DATA VIRTUAL MACHINE BACKUP SERVICE KITCHENER
Penetration & vulnerability assessment

Find Out How Far an Attacker Gets — Before One Tries

A scan tells you what's theoretically vulnerable. A penetration test proves what an attacker could actually reach, how long it takes them, and what it would cost you. We do both, and we're clear about which is which.

Free external pen test on one public IP — no agent, no cost
Detailed reporting on which back-doors exist and how quickly they fall
Remediation guidance in priority order, plus a retest to confirm
Reports written for auditors, insurers, and your board — SOC 2 Type 2 provider
Free — one public IP

Free external pen test on a single public IP

Give us one internet-facing IP address you own and we'll run a real external penetration test against it — no agent, no cost, findings reported back to you.

Must be an IP your organization owns or controls. One IP per free test.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Authorized testing only. We confirm you own the IP before anything runs.

Trusted by organizations across North America

Know what you're buying

A Vulnerability Scan Is Not a Penetration Test

Plenty of providers sell the first and invoice for the second. A scan lists what might be wrong; a pen test proves what an attacker can do with it. Here's the honest difference.

Vulnerability scan
Automated, broad, frequent

Software checks your systems against a database of known vulnerabilities and reports what it matched.

Answers What known weaknesses exist here?
Method Automated tooling, no exploitation
Duration Hours, largely unattended
Limitation Flags issues that may not be reachable, and misses chained or logic flaws entirely
Run continuously
Penetration test
Automated exploitation, deep, repeatable

A purpose-built platform actually attempts to get in — exploiting and chaining weaknesses the way a real attacker would, then stopping short of harm.

Answers What could someone actually do to us?
Method Attack platform that safely exploits and chains what it finds
Duration Runs in hours to days, repeatable on demand
Strength Proves real impact by chaining weaknesses — and cheap enough to repeat quarterly
Run annually or on change

Most organizations should scan continuously and pen test annually — or after any significant change to the environment.

Two tests, two questions

We Offer Both External and Internal Penetration Testing

They model different attackers and find different things. Most organizations need both — one proves the perimeter holds, the other proves a breach doesn't become a catastrophe.

External network
No agent required
Internal network
One agent on the LAN
Attacker modeled
A remote attacker from the public internet with no prior access or credentials.
Someone already inside — a malicious insider, a compromised employee account, or malware that got past the firewall.
Starting point
Outside the perimeter, working with only what the internet reveals about you.
Given user-level access via VPN or a compromised workstation, then trying to move deeper.
Targets
Internet-facing assets: website, email server, remote access and VPN portals, public IPs.
Internal systems, Active Directory, network shares, workstations, and the domain controller.
What it uncovers
Patching, configuration and authentication flaws on the edge, plus services exposed that shouldn't be.
Weak user privileges, poor network segmentation, unpatched internal software — then lateral movement and privilege escalation toward the domain controller and sensitive data.
Techniques
OSINT, host discovery, enumeration, and exploitation of exposed services.
LAN scans, share enumeration, password attacks, credential harvesting, and man-in-the-middle relay attacks.
Agent needed
No agent — we test entirely from outside.
Yes. A single agent is deployed on the internal network for the duration of the test.
Question answered
Can an attacker get in from the outside?
Once someone is inside, how far can they go?
Compliance
Both satisfy testing requirements for PCI DSS HIPAA SOC 2 Cyber insurance

Not sure which you need? Start with the free external test on one public IP. It costs nothing and tells you whether the perimeter question is even the urgent one.

Scope Both Tests
How we test

Attacker Tradecraft, Run as Software

We run testing on an automated attack platform that reproduces the techniques a real intruder uses — enumeration, credential attacks, relay and man-in-the-middle, privilege escalation — and safely exploits what it finds rather than just flagging it. Our engineers scope the test, review every finding, and walk you through what matters.

The advantage is repeatability. Consultant-led testing is expensive enough that most businesses do it once a year and hope. This is affordable enough to run quarterly, so your report reflects the environment you have now — not the one you had ten months ago.

Consistent methodology every run — results are comparable over time
Engineer-reviewed findings, written for the people who have to fix them
Affordable to repeat quarterly rather than annually
Critical findings reported the day we find them
Hacker mask formed from code, representing cyber threats
What we test

Choose the Angles That Match Your Risk

Testing is scoped to your environment and budget. Most clients start with external and phishing, then widen.

External network

Everything facing the internet: firewalls, VPN endpoints, mail servers, exposed services and forgotten hosts.

What's reachable?

Internal network

Assumes a foothold — a compromised laptop or a contractor's access — and measures how far it spreads.

How far do they get?

Web applications

Your customer portal, booking system, or internal tools — authentication, access control, injection, business logic.

Can they misuse it?

Phishing & social engineering

A simulated campaign against your staff, measuring click rates, credential entry, and whether anyone reports it.

Will people bite?

Wireless

Guest and corporate Wi-Fi separation, weak authentication, and rogue access points on your premises.

Is the air secure?

Cloud & Microsoft 365

Tenant configuration, identity, conditional access, storage permissions and over-privileged accounts.

Who has access?
How an engagement runs

Five Phases, and You Know Where We Are Throughout

1

Scope & authorize

Agree targets, methods, timing, and rules of engagement in writing. Nothing is tested without explicit authorization.

Signed scope
2

Reconnaissance

Map the real attack surface — often including assets you'd forgotten were exposed to the internet.

Asset inventory
3

Test & exploit

The platform safely exploits what it finds and chains weaknesses together to establish genuine impact rather than theory.

Proven paths
4

Report & debrief

Executive summary, technical detail with reproduction steps, and a walkthrough call with your team.

Prioritized report
5

Retest

Once you've remediated, we verify the fixes actually closed the finding — and didn't open something new.

Verified closure

Testing windows are agreed in advance. If we find something critical mid-engagement, you hear about it that day — not in the report.

The deliverable

A Report Your Team Can Act On, and Your Auditor Accepts

Every finding is ranked by real-world exploitability, not just CVSS score — because a critical vulnerability behind three other controls matters less than a medium one facing the internet.

You get an executive summary for the board, technical detail with reproduction steps for whoever fixes it, and remediation guidance in priority order. A retest confirms the fixes worked.

Findings, ranked by exploitability
Illustrative structure
Critical Internet-facing service allowing unauthenticated access Fix now
High Credentials reused across admin and standard accounts Days
Medium Missing segmentation between user and server networks This quarter
Low Verbose error messages disclosing software versions Backlog

Categories shown are typical of what testing surfaces. Your report reflects your environment.

DATA PROTECTION SERVICES waterloo
Testing is a snapshot

A Test Tells You About One Day. Monitoring Covers the Rest.

A penetration test is accurate the week it's run. New vulnerabilities land constantly, and your environment changes — so annual testing alone leaves long gaps.

Pairing testing with our Security Operations Center closes them: ethical hackers find what's exploitable, the SOC watches for anyone attempting it. Together they cover organizations of any risk profile.

Security Operations Center
Questions, answered

Penetration Testing FAQs

What exactly is free, and what's the catch?

We'll run a genuine external penetration test against one public IP address that you own, and report what we find. There's no catch and no obligation — it's scoped to a single IP because that's what we can do at no cost. A full engagement covers your whole external range, or your internal network, and that's quoted normally.

What's the difference between external and internal testing?

External models an attacker on the internet with no access, testing your perimeter — website, mail, VPN, public IPs. Internal assumes someone is already inside and measures how far they get: privilege escalation, weak segmentation, and the path to your domain controller. External needs no agent; internal needs one agent deployed on the LAN.

Is the testing automated or done by a person?

The testing itself runs on an automated attack platform — it performs the same enumeration, exploitation and privilege-escalation techniques an intruder would, consistently and far faster than a person. Our engineers scope each engagement, review the findings, remove noise, and debrief you. We'd rather be straight about that than imply a consultant is hand-typing commands for a week. The trade-off is real: highly bespoke business-logic flaws in a custom application are still better found by a specialist consultant, and we'll say so if that's what you need.

Will testing disrupt our systems?

It shouldn't, and we scope it so it doesn't. Genuinely disruptive techniques are excluded by default or run in a maintenance window you choose. The rules of engagement are agreed in writing before anything starts, and you'll have a contact who can stop the test immediately.

How often should we test?

Annually is the common baseline, plus after any significant change — a new application, an office move, a merger, a major infrastructure project. Scanning should run continuously in between, because the gap between annual tests is where most exposure accumulates.

Do we need this for compliance or insurance?

Increasingly, yes. SOC 2, PCI DSS, and many cyber insurance applications either require testing or price it in. Client contracts are the other common driver. Tell us who's asking and we'll make sure the report format satisfies them.

What if you find something serious?

You hear about it that day, with immediate containment advice — we don't sit on a critical finding until the report is polished. If it's actively being exploited, that becomes an incident response conversation rather than a testing one.

Do you test our staff as well as our systems?

If you want us to. Phishing simulation measures how many people click, how many enter credentials, and — more usefully — how many report it. We'd recommend agreeing in advance how results are handled internally, because the point is to improve training, not to discipline anyone.

Do we get help fixing what you find?

The report includes remediation guidance in priority order, and the debrief call is for working through it with your team. If you'd rather we did the remediation work, that's a separate engagement quoted separately — we'll never make the report deliberately unusable to force that.

Let's connect

Find the gaps before someone else does.

Tell us what you need to prove and to whom — a client, an insurer, an auditor, or your own board — and we'll scope testing that answers it without gold-plating.

Scope a penetration test

We'll reply within one business day.

For a free single-IP external test. Must be an IP your organization owns or controls.

We don't share your data. View Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.