ISO 27001
A.8.8 and A.8.29
Technical vulnerability management and security testing in development. Independent evidence auditors expect at Stage 2.
Manual penetration testing across web, API, network and cloud, by testers employed in Sweden. You see the scope, the price and the tester’s name before you sign. Findings are CVSS v3.1-rated and the retest is included rather than quoted later.
Both produce a list of findings. Only one tells you what an attacker can actually do once the easy issues are gone.
Most pentest firms quote a day rate and a start date. Six questions tell you whose report will survive your customer’s security review. We answer all six below.
Ours is included. It is the most common hidden cost when comparing any penetration testing vendor.
Ours is on this page. Almost no provider publishes one, so ask anyone else before you commit.
Sweden-based, employed, named before the engagement.
Many pen testing companies will not answer this directly. If the answer is vague, you are buying a scan at manual prices.
Ours is written for that. Executive summary plus full technical detail.
Agreed in writing before we start, with named contacts on both sides.
Every finding follows the same eleven-field structure. An executive summary for management, full evidence for the people fixing it and a retest attestation at the back.
F-03 Broken access control
High CVSS 8.1
Evidence
1. Log in as user A
2. GET /api/v2/invoices/
3. Replace tenant id
4. Response returns 200
F-01 Remediated
F-02 Remediated
F-03 Remediated
F-04 Risk accepted
Penetration testing cost depends on scope and tester-days, not on a headline day rate. These are the usual ranges. Your exact figure is fixed on a scoped quote before any testing begins.
Thirty minutes, video or phone. You bring what you are worried about. We tell you what a test would cover, what it would cost and when we could start.
Thirty minutes. You leave with a scope, an indicative price.
Takes about a minute. We reply within one business day with available slots.
We protect your privacy. Your details are handled in line with GDPR, stored in the EU and used only to arrange your call. Read our privacy policy.
Most penetration tests are bought because somebody else asked for one. So the report is written for two audiences from the start, not translated afterwards.
Readable by a non-technical stakeholder in a few minutes. What was tested, what was found, how serious it is and what should happen next. Suitable for a board paper or a customer’s security reviewer.
Plus a findings summary table for at-a-glance scanning.
Written for the engineers who will fix the issues, with the full evidentiary detail needed to reproduce and remediate.
Title · severity · CVSS score · vector string · threat · root cause · affected component · evidence · observation and impact · explanation · recommendations.
Take the redacted sample away and decide in your own time. We will not chase you.
Gather from public sources without touching in-scope systems. Compile an inventory of likely target systems.
Sweeping, TCP and UDP port scanning, OS fingerprinting. Automated results manually verified to rule out false positives.
Customise or develop PoC code for the target. Confirm or rule out each suspected vulnerability.
Establish and document the access actually achieved. Persistence assessed and documented only, never left in place.
Implants, test accounts and config changes reversed. Full list of actions taken handed over for verification.
Hidden and default content discovered. Full attack surface mapped for later phases.
Workflow bypasses and multi-stage process flaws. Trust boundaries between roles and tenants, race conditions.
IDOR across all identifiers, vertical and horizontal escalation. MFA bypass paths, session fixation, CSRF protections.
SQLi, XSS, SSRF, SSTI, path traversal, deserialisation. Upload validation bypass, XXE, NoSQL and LDAP injection.
BOLA and BFLA across object and admin endpoints. JWT algorithm confusion, mass assignment, GraphQL abuse.
Tenant segregation, dangerous HTTP methods, open proxy. Security headers, TLS configuration, known CVEs.
DOM-based XSS, postMessage origin validation. Browser storage, clickjacking, source maps and stack traces.
Findings chained into a realistic compromise path. Safe, minimal proof. No bulk exfiltration, no service degradation.
Every finding re-tested and re-rated before the report is final. After you remediate: root cause, regressions, related code paths.
| Rating | Description | Typical criteria |
|---|---|---|
| Critical | Immediate, severe risk to confidentiality, integrity or availability. | Unauthenticated RCE, full database compromise, complete authentication bypass. |
| High | Significant risk requiring urgent remediation. | Authenticated RCE, broken access control exposing all user data, SQLi with extraction. |
| Medium | Meaningful risk, typically requiring an additional factor to exploit. | Reflected XSS on an authenticated page, IDOR on non-sensitive data, missing rate limiting. |
| Low | Limited risk, often defence in depth. | Missing security headers, verbose errors, outdated software with no known exploit. |
| Info | No direct risk but worth recording. | Best-practice deviations and observations. |
Ratings are informed by CVSS but adjusted for your business context. A high CVSS score behind strong compensating controls is rated differently from the same issue sitting exposed. Every rating carries a written rationale.
| NIST SP 800-115 | Covered in |
|---|---|
| Planning | Pre-engagement, scoping, authorisation |
| Discovery | Reconnaissance, scanning and enumeration |
| Attack | Exploitation, post-exploitation |
| Reporting | Findings, risk rating, retest, debrief |
| OWASP Top 10 | Covered in |
|---|---|
| A01 Broken Access Control | Access handling, API security |
| A03 Injection | Input handling, client-side |
| A04 Insecure Design | Application logic |
| A05 Misconfiguration | Hosting and configuration |
All ten OWASP categories are mapped in the full methodology. A09, logging and monitoring, is cross-cutting.
Commissioning ISO 27001 penetration testing or evidence for another framework? Findings map to the control you need and the retest attestation closes the finding rather than leaving it open.
A.8.8 and A.8.29
Technical vulnerability management and security testing in development. Independent evidence auditors expect at Stage 2.
Article 21(2)
Vulnerability handling and testing the effectiveness of your security measures. In Sweden, implemented as SFS 2025:1506.
Articles 24 to 27
Digital operational resilience testing. Baseline testing for financial entities, with TLPT applying separately to significant ones.
Requirement 11.4
Internal and external penetration testing at least annually. Scoped CDE testing with retest confirmation.
Trusted by 100+ Swedish Kommuner, Regions and Corporations Since 2002








eBuilder Security helps us meet our IT and information security needs. We are very satisfied by their deep knowledge, comprehensive services, and dedication to strengthening our cybersecurity posture. From End Point Protection and advisory and auditing to penetration testing, eBuilder Security has been a reliable partner in safeguarding our organization.
Christian Sørensen
Internal Operations Director, Médecins Sans Frontières, Norway
Through their range of security services and our decision to choose their MDR solution, eBuilder Security has significantly elevated our security posture. During the implementation phase, they were quick to assist and propose solutions to any challenges we encountered. The transition from project to production has been smooth, and their backend team quickly grasped our business needs. eBuilder Security is a valued partner for our future security efforts.
Gerth Ericsson
IT Manager, Vandewiele, Sweden
The product increases knowledge and security awareness. It helps organizations develop a good information security culture. I am particularly pleased that it is an end-to-end solution where eBuilder Security takes care of the entire process from kick-off to reporting, while allowing for customization to suit the conditions unique to our business.
Per Eriksson
Information Security Strategist, Varbergs Kommun, Sweden
Yes, at no extra cost. Follow-up testing verifies the fix against the original evidence, confirms it addresses the root cause rather than the payload we reported and checks for regressions. Finding status is updated to remediated, partially fixed or risk accepted, with supporting evidence.
Yes. The executive summary is written to be read by a non-technical stakeholder in a few minutes and the report includes scope confirmation and a findings summary table. If you need a version with internal hostnames removed we produce it as part of the engagement rather than as an extra.
Scanning is conducted to minimise the risk of destabilising target systems, particularly against production. Proof-of-concept code is tested in an isolated environment before it is used against your systems. Any technique carrying a risk of service disruption is agreed explicitly during scoping and a stop-testing procedure is in place before we start.
Cleanup is a formal phase. Web shells, implants, test accounts and configuration changes are removed, uploaded tooling is confirmed gone and you receive a full list of actions taken so your team can verify the environment is back to its pre-engagement state.
Then the report says so and it documents what was tested and how, which is the evidence your customer or auditor needs. We do not inflate severity to justify the invoice. We will also tell you honestly if the scope was too narrow to be meaningful.
Yes, as a separate engagement with its own rules of engagement. For most organisations at this size we recommend a scoped penetration test first, because an objective-led adversary simulation assumes your known issues are already closed.
We confirm the start date when the scope is signed. Most Swedish providers are booking four to eight weeks out. If you have a date in mind, raise it on the first call and we will tell you where we can fit it.
Yes and most engagements have one. Bring the date to the call. We will tell you what can be tested properly in the time and what would have to come out.
The retest window is agreed at scoping so it fits your release plan. If your fix waits on a release train or a supplier, tell us and we will not quote you for a second engagement.
No. You get a fixed price for an agreed scope, shown in tester-days. Retest, executive summary and debrief are inside the fee, not added to it.
Included: scoping, the test, the report, the debrief and the retest. Extra only if you widen the scope mid-engagement and we have agreed it in writing before we act on it.
No. Criticals go to your named contact as soon as they are confirmed. The escalation path is agreed in writing before testing starts.
Yes. The report closes with a retest attestation stating what was tested, when, by whom, the methodology and the remediation status at close. It is written to be forwarded to a customer or an auditor.
In most cases, yes. The report states scope, dates, methodology, findings and retest status plainly. Bring the questionnaire to the call. Occasionally a reviewer specifies a particular standard and we can check it against the scope.
MCFFS 2026:11 takes effect. It requires organisations covered by Cybersäkerhetslagen to run security tests and reviews. Its general advice names both automated and manual testing but does not name penetration testing. A scoped manual test with a retest is one way to evidence it, not the only one.
MCFFS 2026:12 lands the same day but governs how the regulator runs its own audits. It obliges you to commission nothing.
Yes to both. We can send drafts before the scoping call so legal review runs in parallel. Your templates work too.
Indicative price and a start date on the call. No obligation.
Book a 30-minute scoping callNot ready yet?