Service · Offensive
Penetration testing: we attack before someone else does.
Realistic attack simulations by certified ethical hackers. You learn where an attacker gets in, how far they get and what you need to do about it. In language your management understands too.
from CHF 7,800
fixed price, no surprises
1 – 10 days
depending on scope
30 days
retest included
2 reports
executive and technical, with CVSS
What we test
You choose the target area, we choose the attack methods. Remote or on site, in Switzerland.
External
Everything reachable from the internet: firewalls, VPN, mail servers, websites. The view of an attacker with no access.
Internal
What happens once an attacker is inside? Lateral movement, privilege escalation, access to domain controllers and backups.
Web applications and APIs
Custom applications, customer portals, interfaces. Based on OWASP, but focused on what actually causes damage in your case.
Cloud
Microsoft 365, Azure, AWS: misconfigurations, excessive permissions, open storage. The most common entry point at SMEs.
Mobile
iOS and Android apps including the backend. Data storage, communication, authentication.
Social engineering
Phishing, phone calls, physical access. Because the easiest way into a company usually goes through people.
Transparent packages
All prices in Swiss francs excluding VAT. Custom scoping is possible at any time.
Starter
CHF 7,800
Single scope, up to 5 days
- 1 target area (web or network)
- Executive and technical report
- 30-day retest included
- Social engineering module
- Red team scenarios
Professional · Popular
CHF 9,800
Multi-scope, up to 10 days
- 3 target areas
- Executive and technical report
- 30-day retest included
- Social engineering module
- Red team scenarios
Red Team
On request
Full adversary simulation
- Unrestricted scope
- Executive and technical report
- Retest and debrief
- Social engineering and physical access
- Full red team scenarios
A proven process
Scoping call
Define goals, rules of engagement and success criteria. What may be tested, what may not, when, and whom we call if something goes wrong.
Reconnaissance
OSINT collection and passive footprinting. What does the internet know about your company that an attacker would use?
Active testing
Exploitation, lateral movement, privilege escalation. Controlled, documented, without disrupting operations.
Reporting
Technical report with CVSS ratings and reproduction steps for your IT. Executive report with risks and priorities for management.
Retest
Within 30 days we verify that the fixes work. Included in Starter and Professional.
Frequently asked questions
What does a penetration test cost in Switzerland?
With us, from CHF 7,800 for one target area and CHF 9,800 for three target areas including social engineering. Red team engagements are quoted individually. All prices exclude VAT, with no hidden day rates.
Will the test disrupt operations?
No. We test in a controlled way and agree risky steps with you beforehand. If needed, we test outside business hours.
How is this different from a vulnerability scan?
A scanner finds known vulnerabilities and produces a list. A penetration test shows which of them an attacker can actually chain together to reach your data. That is the difference between 400 findings and the 5 that matter.
Do I need a pentest for cyber insurance or ISO 27001?
Increasingly, yes. Many insurers require a recent pentest, and ISO 27001 as well as NIS2 expect regular technical testing. Our reports are designed for that.
How often should I test?
At least once a year and after every major change: new application, cloud migration, acquisition. Between tests, Spectacles makes sure you see what is going on.
Request a quote
Briefly describe what should be tested. You will receive a concrete quote with scope, duration and fixed price within one business day.