kind that cause the serious breaches. A penetration test is manual and done by people who look for precisely that.

Types of penetration test

We test what attackers actually go after. The typical engagements:

  • Web Application Penetration Testing - Manual testing plus source-code review. We read the code and prove exploitability by hand, not just probe the surface.
  • Assume Breach Assessment - We start as a compromised employee inside your network and show how far a skilled attacker gets, then exactly what stops them.
  • Cloud Penetration Testing - AWS, Azure and GCP: identity, misconfiguration and privilege-escalation paths, tested the way attackers actually move, not a checklist scan.
  • Source Code Audit - Line-by-line review across most stacks. Source-assisted testing finds the logic and access-control bugs scanners walk straight past.
  • DevSecOps - Security wired into your CI/CD: SAST, DAST, dependency and IaC scanning, and pipelines your developers will actually keep using.
  • Binary Exploitation & Fuzzing - Coverage-guided fuzzing and manual reversing of binaries and firmware. We took a Mitel IP phone from nothing to unauthenticated root (CVE-2024-31963). See the research.
  • Network & Infrastructure Testing - External and internal network testing: exposed services, patch gaps and lateral-movement paths, exploited by hand and verified.
  • AI Security Audit - We audit the LLMs and agents you ship, and the AI in your pipeline: prompt injection with real impact, agent sandbox escapes and data exposure. That is how we found an RCE in an AI pentester agent. See the research.

How a penetration test works at Baldur

  1. 01

    Scope

    We agree targets, rules of engagement and what a critical finding means for your business before anything starts. You know exactly what we touch, and when.

  2. 02

    Recon

    We map the real attack surface: endpoints, versions, exposed services and how the pieces talk to each other.

  3. 03

    Exploitation

    We run advanced attacks like a real threat actor. Scanners find the obvious; access-control and logic flaws take a human, and those are the ones that hurt.

  4. 04

    Source-assisted review

    With source access we trace the bug to the line and prove whether it is exploitable.

  5. 05

    Report

    A management summary and a technical report: every finding reproducible, rated, and paired with a concrete fix.

  6. 06

    Retest

    After you remediate, we verify the fix actually closes the issue, and that the fix is not incomplete.

What you get

  • Two reports: a management summary in business terms and a technical report your engineers can act on directly.
  • Reproducible findings, each with the steps, the request, and where relevant a proof-of-concept.
  • A priority order that makes sense: rated on real exploitability and impact, not just CVSS.
  • Concrete remediation for each finding, and a mitigation where it buys you time.
  • An expert walkthrough with a Q&A round, so both management and the technical team understand the result.
  • A letter of attestation: a signed, non-sensitive document confirming the test was carried out, which can include a verification that the fixes were checked.
  • A retest once you have remediated.

What does a penetration test cost?

The price of a penetration test depends on the work, not a fixed price list. What determines it:

  • Scope: how many applications, systems or network segments are in scope.
  • Size and complexity: roles and features, integrations, and how much business logic there is to understand.
  • Environment: web, cloud, internal network, embedded devices or binaries.
  • Access: whether we test black box or get source code and accounts (source access finds more in less time).

How we do it in practice: you tell us what needs testing on a short call. We come back with a fixed quote and a number of days, so you know exactly what you pay for before we start. Book a scoping call and you have a concrete quote.

Penetration testing and the law: NIS2, DORA, CRA and ISO 27001

More companies have to test because legislation or a standard requires it. In short:

  • NIS2 requires essential and important entities to manage risk and test the effectiveness of their measures. A penetration test is a recognised way to document exactly that.
  • DORA requires financial entities to test their digital resilience, at the heavy end as threat-led red teaming (TIBER).
  • CRA (Cyber Resilience Act) sets security requirements for products with digital elements, including vulnerability handling; a test documents that the requirements have been verified.
  • ISO 27001 does not require a penetration test verbatim, but a test is the normal way to verify controls and close findings from an audit.

We write the report so it can go straight into your documentation for an auditor or a customer.

Who is Baldur?

Baldur Security (Baldur Security ApS, CVR 45584860) is a Danish offensive security company. We work white box, ideally with source code, because it finds more than probing blind from the outside. The team holds OSCE and OSCP, has delivered 100+ penetration tests across sectors such as banking, healthcare and the public sector for organisations from 10 to 10,000 employees, and has published around 33 CVEs and submitted 300+ bug bounty reports. A few examples:

See all our research and advisories →

Frequently asked questions

What is the difference between a penetration test and a vulnerability scan?

A scan is automated and finds known flaws. A penetration test is manual: a human actively tries to break in and also finds logic and access-control flaws a scanner cannot reason its way to.

How often should we run a penetration test?

At least once a year and on major changes: a new application, new architecture or a significant feature. Some standards and customers require it annually. For more continuous needs we can build AI pentest bots that test on an ongoing basis.

How long does a penetration test take?

Most engagements are one to three weeks depending on scope. We give a number of days with the quote, so you know the timeline up front.

Do you test in production or a test environment?

Both happen. We agree it in scoping and set the rules so we do not disrupt operations. A lot can be tested safely in production once the boundaries are set, but we prefer a test environment.

Do you need our source code?

Not necessarily, but we recommend it. Source access finds more and deeper flaws in less time. We also test black box if that is what you need.

What does a penetration test cost?

It depends on scope, complexity, environment and access. We give a fixed quote after a short scoping call, so you know exactly what you pay for before we start.

Can you help with NIS2, DORA, CRA or ISO 27001?

Yes. We write the report so it can be used directly as documentation for an auditor, customer or authority.

What do we get afterwards?

A management summary, a technical report with reproducible findings and concrete fixes, an expert walkthrough with Q&A, a letter of attestation, and a retest once you have remediated.

Do you only work in Denmark?

We are based in Denmark and work with clients worldwide. Reports and meetings can be in Danish or English.

Tell us what you need tested

A 30-minute call is enough to scope most engagements, and it is entirely no-obligation.

Book a scoping call