Do you perform penetration testing?
Yes — scoped web application penetration testing, run by a certified Web Penetration Tester under written authorisation and agreed rules of engagement. What is not included is full-scope red-team work, social engineering and physical intrusion: those need a different team, a different contract and a different conversation with your legal counsel. The scope is written down and signed before anything is tested.
Do we need to authorise the testing?
Yes, in writing, from whoever owns the assets — before anything begins. If the target runs on a third-party platform, that provider usually has to authorise it too. Testing infrastructure without documented authorisation is a legal problem for both sides, so it is a hard prerequisite rather than a formality.
We are a small company. Is this overkill?
The opposite: companies without a security team are the ones with the largest blind spot, and the discovery step is cheap. Knowing what you expose costs far less than finding out through an incident.
What do we get at the end?
An inventory of your external footprint, a test report with reproduction steps for each finding, severity and business impact, a mitigation plan with owners and dates, a risk register, and a monitoring baseline that keeps running. Retesting after remediation is agreed up front rather than sold back to you later.