Penetration testing Provider based in Sweden

Independent Penetration Testing Based in Sweden

Manual penetration testing across web, API, network and cloud, by testers employed in Sweden. You see the scope, the price and the tester’s name before you sign. Findings are CVSS v3.1-rated and the retest is included rather than quoted later.

  • Free retest included
  • Sweden-based testers
  • Board-ready report
eBuilder Security · Engagement In progress
Engagement in progress Phase 2 of 5
Methodology Reference v1.0 Free retest on close
Definition

A Manual Test, Not a Scan With a Logo on It

Both produce a list of findings. Only one tells you what an attacker can actually do once the easy issues are gone.

Vulnerability scan

Automated and Broad

  • Lists potential weaknesses from a signature database.
  • Logic flaws have no recognisable signature so scanners generally will not find them.
  • You receive a tool export. Your customer’s security reviewer will recognise it as one.
Penetration test

Manual, Chained, Proven

  • A tester works by hand across the agreed phases, then hands over.
  • Access handling and input handling tested against your real data model and trust boundaries.
  • Lower-severity issues chained together to demonstrate a realistic compromise path.
Shortlisting

What to Ask Any Penetration Testing Provider

Most pentest firms quote a day rate and a start date. Six questions tell you whose report will survive your customer’s security review. We answer all six below.

Is the Retest Included or Quoted Separately?

Ours is included. It is the most common hidden cost when comparing any penetration testing vendor.

Can I See a Redacted Sample Report First?

Ours is on this page. Almost no provider publishes one, so ask anyone else before you commit.

Who Does the Work and Where Do They Sit?

Sweden-based, employed, named before the engagement.

What Is the Manual-to-Automated Split?

Many pen testing companies will not answer this directly. If the answer is vague, you are buying a scan at manual prices.

Can the Report Be Shared Outside My Company?

Ours is written for that. Executive summary plus full technical detail.

Who Can Stop the Test and How?

Agreed in writing before we start, with named contacts on both sides.

Before you book anything

See Exactly What You Get

Every finding follows the same eleven-field structure. An executive summary for management, full evidence for the people fixing it and a retest attestation at the back.

1. Executive summary
Critical 1 High 3
Medium 5 Low 2
Finding, 11 fields

F-03 Broken access control
High CVSS 8.1

Evidence
1. Log in as user A
2. GET /api/v2/invoices/
3. Replace tenant id
4. Response returns 200

Retest attestation

F-01  Remediated
F-02  Remediated
F-03  Remediated
F-04  Risk accepted

Lead tester
Scope and cost

What We Test and What a Penetration Test Costs

Penetration testing cost depends on scope and tester-days, not on a headline day rate. These are the usual ranges. Your exact figure is fixed on a scoped quote before any testing begins.

Web Application and API

SEK 50,000 – 120,000 Web apps, portals and APIs

External Penetration Testing

SEK 50,000 – 100,000 Your internet-facing perimeter

Cloud, Azure or AWS

SEK 80,000 – 200,000 Tenant, identity and configuration

Internal Network and AD

SEK 80,000 – 220,000 Assumed breach from the inside

Mobile, iOS and Android

SEK 55,000 – 120,000 App, storage and backend APIs

Annual Penetration Test Programme

Scoped yearly Scheduled tests across the year
Scoping call

Scope Your Test in a 30-Minute Call

Thirty minutes, video or phone. You bring what you are worried about. We tell you what a test would cover, what it would cost and when we could start.

  1. 1
    You tell us what needs testing The application, perimeter, cloud account or network you are worried about and who is asking for the test.
  2. 2
    We tell you what to test and what to leave out Black box, grey box or white box per asset and the depth that gives you meaningful evidence rather than a longer invoice.
  3. 3
    You get an indicative price and a start date Tester-days, not a day rate. If your deadline moves, we tell you what is possible.
  4. 4
    You get a written scope summary Yours to keep and to put in front of any other provider. No obligation.

Thirty minutes. You leave with a scope, an indicative price.

Book a 30-Minute Scoping Call

Takes about a minute. We reply within one business day with available slots.

We protect your privacy. Your details are handled in line with GDPR, stored in the EU and used only to arrange your call. Read our privacy policy.

The deliverable

A Report You Can Forward the Same Day

Most penetration tests are bought because somebody else asked for one. So the report is written for two audiences from the start, not translated afterwards.

For management

Executive Summary

Readable by a non-technical stakeholder in a few minutes. What was tested, what was found, how serious it is and what should happen next. Suitable for a board paper or a customer’s security reviewer.

Plus a findings summary table for at-a-glance scanning.

For the people fixing it

Technical Findings

Written for the engineers who will fix the issues, with the full evidentiary detail needed to reproduce and remediate.

Title · severity · CVSS score · vector string · threat · root cause · affected component · evidence · observation and impact · explanation · recommendations.

Rather Read It Than Book a Call?

Take the redacted sample away and decide in your own time. We will not chase you.

How we test, phase by phase 14 phases across two tracks
Before anything is tested. No testing begins without a signed Letter of Authorization from someone with the legal authority to grant it, a documented scope covering what is explicitly out of scope, an agreed testing window with any blackout periods and a communication plan naming who can stop the test and how.

Infrastructure Track, 5 Phases

01

Reconnaissance

Gather from public sources without touching in-scope systems. Compile an inventory of likely target systems.

02

Scanning and Enumeration

Sweeping, TCP and UDP port scanning, OS fingerprinting. Automated results manually verified to rule out false positives.

03

Exploitation

Customise or develop PoC code for the target. Confirm or rule out each suspected vulnerability.

04

Post-Exploitation

Establish and document the access actually achieved. Persistence assessed and documented only, never left in place.

05

Cleanup

Implants, test accounts and config changes reversed. Full list of actions taken handed over for verification.

Application Track, 9 Phases

01

Recon and Mapping

Hidden and default content discovered. Full attack surface mapped for later phases.

02

Application Logic

Workflow bypasses and multi-stage process flaws. Trust boundaries between roles and tenants, race conditions.

03

Access Handling

IDOR across all identifiers, vertical and horizontal escalation. MFA bypass paths, session fixation, CSRF protections.

04

Input Handling

SQLi, XSS, SSRF, SSTI, path traversal, deserialisation. Upload validation bypass, XXE, NoSQL and LDAP injection.

05

API Security

BOLA and BFLA across object and admin endpoints. JWT algorithm confusion, mass assignment, GraphQL abuse.

06

Hosting and Configuration

Tenant segregation, dangerous HTTP methods, open proxy. Security headers, TLS configuration, known CVEs.

07

Client-Side and Local

DOM-based XSS, postMessage origin validation. Browser storage, clickjacking, source maps and stack traces.

08

Impact Demonstration

Findings chained into a realistic compromise path. Safe, minimal proof. No bulk exfiltration, no service degradation.

09

Follow-Up Testing

Every finding re-tested and re-rated before the report is final. After you remediate: root cause, regressions, related code paths.

Rating scale and standards mapping CVSS, NIST SP 800-115, OWASP Top 10
RatingDescriptionTypical criteria
CriticalImmediate, severe risk to confidentiality, integrity or availability.Unauthenticated RCE, full database compromise, complete authentication bypass.
HighSignificant risk requiring urgent remediation.Authenticated RCE, broken access control exposing all user data, SQLi with extraction.
MediumMeaningful risk, typically requiring an additional factor to exploit.Reflected XSS on an authenticated page, IDOR on non-sensitive data, missing rate limiting.
LowLimited risk, often defence in depth.Missing security headers, verbose errors, outdated software with no known exploit.
InfoNo direct risk but worth recording.Best-practice deviations and observations.

Ratings are informed by CVSS but adjusted for your business context. A high CVSS score behind strong compensating controls is rated differently from the same issue sitting exposed. Every rating carries a written rationale.

NIST SP 800-115Covered in
PlanningPre-engagement, scoping, authorisation
DiscoveryReconnaissance, scanning and enumeration
AttackExploitation, post-exploitation
ReportingFindings, risk rating, retest, debrief
OWASP Top 10Covered in
A01 Broken Access ControlAccess handling, API security
A03 InjectionInput handling, client-side
A04 Insecure DesignApplication logic
A05 MisconfigurationHosting and configuration

All ten OWASP categories are mapped in the full methodology. A09, logging and monitoring, is cross-cutting.

Compliance

An Audit or Certification

Commissioning ISO 27001 penetration testing or evidence for another framework? Findings map to the control you need and the retest attestation closes the finding rather than leaving it open.

ISO 27001

A.8.8 and A.8.29

Technical vulnerability management and security testing in development. Independent evidence auditors expect at Stage 2.

NIS2 / Cybersäkerhetslagen

Article 21(2)

Vulnerability handling and testing the effectiveness of your security measures. In Sweden, implemented as SFS 2025:1506.

DORA

Articles 24 to 27

Digital operational resilience testing. Baseline testing for financial entities, with TLPT applying separately to significant ones.

PCI DSS v4.0

Requirement 11.4

Internal and external penetration testing at least annually. Scoped CDE testing with retest confirmation.

Trusted by 100+ Swedish Kommuner, Regions and Corporations Since 2002

References

In Their Own Words

Questions

Asked Before Every Scoping Call

Is the retest included?

Yes, at no extra cost. Follow-up testing verifies the fix against the original evidence, confirms it addresses the root cause rather than the payload we reported and checks for regressions. Finding status is updated to remediated, partially fixed or risk accepted, with supporting evidence.

Can I send the report to my customer?

Yes. The executive summary is written to be read by a non-technical stakeholder in a few minutes and the report includes scope confirmation and a findings summary table. If you need a version with internal hostnames removed we produce it as part of the engagement rather than as an extra.

Will you break production?

Scanning is conducted to minimise the risk of destabilising target systems, particularly against production. Proof-of-concept code is tested in an isolated environment before it is used against your systems. Any technique carrying a risk of service disruption is agreed explicitly during scoping and a stop-testing procedure is in place before we start.

What happens to anything you leave behind?

Cleanup is a formal phase. Web shells, implants, test accounts and configuration changes are removed, uploaded tooling is confirmed gone and you receive a full list of actions taken so your team can verify the environment is back to its pre-engagement state.

What if you find nothing serious?

Then the report says so and it documents what was tested and how, which is the evidence your customer or auditor needs. We do not inflate severity to justify the invoice. We will also tell you honestly if the scope was too narrow to be meaningful.

Do you run red team engagements?

Yes, as a separate engagement with its own rules of engagement. For most organisations at this size we recommend a scoped penetration test first, because an objective-led adversary simulation assumes your known issues are already closed.

How soon can you start and how far ahead do we need to book?

We confirm the start date when the scope is signed. Most Swedish providers are booking four to eight weeks out. If you have a date in mind, raise it on the first call and we will tell you where we can fit it.

Can you work to a fixed date, such as an audit, a release or a customer deadline?

Yes and most engagements have one. Bring the date to the call. We will tell you what can be tested properly in the time and what would have to come out.

How long do we have to use the free retest?

The retest window is agreed at scoping so it fits your release plan. If your fix waits on a release train or a supplier, tell us and we will not quote you for a second engagement.

Do you charge a day rate?

No. You get a fixed price for an agreed scope, shown in tester-days. Retest, executive summary and debrief are inside the fee, not added to it.

What is included in the price and what would be extra?

Included: scoping, the test, the report, the debrief and the retest. Extra only if you widen the scope mid-engagement and we have agreed it in writing before we act on it.

If you find something critical mid-test, do we wait for the report?

No. Criticals go to your named contact as soon as they are confirmed. The escalation path is agreed in writing before testing starts.

Do we get a summary or attestation we can share externally?

Yes. The report closes with a retest attestation stating what was tested, when, by whom, the methodology and the remediation status at close. It is written to be forwarded to a customer or an auditor.

Our customer’s questionnaire asks for an independent test within the last twelve months. Does this answer it?

In most cases, yes. The report states scope, dates, methodology, findings and retest status plainly. Bring the questionnaire to the call. Occasionally a reviewer specifies a particular standard and we can check it against the scope.

What changes on 1 October 2026?

MCFFS 2026:11 takes effect. It requires organisations covered by Cybersäkerhetslagen to run security tests and reviews. Its general advice names both automated and manual testing but does not name penetration testing. A scoped manual test with a retest is one way to evidence it, not the only one.

MCFFS 2026:12 lands the same day but governs how the regulator runs its own audits. It obliges you to commission nothing.

Do you sign an NDA and a data processing agreement?

Yes to both. We can send drafts before the scoping call so legal review runs in parallel. Your templates work too.

Ready to Scope It? Thirty Minutes to Scope Your Test.

Indicative price and a start date on the call. No obligation.

Book a 30-minute scoping call
Free retest included Sweden-based testers

Not ready yet?