WHAT WE DO

Cyber Security Services

From application penetration testing to compliance advisory, each engagement is run by certified consultants who stay with the work from scoping to re-test — and delivered with output your engineers can act on.

01

Web Application Penetration Testing

Web applications are the most common entry point for attackers. Our Web Application Penetration Testing (WAPT) service delivers a thorough, manual-first assessment of your web-facing applications — covering everything from input validation and authentication bypass to complex multi-step business logic flaws that automated scanners structurally cannot detect. We test against the OWASP Top 10, the WSTG (Web Security Testing Guide), and custom threat models developed specifically for your application's architecture and business context.

WHAT'S INCLUDED

  • Reconnaissance & attack surface mapping
  • Authentication & session management testing
  • OWASP Top 10 vulnerability assessment
  • Business logic and workflow abuse testing
  • File upload, injection, and encoding vulnerability testing
  • API endpoint security review
  • Detailed technical report + executive summary
  • Complimentary re-test after remediation
OWASPWSTGAuth BypassIDORSQLiXSSSSRFCSRF
View service details
02

Mobile Application Penetration Testing

Mobile applications present a distinct and often underestimated attack surface. Our Mobile Application Penetration Testing service covers both iOS and Android platforms with a methodology aligned to the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Security Testing Guide (MSTG). We conduct both static and dynamic analysis — examining the application binary, local data storage, network communication, authentication flows, and runtime behaviour.

WHAT'S INCLUDED

  • Static analysis — binary, code, and configuration review
  • Dynamic analysis — runtime behaviour and instrumentation
  • Reverse engineering and binary protections assessment
  • Certificate pinning and SSL/TLS communication testing
  • Local storage and data leakage assessment
  • API authentication and authorisation testing
  • Backend API security review
  • OWASP MASVS Level 1 & Level 2 coverage
iOSAndroidOWASP MASVSMSTGFridaBurp SuiteAPI Security
View service details
03

API Security Testing

APIs are the connective tissue of modern applications — and consistently the most exploited attack surface in enterprise breaches. Our API Security Testing service covers REST, GraphQL, and SOAP APIs with a methodology rooted in the OWASP API Security Top 10 and enriched with real-world attacker techniques. We go beyond basic input validation to test for BOLA/IDOR, broken function-level authorisation, mass assignment, unrestricted resource consumption, and security misconfiguration.

WHAT'S INCLUDED

  • API discovery and full endpoint enumeration
  • Authentication and authorisation testing (OAuth, JWT, API Keys)
  • OWASP API Security Top 10 assessment
  • BOLA / IDOR and privilege escalation testing
  • Mass assignment and parameter tampering
  • Rate limiting and throttling bypass testing
  • GraphQL-specific testing (introspection, batching attacks, query depth)
  • API documentation and schema review
RESTGraphQLSOAPBOLAOAuthJWTOWASP API Top 10
04

AI / LLM Security Testing

The rapid integration of large language models into enterprise products has created an entirely new category of security risk. Most traditional penetration testing firms are not equipped to test these surfaces. Varihunt is. Our AI and LLM Security Testing service is built on active research into GenAI attack surfaces, aligned to the OWASP LLM Top 10, and informed by real-world red team exercises against AI-powered products.

WHAT'S INCLUDED

  • Prompt injection — direct and indirect attack testing
  • Jailbreak and safety guardrail bypass assessment
  • Sensitive data and PII exfiltration via model outputs
  • Insecure output handling and downstream injection risks
  • Model denial-of-service and resource exhaustion testing
  • RAG pipeline and vector database security review
  • Third-party model and plugin supply chain risk assessment
  • OWASP LLM Top 10 full coverage report
Prompt InjectionLLMGenAIOWASP LLM Top 10RAG SecurityEU AI Act
05

IT Security & Audit Services

A security audit is only valuable if it produces clear, actionable output that your organisation can actually implement. Our IT Security and Audit service combines technical assessment with regulatory expertise to give you a 360-degree view of your security posture — and a prioritised roadmap to improve it. We deliver structured gap analyses against the frameworks that matter to your regulators, your customers, and your board.

WHAT'S INCLUDED

  • Comprehensive security posture gap analysis
  • Risk register development and threat landscape mapping
  • Framework mapping: ISO 27001, GDPR, NIS2, DORA, SOC 1, SOC 2, PCI-DSS
  • Security policy and procedure review
  • Access control and identity management assessment
  • Third-party and supply chain risk review
  • Executive summary and board-ready reporting
  • Remediation roadmap with prioritised action plan
ISO 27001GDPRNIS2DORASOC 1SOC 2PCI-DSSRisk Register
06

Tabletop & Desktop Exercises

Your incident response plan is only as good as the last time you tested it under pressure. Tabletop and desktop exercises are the most effective way to validate your team's readiness, identify process gaps, and build the muscle memory that matters when a real incident strikes. Varihunt facilitates structured, scenario-based exercises tailored to your industry, threat landscape, and organisational structure.

WHAT'S INCLUDED

  • Pre-exercise threat landscape briefing tailored to your sector
  • Scenario design: ransomware, data breach, DDoS, insider threat, supply chain attack
  • Facilitated exercise session (half-day or full-day format)
  • Parallel technical and executive track options
  • Real-time inject escalations to test decision-making under pressure
  • Post-exercise hot wash and findings debrief
  • Written report with identified gaps and recommended playbook improvements
Incident ResponseRansomware SimulationRed TeamExecutive BriefingIR Playbook
07
COMPLIANCE ADVISORY

ISO 27001 Implementation & Audit Support

End-to-end support for organisations pursuing ISO 27001 certification — from gap analysis and ISMS design to control implementation, internal audits, and certification readiness.

WHAT'S INCLUDED

  • Initial ISO 27001 gap analysis against all Annex A controls
  • Information Security Management System (ISMS) scope definition
  • Risk assessment and risk treatment plan development
  • Statement of Applicability (SoA) preparation
  • Security policy and procedure documentation
  • Control implementation guidance across all 93 Annex A controls
  • Internal audit facilitation
  • Certification body (Stage 1 & Stage 2) audit readiness assessment
  • Post-certification surveillance support
ISO 27001ISO 27002ISMSGap AnalysisSoAInternal AuditAnnex A
08
COMPLIANCE ADVISORY

NIS2 Compliance Advisory

The EU's NIS2 Directive expands cybersecurity obligations across 18 critical sectors with significant penalties for non-compliance. We assess, gap-analyse, and build your NIS2 compliance roadmap.

WHAT'S INCLUDED

  • NIS2 applicability assessment — essential vs important entity classification
  • Gap analysis against all NIS2 Article 21 security measures
  • Supply chain and third-party risk evaluation
  • Incident reporting procedure design (72-hour notification compliance)
  • Governance and board-level accountability framework
  • Risk management programme development
  • NIS2 compliance roadmap with prioritised remediation steps
  • Ongoing compliance monitoring advisory
NIS2EU Cyber ResilienceIncident ReportingSupply Chain RiskBoard Accountability
09
COMPLIANCE ADVISORY

SOC 1 Readiness & Advisory

SOC 1 reports are critical for service organisations that impact clients' financial reporting. We help you define scope, document controls, and prepare for Type I or Type II audit.

WHAT'S INCLUDED

  • Service organisation boundary and scope definition
  • Identification of relevant financial reporting control objectives
  • Control documentation and control matrix development
  • Gap analysis and control deficiency remediation guidance
  • Management assertion and description of the system preparation support
  • Type I readiness assessment — design of controls
  • Type II readiness assessment — operating effectiveness over a defined period
  • Auditor liaison support during the formal SOC 1 audit
SOC 1SSAE 18ISAE 3402Type IType IIFinancial ControlsService Organisations
10
COMPLIANCE ADVISORY

SOC 2 Readiness & Advisory

SOC 2 is now the baseline trust credential for SaaS and technology companies selling to enterprise buyers. We guide you through control design, evidence collection, and audit readiness — faster and without the false starts.

WHAT'S INCLUDED

  • Trust Services Criteria scoping — Security, Availability, Confidentiality, Privacy, Processing Integrity
  • Control environment gap analysis against chosen criteria
  • Control design and implementation guidance
  • Policy and procedure documentation support
  • Evidence collection programme and tooling recommendations
  • Vendor and third-party risk management framework
  • Type I readiness assessment
  • Type II readiness assessment — 3, 6, or 12-month observation period support
  • Auditor selection guidance and liaison support
SOC 2Trust Services CriteriaType IType IISaaS SecurityCompliance Automation

CHOOSING AN ENGAGEMENT

Which service fits your situation?

Most engagements begin with a conversation rather than a fixed package. The questions below cover what buyers typically ask before scoping a project.

Which service do I need if I am not sure?

If you are preparing for a compliance audit, an IT Security and Audit engagement or the relevant compliance advisory (ISO 27001, NIS2, SOC 1, or SOC 2) is usually the starting point, because it identifies the gaps that testing and remediation should target. If you have a live application and want to understand its exposure before an audit, a web, mobile, or API penetration test is the direct route. If your product uses large language models, the AI and LLM security testing service applies. A scoping call will narrow this down based on your architecture, regulatory deadlines, and what your customers or board are asking for.

How are engagements priced?

Penetration testing and advisory engagements are scoped and fixed-price, not hourly. The price is based on the size and complexity of the target surface, the number of environments, the platforms involved, and the reporting and retest requirements. After the scoping call, you receive a written proposal with the scope, deliverables, timeline, and fixed fee. There are no additional charges for the retest, which is included in the engagement.

How quickly can testing start?

Typical lead time from a signed proposal to the start of active testing depends on consultant availability and the time required to prepare access, test accounts, and documentation. We will give you an accurate start date during scoping rather than an estimate in marketing copy. If you have a fixed regulatory deadline, tell us during the first call so the timeline can be planned around it.

Can you work under NDA and within our regulatory region?

Yes. Engagements are conducted under a mutual non-disclosure agreement, and findings are treated as confidential. With offices in Finland, the United States, and the UAE, engagements can be delivered within EU, US, or Gulf regulatory contexts, and data handling can be aligned with GDPR or equivalent requirements. Where a specific data residency or contractual clause is required, it is agreed before the engagement begins.

What qualifications do your consultants hold?

Our consultants hold industry-recognised certifications including CISA and ISO 27001:2022 Lead Auditor, and testing is performed against established standards: OWASP WSTG for web applications, OWASP MASVS and MSTG for mobile, and the OWASP API Security Top 10 for APIs. CVSS v3.1 is used for severity rating. Certifications and standards inform the work, but the measure that matters to buyers is that the people who scope the engagement run it and write the report.

Do you offer ongoing testing programmes?

Yes. Where a compliance programme or a rapidly changing environment warrants it, engagements can be structured as recurring testing cycles rather than one-off assessments. Annual or more frequent cadences are agreed explicitly and aligned to your regulatory deadlines and release cycles. The objective is a programme that keeps evidence current, not a recurring retainer for its own sake.

How are findings delivered and tracked?

Findings are delivered in a report with an executive summary for leadership and a technical section for engineering. Each finding includes its CVSS severity, a proof of concept, the root cause, and prioritised remediation guidance. After remediation, a complimentary retest verifies the fixes, and an attestation letter is issued. The engagement is not considered closed until the retest is complete.

FAQ

Frequently asked questions

How long does the test take?

Engagement length varies by service and scope. Application testing depends on the size and complexity of the target surface; compliance advisory depends on the framework and organisational maturity. A precise timeline is confirmed during scoping. Testing is delivered in sprints with regular progress updates.

What testing methodology do you follow?

Testing follows established standards: OWASP WSTG for web, OWASP MASVS and MSTG for mobile, the OWASP API Security Top 10 for APIs, and the OWASP LLM Top 10 for AI. PTES informs scoping and reporting, and CVSS v3.1 is used for severity rating. Every finding is manually validated.

Is a retest included?

Yes. Penetration testing engagements include a complimentary retest after remediation. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price and the engagement is not closed until it is complete.

What does the report contain?

Reports include an executive summary for leadership and a technical section for engineering. Each finding has its CVSS severity, a proof of concept, the root cause, and prioritised remediation guidance. Findings are mapped to the relevant framework and control objectives where applicable.

Does this satisfy NIS2 or ISO 27001 requirements?

Testing does not by itself constitute compliance with NIS2, ISO 27001, SOC 1, or SOC 2. It provides evidence for specific control objectives within each framework. Compliance is achieved through the broader control environment, policies, and processes, with testing as one input. We align testing to your compliance programme.

What do you need from us before testing starts?

Before an engagement, we need a description of the target or programme, the platforms and technologies involved, available environments, and any regulatory drivers or deadlines. Rules of engagement, timelines, and points of contact are agreed during scoping. Written authorisation is confirmed before work begins.

Not sure which service fits?

Start with a conversation. We'll look at your situation and recommend the right engagement — and tell you if you don't need one yet.

Request a Scoping Call