Customer-Led Penetration Testing
Description
IT infrastructures are exposed to a wide range of threats. The many dependencies between configuration items in modern hosting environments require coordinated change processes and risk analyses. However, penetration testing often yields results that require closer examination to accurately assess the associated risks. We are therefore keen to collaborate with you to ensure your tests run as smoothly as possible and yield the best possible results. For instance, extending log file retention during the test may be advisable. Preparation and detailed planning are essential to ensure we can intervene quickly in an emergency should your test cause issues within your setup. These plans should clearly define the attack targets and the testing methodology. Please note that service disruptions caused by the test are not covered by SLA agreements, and your setup operates on shared infrastructure. You must ensure that the functionality and performance of other customers' setups are not compromised.
What we aim to achieve with this service
- Optimal support for your test planning and execution
- Safeguarding your investment in the tests and their results
- Protection against liability claims
- Guaranteed rapid assistance for issues, with a response time of under 5 minutes from receipt of the alert
- Rollback capability using pre-test data to restore the setup's functionality
- Setup optimization for result analysis (for example, log files, performance headroom, etc.)
What you can expect from us
- Expert advice
- Identification of potential risks the test poses to your setup, based on your documentation
Optional Service Features
- Prompt backup of your servers and data before the test run
- Review of test results to determine necessary measures
- Execution of rollbacks
- Reservation of specialist personnel for the test period, with telephone availability throughout the duration of the test
- White-box testing
Important Notes & Deadlines
- Testing outside our standard business hours is not permitted.
- We reserve the right to take countermeasures at any time, without stating a reason, to protect its own systems or those of other customers.
- Tests designed to measure bandwidth or DoS resilience are not permitted.