We test your online presence. We test ourselves just as hard.
Praeferre's penetration testing team probes your websites, applications, APIs and cloud infrastructure the way a real attacker would — then maps every finding to the frameworks your compliance programme already runs on. And because your compliance data lives on our platform, we hold Praeferre itself to the same standard, tested regularly against the same requirements we test for you.
Almost every catastrophic breach started as a known, fixable issue
Attackers rarely need a novel technique. They need a vulnerability nobody found in time — and the gap between "patch available" and "patch applied" is exactly what penetration testing exists to close.
One missed patch, $700M in settlements
A critical vulnerability in Apache Struts had a patch available for months before attackers used it to breach Equifax's systems — exposing the personal data of around 147 million people over two months, undetected.
The FTC's own conclusion: Equifax had the fix. What it lacked was a way to verify the fix actually held — the exact gap independent penetration testing is designed to catch.
Total settlement following the breach, covering penalties, consumer compensation and identity protection services — against a vulnerability with a known fix sitting unapplied.
The average time organisations take to patch a known vulnerability once it's identified — an exposure window regular testing is built to shrink.
Sources: Federal Trade Commission, on the Equifax settlement · Verizon 2025 Data Breach Investigations Report, via Novee.
Of breaches in 2026 involved a software vulnerability as a contributing factor — the exact class of issue a penetration test is built to surface before an attacker finds it first.
Average cost of a data breach — against which a properly scoped penetration test typically runs a few thousand pounds, not millions.
Engagement needed to satisfy PCI DSS 11.4, ISO 27001 Annex A and SOC 2 CC4.1 simultaneously, when scoped correctly from the outset.
Sources: ComplyJet, on 2026 breach and pentest cost benchmarks.
Real attack techniques, aimed at what you've actually got exposed
Automated scanners find what's already known. Praeferre's testers go further — chaining misconfigurations, testing business logic, and validating whether a vulnerability is genuinely exploitable in your specific environment, not just theoretically present.
- Methodology aligned to OWASP and NIST SP 800-115
- Every finding includes proof-of-concept, not just a description
- Free retest included once remediation is applied
We hold ourselves to the same bar we test you against
Your compliance evidence, your vendor assessments, your AI redaction logs — all of it lives on Praeferre. That means Praeferre's own infrastructure is tested on a regular cycle against the same requirements your compliance programme needs, not as a one-off certificate but as a running discipline: scope, test, report, remediate, retest, repeat.
- Independent testing on a recurring cycle, not a single point-in-time certificate
- Results feed directly into your own GRC evidence base — ask your DPO to show you
- Scoped against the same standards this page tests your systems for
This cycle runs continuously on Praeferre's own infrastructure — the same platform holding your compliance evidence is never more than one cycle away from its next independent test.
Frequency depends on the framework — we scope to whichever applies
Some regimes are prescriptive about cadence. Others leave it to risk judgement. Either way, the right scope can satisfy more than one framework in a single engagement.
PCI DSS 4.0
Explicitly mandates internal and external testing under Requirement 11.4. Service providers face a shorter clock on segmentation testing specifically.
ISO 27001
Doesn't name penetration testing explicitly, but Annex A's technical vulnerability and security testing controls make it the standard way organisations demonstrate they're met.
SOC 2
Not named as a requirement, but auditors treat it as the clearest available evidence for CC4.1 — that your controls hold up under real adversarial conditions.
Find out what's exposed before someone else does
Tell us what's in scope — a single application or your full external estate — and we'll come back with a proposal mapped to the frameworks you actually need to satisfy.