IT Security Penetration Tests

May we hack you? Or would you rather leave that to the cybercriminals?

Spinae has a family of security assessments, bundled under the name Security MRI. 
Using the same tactics and techniques that hackers use, we determine the vulnerabilities and/or points of weakness in your application, infrastructure or employees.

Complete Security MRI​

Our Complete Security MRI is our most extensive offering in the line of security assessments. Using the same tactics and techniques that cyber criminals use, we attempt to bypass your security measures in every possible way.

This includes: Phishing Campaigns, external penetration tests, internal penetration tests, physical security penetration tests, security questionnaires and more.

Spinae’s testing methodology is 95% manual and is derived from the SANS Pentest Methodology, the MITRE ATT&CK framework for enterprises, and NIST SP800-115 to ensure compliance with most regulatory requirements.

Based on our findings, we put the necessary advice in our reports on how to improve your security. If desired, Spinae can also implement these improvements for you.

Our ethical hackers use tactics and techniques used by cyber criminals to put your defenses to the test and try to find weaknesses in your web application.

The Application Security MRI is an application penetration test, focused on assessing the security of web applications and their underlying infrastructure.

Application Penetration Test

Infrastructure Penetration Test

Our Infrastructure Security MRI is focused on your internal infrastructure and clients. Using the same tactics and techniques that cyber criminals use, we assess the current state of your internal infrastructure. 

Based on our findings, we put the necessary advice in our reports on how to improve your security. If desired, Spinae can also implement these improvements for you.

A lot of information is already publicly available to everyone on the internet. Gathering this type of information is called open-source intelligence, or OSINT.

Gathering this information is completely legal even without signing any contract, so any hacker can do this without being afraid of any legal consequences.

If you wish to get an insight into what information is public and how much hackers can find out about you merely scanning the ‘open field’, our Basic Security MRI is right for you.

Spinae will create a report of all the public findings using open-source intelligence tools and tactics. 

Basic Security MRI