Skip to content
Security & risk

Find out what an attacker can actually reach.

Penetration testing against your web apps, cloud, mobile and internal network. You get the path an attacker would take, the one fix that closes it, and a retest that proves it closed.

Where we have experience

  • Banking
  • Government
  • E-commerce
  • Consumer technology
  • Energy and utilities

What we do

Testing, tooling, and the advice in between.

Most engagements start with a test. The other two exist because a report nobody can act on is an invoice with a list attached.

Penetration testing

Web applications and APIs, cloud and infrastructure, mobile clients, and internal networks including Active Directory. Manual testing against a scope fixed before the fee, with the retest in it.

Custom security tooling

For the check that does not exist as a product. Detection written for your own log shape, an access review that runs itself, a scanner for the one thing your stack does differently.

Advisory

Threat modelling before a build, the security questionnaire you have been sent, or a second opinion on an architecture. Priced by the piece of work rather than as a retainer.

How the engagement runs

Four steps, and the retest is in the fee.

The same shape whether it is one web app or the whole estate. What changes is the scope, and the scope is fixed before you get a number.

  1. 01

    Scope and rules

    Targets, test windows, what is out of bounds, and who to call if something goes down. Agreed in writing before anything is touched.

  2. 02

    Test

    Hands on the keyboard against the scope, with tooling where tooling genuinely helps. Anything critical reaches you the day we find it.

  3. 03

    Report and debrief

    Findings ranked by what they reach, reproduction steps for each, a fix order, and an hour with your engineers to walk it.

  4. 04

    Retest

    We re-run the same tests against your fixes and record what closed. It is in the fee, because closing the findings is the point.

What we find

A path, not two hundred issues.

A scanner produces a list. What matters is which findings chain together into something that reaches your data, and which single fix breaks that chain.

  • Findings ranked by what they reach, not by a default severity score
  • Reproduction steps your engineers can follow without calling us
  • Anything critical reported the day it is found, not at the end
  • A fix order, so nobody starts with the cheapest finding
  • No scanner output pasted in to make the document longer

What you get

The report is the deliverable.

Written for two readers at once. The engineer who has to fix it needs the reproduction steps. The person deciding what gets fixed first needs to know what each finding actually reaches.

  • Severity argued from what it reaches, with the reasoning shown
  • Every finding carries the evidence and the steps to reproduce it
  • The retest result recorded against each finding once it closes
  • A one-page version for the people who will not read the rest
  • Yours to hand to a client or an insurer without asking us

Typical shape

What a test usually looks like.

Short enough that the system has not changed by the time the report lands, and scoped tightly enough that we can start within a few weeks of the first call.

5–12working days for most tests, retest included

Scoped before it is priced

Targets and rules of engagement are agreed first, so the fee is against a real scope rather than a guess at one. Nothing outside it gets touched.

The retest is in the fee

You are paying to have findings closed, not counted. We re-run the same tests against your fixes and record what actually closed.

How we test

The standards we test against.

Published methodology, so coverage is checkable against something other than our word. Tooling where tooling helps, and manual testing for everything it misses.

  • OWASP ASVS
  • OWASP MASVS
  • OWASP Top 10
  • PTES
  • CVSS v4
  • MITRE ATT&CK
  • Burp Suite
  • nmap
  • BloodHound
  • ScoutSuite
  • Semgrep
  • Nuclei

The limits

What we are not.

If any of these is a hard requirement for you, say so on the first call and we will tell you straight away whether we are the wrong firm for it.

  • We do not test our own builds

    If Ackho wrote the software, we will not test it and call the result independent. We will help you scope it for someone else, and we will fix what they find.

  • We are not certified

    We test to OWASP and PTES methodology. We have not been audited against ISO 27001 or SOC 2 and we will not imply otherwise on a tender. If your procurement needs a certificate from the tester, we are not the right supplier.

  • We do not run a 24/7 desk

    A test has a start and an end. We are not a monitoring service and we hold no incident rota, so ask about capacity before you depend on us for one.

FAQ

Penetration testing questions we get asked

How much does a penetration test cost in Singapore?
It depends on scope, which is why the targets and the rules of engagement are agreed before we quote. The fee is fixed against that scope and includes the retest, so the number you see before committing is the number you pay.
What do you test?
Web applications and APIs, cloud and infrastructure, mobile clients, and internal networks including Active Directory. If a scope needs something we do not do, we will say so rather than stretch to fit it.
How long does a test take?
Most run five to twelve working days including the report. Scoping happens before that, and the retest sits a few weeks later once your team has had time to fix.
Will the test break anything?
The rules of engagement set what we will not touch, when we test and who to call. Anything that risks availability runs in a window you choose, or against a staging copy if you would rather.
Do you retest after we fix?
Yes, and it is in the fee. We re-run the same tests against your fixes and record the result against every finding, so the report ends as a record of what closed rather than a list of what was wrong.
Can you test software Ackho built?
No. We will not test our own work and call the result independent. We will help you scope it for another firm and fix what they find.
Does a penetration test make us PDPA compliant?
No, and anyone saying otherwise is selling something. PDPA requires reasonable security arrangements for personal data, and a test is evidence you looked and acted. Where personal data is in scope we say what each finding means for it.
Can you complete our security questionnaire?
Yes. Send it before the engagement rather than after, because a few of the answers are decisions we would make differently depending on what it requires.

Tell us the partthat is costing you.

One call. We tell you what we would build, what we would not, and what it costs, before either of us commits.

Tell us the workflow.

It goes to the people who would do the work, not to a sales inbox.

Used only to reply to you. We won't add you to a list or share it with anyone.

Ackho