Praeferre/Platform/Penetration Testing
Penetration Testing

We test your online presence. We test ourselves just as hard.

Praeferre's penetration testing team probes your websites, applications, APIs and cloud infrastructure the way a real attacker would — then maps every finding to the frameworks your compliance programme already runs on. And because your compliance data lives on our platform, we hold Praeferre itself to the same standard, tested regularly against the same requirements we test for you.

OWASP · NISTMethodology behind every engagement
CVSS-scoredEvery finding, prioritised and proven
Free retestIncluded once remediation is complete
Findings mapped to: PCI DSS 11.4 ISO 27001 ANNEX A SOC 2 CC4.1 CYBER ESSENTIALS PLUS CAF 4.0 · A4 SUPPLY CHAIN
Why it matters

Almost every catastrophic breach started as a known, fixable issue

Attackers rarely need a novel technique. They need a vulnerability nobody found in time — and the gap between "patch available" and "patch applied" is exactly what penetration testing exists to close.

Case study · Equifax, 2017

One missed patch, $700M in settlements

A critical vulnerability in Apache Struts had a patch available for months before attackers used it to breach Equifax's systems — exposing the personal data of around 147 million people over two months, undetected.

Mar 2017Apache discloses the Struts vulnerability and ships a patch. Equifax's own security team orders it applied within 48 hours.
May 2017The patch was never confirmed applied. Attackers exploit the same vulnerability and gain access.
Jul 2017Suspicious traffic is finally detected — four months after the original alert, and two months into the breach.

The FTC's own conclusion: Equifax had the fix. What it lacked was a way to verify the fix actually held — the exact gap independent penetration testing is designed to catch.

$700M
Settlement · FTC, CFPB & 50 states

Total settlement following the breach, covering penalties, consumer compensation and identity protection services — against a vulnerability with a known fix sitting unapplied.

32 days
Average patch time · Verizon 2025

The average time organisations take to patch a known vulnerability once it's identified — an exposure window regular testing is built to shrink.

Sources: Federal Trade Commission, on the Equifax settlement · Verizon 2025 Data Breach Investigations Report, via Novee.

31%

Of breaches in 2026 involved a software vulnerability as a contributing factor — the exact class of issue a penetration test is built to surface before an attacker finds it first.

$4.88M

Average cost of a data breach — against which a properly scoped penetration test typically runs a few thousand pounds, not millions.

1 test

Engagement needed to satisfy PCI DSS 11.4, ISO 27001 Annex A and SOC 2 CC4.1 simultaneously, when scoped correctly from the outset.

Sources: ComplyJet, on 2026 breach and pentest cost benchmarks.

Testing your online presence

Real attack techniques, aimed at what you've actually got exposed

Automated scanners find what's already known. Praeferre's testers go further — chaining misconfigurations, testing business logic, and validating whether a vulnerability is genuinely exploitable in your specific environment, not just theoretically present.

Web applications APIs Cloud infrastructure Internal networks Segmentation testing
  • Methodology aligned to OWASP and NIST SP 800-115
  • Every finding includes proof-of-concept, not just a description
  • Free retest included once remediation is applied
Scope a test
Findings · praeferre-client-app.com
CRITICALAuthentication bypass via JWT signature confusionCVSS 9.1FIXED
HIGHIDOR exposing other customers' invoice dataCVSS 8.2FIXED
MEDIUMVerbose error messages reveal internal stack pathsCVSS 5.4FIXED
LOWMissing security headers on static asset domainCVSS 2.6OPEN
Our platform is tested too

We hold ourselves to the same bar we test you against

Your compliance evidence, your vendor assessments, your AI redaction logs — all of it lives on Praeferre. That means Praeferre's own infrastructure is tested on a regular cycle against the same requirements your compliance programme needs, not as a one-off certificate but as a running discipline: scope, test, report, remediate, retest, repeat.

  • Independent testing on a recurring cycle, not a single point-in-time certificate
  • Results feed directly into your own GRC evidence base — ask your DPO to show you
  • Scoped against the same standards this page tests your systems for
Ask about our last test cycle
Continuous Test Cycle
01
Scope
02
Test
03
Report
04
Remediate
05
Retest

This cycle runs continuously on Praeferre's own infrastructure — the same platform holding your compliance evidence is never more than one cycle away from its next independent test.

How often you need it

Frequency depends on the framework — we scope to whichever applies

Some regimes are prescriptive about cadence. Others leave it to risk judgement. Either way, the right scope can satisfy more than one framework in a single engagement.

Prescriptive

PCI DSS 4.0

Explicitly mandates internal and external testing under Requirement 11.4. Service providers face a shorter clock on segmentation testing specifically.

Annually + after significant change · segmentation every 6 months
Risk-based

ISO 27001

Doesn't name penetration testing explicitly, but Annex A's technical vulnerability and security testing controls make it the standard way organisations demonstrate they're met.

Typically annually, or after major change
Evidence-driven

SOC 2

Not named as a requirement, but auditors treat it as the clearest available evidence for CC4.1 — that your controls hold up under real adversarial conditions.

Recommended within each audit observation period
Start your compliance journey

Find out what's exposed before someone else does

Tell us what's in scope — a single application or your full external estate — and we'll come back with a proposal mapped to the frameworks you actually need to satisfy.