Services · Central Illinois

Six engagements. One question each.

Every test on this page answers a specific question about a specific attack surface. Picking the right one matters more than buying the most expensive one, and the fastest way to get that right is a twenty-minute call where we ask what you are trying to prove and to whom.

Service catalog

External Penetration Testing illustration

External Penetration Testing

Assess internet-facing assets to identify exploitable weaknesses before attackers do.

Testing window
5–10 business days
Standards
PTES, NIST SP 800-115
View methodology and pricing factors
Internal Penetration Testing illustration

Internal Penetration Testing

Simulate an internal adversary to evaluate lateral movement and privilege escalation risk.

Testing window
5–10 business days
Standards
PTES, NIST SP 800-115
View methodology and pricing factors
Web Application Testing illustration

Web Application Testing

Test modern web applications for logic flaws, auth issues, and exploitable vulnerabilities.

Testing window
5–15 business days
Standards
OWASP WSTG, OWASP ASVS
View methodology and pricing factors
Mobile Application Testing illustration

Mobile Application Testing

Evaluate mobile apps and connected APIs for insecure data flows and client-side abuse paths.

Testing window
5–12 business days
Standards
OWASP MASTG, OWASP MASVS
View methodology and pricing factors
IoT Security Testing illustration

IoT Security Testing

Assess connected devices, interfaces, and supporting infrastructure for real-world attack paths.

Testing window
10–20 business days
Standards
OWASP IoT Top 10, NIST IR 8259
View methodology and pricing factors
API Security Testing illustration

API Security Testing

Analyze API endpoints for authorization flaws, data exposure, and abuse opportunities.

Testing window
5–10 business days
Standards
OWASP API Security Top 10, OWASP WSTG
View methodology and pricing factors

Which test do you actually need?

Most organizations start with an external test, because the perimeter is what the whole internet can reach and because it is what auditors and insurers ask about first. If you have never had a test, start there.

If your primary risk is ransomware or an employee clicking the wrong link, an internal test tells you more, because it measures what happens after the perimeter fails rather than whether it holds.

If you sell software, the application is the product and the product is the risk. Web application testing covers what your users see; API testing covers what your integrations, mobile clients, and partners talk to. Multi-tenant platforms should have both, since tenant isolation is enforced separately at each layer.

Mobile and IoT are specialist engagements for organizations shipping something onto a device they do not control. Both are most valuable before release, and IoT dramatically so — hardware findings are close to unfixable once a production run has left the factory.

What every engagement includes

Manual exploitation, not scanner output
Automated tooling is an input to our process. Every candidate finding is verified by hand, and false positives never reach your report.
A report written by the person who tested
No offshore report writing, no template with your logo dropped in. The operator who ran the engagement writes the findings.
Business impact in plain language
An executive summary a board or an insurer can read, alongside technical detail your engineers can act on without translation.
Free retest within 90 days
Fix the findings and we verify them, then issue an updated report and attestation letter showing what is closed.
Attestation letter for third parties
A shareable summary confirming scope, dates, and methodology, with no sensitive detail — for customers, auditors, and cyber liability renewals.
Fixed fee, agreed before we start
Scoped from a short call and quoted as a fixed price. No hourly billing and no change orders halfway through the engagement.

Frequently asked questions

How long does a penetration test take?

Most engagements run 5 to 10 business days of active testing, with the report delivered 5 business days afterward — roughly 2 to 4 weeks from kickoff to final document. Web application and IoT assessments run longer, up to 15 and 20 business days respectively, because the surface area is larger and less predictable.

What does a penetration test cost?

We quote a fixed fee after a short scoping call, with no hourly billing and no change orders once testing starts. Price is driven by measurable scope: live host count for network tests, user roles and workflows for applications, endpoints multiplied by roles for APIs, and device models for IoT. Each service page lists the specific variables that move the number.

How often should we test?

Annually at minimum, which is what most compliance frameworks, cyber insurers, and enterprise customers expect. Test again after any material change: a cloud migration, an acquisition, a new authentication system, or a significant application release. Continuous change with annual testing means eleven months of drift.

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan matches version numbers and signatures against a database and produces a list of possibilities, including a meaningful number of false positives. A penetration test verifies each candidate by hand, discards what is not real, and chains the remainder together to demonstrate actual impact. Scanning is one input to our process, not the product.

Will testing disrupt our production systems?

No. We exclude denial-of-service testing by default, throttle credential attacks to avoid account lockouts, never encrypt or delete data, and stop before any action likely to disrupt a running service. You get an emergency stop contact before testing begins and we agree on blackout windows in advance.

Do you work with organizations outside Central Illinois?

Yes. We are based in the Peoria area and work regularly across Bloomington–Normal, Champaign–Urbana, Springfield, and Decatur, but nearly all testing is performed remotely and we take engagements nationwide. On-site work is available where physical or wireless access is part of the scope.

What do we actually receive at the end?

An executive summary written for a non-technical reader, technical findings with CVSS v4.0 vectors and reproduction steps, remediation guidance specific to your stack, and a shareable attestation letter for customers, auditors, and insurers. Retesting of remediated findings is included for 90 days.

Based in Central Illinois. Engagements nationwide.

We work with organizations in Peoria, Bloomington–Normal, Champaign–Urbana, Springfield, and Decatur, and testing is performed remotely for clients across the country. Every engagement is run by an operator holding OSEP, OSWE, and OSCP with awards and fourteen published CVEs to their name.