For growing companies with lean teams

Penetration testing your team can work with.

Clear evidence for audits and customer reviews. Practical remediation guidance, shaped around your systems and the people who maintain them.

Common reasons to test

  • SOC 2
  • ISO 27001
  • PCI DSS
  • Customer security reviews

Our approach

Good advice has to fit the team doing the work.

Growing companies have real security obligations and limited time to meet them. A useful assessment needs to account for both.

Dexterity Security works with lean engineering and IT teams, typically at companies with 50–200 employees. We help you understand the risks and plan the work that follows.

Start with your requirements

We discuss what prompted the assessment, which systems need testing and who will carry out the fixes before proposing the work.

Make the next steps practical

Recommendations account for your existing tools, engineering capacity and dependencies. Where appropriate, we discuss interim mitigations alongside longer-term fixes.

Keep the findings honest

Findings retain their assessed severity. Urgent risks are flagged promptly, and unresolved issues stay visible while your team works through them.

Services

Focused on the systems
your business relies on.

From customer-facing software to the infrastructure behind it, we shape the assessment around how your systems work together and the evidence you need.

Web, mobile
& API security

Test the workflows your customers depend on, from sign-in to account management. We examine how your application and its APIs protect data across different users, roles and customer accounts.

Application testing scope

Web applications & APIs. Authentication, access control, business logic, input handling and integrations, including REST, GraphQL and gRPC services.

iOS & Android. Local data storage, platform permissions, communication with backend services and the security boundaries between the app and device.

Cloud &
container platforms

Review the cloud services and deployment platforms behind your product, including container and Kubernetes environments. We focus on permissions, exposed services and the separation between workloads.

Cloud & container scope

AWS, Azure & Google Cloud. Identity and access policies, storage exposure, network configuration and managed services, scoped to the accounts your business operates.

Containers & orchestration. Container images, runtime settings, Kubernetes permissions, secrets and workload isolation. Infrastructure code and CI/CD configuration can be included in the review.

AI & LLM
applications

Assess what your AI features can access, reveal and do. Testing follows the way your assistants, agents and document-search features connect to business data and systems.

AI testing scope

Data & trust boundaries. Prompt injection, sensitive information exposure and access controls in retrieval-augmented generation (RAG) workflows, including separation between customers' documents.

Actions & integrations. Agent and tool permissions, approval controls, model output handling and usage limits. Findings explain the observed security impact in your application.

Networks
& identity

Understand what access to one account or device could mean for the rest of your environment. We examine external exposure, internal network boundaries and the identity controls your team relies on.

Network testing scope

External & internal networks. Internet-facing services, remote access, network segmentation and wireless security, with public exposure reviews where relevant.

Identity & endpoints. Active Directory and Entra ID configuration, authentication and privilege boundaries, alongside Windows, Linux and macOS hardening reviews.

Software review
& reverse engineering

Review security-sensitive behavior inside your software, from local data handling to privileged operations. Source code review, reverse engineering and runtime analysis help answer specific questions about desktop applications, services and compiled components.

Software review scope

With source code. Targeted review of security controls, sensitive data flows, dependencies and update mechanisms, supported by testing of the running application.

With compiled software. Binary analysis and reverse engineering to assess local storage, inter-process communication, memory safety and privilege boundaries. We agree the components and review depth before work begins.

What you receive

A report,
and a way forward.

A written record of what was assessed, what was found and what to do next. Ready for your internal review and the evidence package you share with auditors or customers.

Talk through your requirements
Executive summary & scope
A plain-language view of the risks that need management attention, with the systems assessed, testing approach and limitations clearly documented.
Technical findings
Each finding connects the affected component to evidence, business impact and recommended fixes, with assessed severity and CVSS scoring where applicable.
Remediation priorities
Recommended fixes and relevant implementation considerations. We distinguish urgency from effort and discuss interim mitigations where appropriate.
Remediation verification
Where included, a separate record links results to the original findings: fixed, partially fixed, not fixed or not tested. Verification evidence and remaining issues stay visible.
Completion letter
Where required in the agreed deliverables, a concise confirmation of the assessment scope and dates for your evidence package.

Working together

Know what happens next.

Your proposal sets out the work, the schedule and the support available after delivery.

  1. Agree the engagement

    Document the scope, fee and deliverables in the statement of work. Set access, testing boundaries and contacts in the rules of engagement.

  2. Test & communicate

    Test within the agreed window and keep your contact informed. Critical findings are raised promptly with evidence and immediate mitigation advice.

  3. Review the findings

    Walk through the report with your team, clarify the impact and discuss a practical remediation sequence.

  4. Verify the fixes

    Carry out the agreed retesting and document what has been resolved and what remains open.

Support sessions, retest rounds, deadlines and any additional fees are specified before work starts. Changes to scope are agreed in writing before additional work begins.

About Dexterity Security

Experienced testing.
A practical point of view.

Our consulting background includes security assessments for Fortune 500 technology companies and work at an international cybersecurity consultancy.

Dexterity Security brings that experience to smaller teams: carefully scoped assessments, straightforward conversations and recommendations grounded in how your business operates.

Professional certifications

OSCE³
OSED · OSEP · OSWE
GXPN
Advanced penetration testing
OSMR
macOS security
OSCP
Penetration testing
CRTO
Red team operations
OSWP
Wireless security

Before we begin

A few things
you may be wondering.

If you're arranging a test for the first time, we can help you work through the details.

What if we cannot fix everything immediately?

We help you distinguish urgent action from work that needs planning, taking your team's capacity and technical dependencies into account. Where appropriate, we discuss interim mitigations and their limits.

Findings keep their assessed severity, and outstanding risks remain documented. Any decision to accept risk belongs to your organization and must account for the requirements you need to meet.

What will you need from our team?

Typically, a technical point of contact, an agreed asset list, appropriate test access and any relevant documentation. We confirm the prerequisites before scheduling and ask who will handle remediation so the walkthrough reaches the right people.

What if we are not sure what needs testing?

Start with the request from your auditor or customer, your deadline and an outline of your systems. We help clarify the scope and requested evidence. If an expectation is unclear, we recommend confirming it with the party reviewing the report before testing begins.

How long does an assessment take?

A standard web application assessment typically involves one to two weeks of active testing. Preparation, report delivery and retesting have their own dates. Your proposal provides a schedule based on the actual scope, access requirements and availability.

How do pricing, support and retesting work?

We provide a fixed-price proposal after scoping. It specifies the testing and deliverables, the remediation discussions included, and the number and timing of any retest rounds. Additional implementation work, extra rounds or expanded scope are agreed separately before they begin.

Does a penetration test guarantee compliance?

The report provides evidence of the work completed within the agreed scope. Your auditor or customer determines whether that evidence meets their requirements. A report or summary letter is not a certification or a guarantee that every vulnerability has been identified.

Let's talk

Tell us what you need
to move forward.

Your deadline, the systems involved and what prompted the assessment are a useful place to start. We'll follow up to clarify scope and outline a fixed-price proposal.

Usually responds within 24 hours.

Discuss your assessment

A brief description is enough to get started.

If known, include your deadline and the systems you need tested.

Please leave out passwords, API keys and sensitive technical details. Read our privacy policy.