CISSP/CISA-LED · INDEPENDENT · CALGARY & CANADA-WIDE

Penetration Testing
Prove What an Attacker Could Actually Do

A penetration test is a controlled, authorized attack on your systems by an experienced tester who tries to break in the way a real attacker would. You get a clear picture of what is exposed, what an intruder could reach, and exactly what to fix first. ThreeShield tests independently of your MSP and internal IT, so the results are an honest second opinion.

A Real Test, Not a Scanner Report

Many "penetration tests" are an automated scan with a logo on the cover. Ours is hands-on. We use commercial and proprietary tools to map your attack surface, then a person works through what the tools surface, chains weaknesses together, and shows the real path an attacker would take. We regularly find serious exposure that automated tools score as low risk.

Tests We Run

Choose one, or combine several into a single engagement. We scope each to how your organization actually operates.

External Network

We test everything an attacker can reach from the internet: your firewalls, VPN, email, remote access, and any forgotten service left exposed. This is the most common starting point.

Internal Network

We test what someone could do once inside, whether a phished employee or a visitor on your network. This shows how far a foothold spreads and whether an attacker reaches your critical data.

Web Application

Hands-on testing of your web apps, portals, and APIs against the OWASP Top 10 and beyond: authentication flaws, access-control gaps, injection, and business-logic abuse that scanners miss.

Cloud (Microsoft 365, Azure, Google, AWS)

We review your cloud tenant the way an attacker probes it: risky permissions, weak conditional access, exposed storage, and identity paths that lead to admin.

Wireless

Testing of your Wi-Fi for weak encryption, rogue access points, and guest networks that quietly reach production systems.

Social Engineering & Phishing

Authorized phishing, pretext calling, and physical entry attempts that test your people and processes, not just your technology. People are how most breaches start.

Independent of your MSP and internal IT

ThreeShield reports at arm's length from whoever runs your IT. A team cannot objectively grade its own work, so an independent test is what gives your board, your insurer, your auditor, and your clients a reason to trust the result. We are glad to work alongside your MSP to fix what we find, but we report to you.

Penetration Tests for Compliance and Insurance

If a standard or an insurer is asking for a test, our report is written to answer them directly, with the scope, method, findings, and retest results they expect to see.

DriverWhat it asks forWhat ThreeShield delivers
PCI DSS Requirement 11.4Internal and external penetration testing every year and after major changes, plus segmentation testingScoped test and segmentation validation, with a report your assessor accepts
SOC 2Evidence of an annual penetration testIndependent report and retest confirmation for your audit file
Cyber insuranceProof a test was done in the past yearDated report and attestation letter for your renewal
Client security questionnairesConfirmation of regular third-party testingA shareable summary you can send to prospects and clients

How an Engagement Runs

1. Scope and rules of engagement

We agree in writing on what is in scope, the testing window, and anything to handle gently. You get a fixed price before we start.

2. Reconnaissance

We map your attack surface and the exposure an attacker would gather about you before touching anything sensitive.

3. Exploitation

We safely attempt to exploit what we find, confirming which weaknesses are real rather than theoretical.

4. Post-exploitation

Where we gain a foothold, we show how far it reaches: lateral movement, privilege escalation, and access to sensitive data.

5. Report and debrief

You get a prioritized report written in plain language, with an executive summary for leadership and technical detail for your IT team, and a call to walk through it.

6. Retest

After you fix the findings, we retest and confirm the fixes worked, in writing.

Penetration Test or Vulnerability Assessment?

They answer different questions, and many organizations need both. A vulnerability assessment gives you broad, regular coverage of known weaknesses at a lower cost. A penetration test proves, once or twice a year, what an attacker could actually accomplish.

Vulnerability assessmentPenetration test
Main questionWhat weaknesses exist?What could an attacker actually do?
ApproachBroad scanning, validated by handFocused, hands-on exploitation
CoverageWide across the whole environmentDeep along realistic attack paths
How oftenMonthly or quarterlyOnce or twice a year, and after big changes
Best forOngoing hygiene and early warningProof of real-world risk for audits and insurers

Read more about vulnerability assessments, or see how both fit into a full cybersecurity audit.

Penetration Testing FAQ

A vulnerability assessment finds and ranks known weaknesses across your environment. A penetration test goes further: a tester actively tries to exploit those weaknesses, chain them together, and show what an attacker could reach. A vulnerability assessment answers what could be wrong; a penetration test answers what someone could actually do about it.

Price depends on scope: the number of external addresses or applications, whether internal and cloud testing is included, and whether social engineering is in scope. A focused external test of a small environment is a few thousand dollars; a full external, internal, and web-application engagement for a mid-sized organization runs higher. We scope and quote a fixed price before any work starts, so there are no surprises.

Often, yes. PCI DSS Requirement 11.4 calls for internal and external penetration testing at least once a year and after significant changes, plus segmentation testing where segmentation reduces scope. SOC 2 and many client security questionnaires expect an annual penetration test. Cyber-insurance applications increasingly ask whether one has been done in the past year. Our reports are written to satisfy these requirements.

It should not. Testing is planned with you in advance through written rules of engagement that set the scope, the testing window, and any systems to handle gently or avoid. We exclude denial-of-service testing unless you specifically ask for it. Most testing runs against production safely; where it cannot, we test a staging copy.

Yes. We report at arm's length from whoever runs your IT, so the findings are an honest second opinion rather than a team grading its own work. That independence is what makes the report carry weight with your board, your insurer, your auditor, and your clients.

In a black-box test the tester starts with no inside knowledge, like an outside attacker. In a grey-box test the tester is given limited information, such as a standard user login, which finds more in less time. In a white-box test the tester has full documentation and credentials for the deepest coverage. We recommend the approach that gives you the most useful findings for your budget, and grey-box is the common choice.

Yes. Every engagement includes a retest of the issues we reported, so you get written confirmation that the fixes worked. That confirmation is what auditors and insurers want to see, not just the original list of problems.

Find out what an attacker could reach

Tell us what you want tested and we will scope a fixed-price engagement, run it independently of your IT team, and hand you a report you can act on and share.

Get a Pen Test Quote

Independent · Fixed-price · Retest included