Skip to content
MAWT Logo
Security

Test your defenses the way an attacker would under contract.

Overview

Targeted penetration tests on your web applications, APIs and infrastructure. Clear scope, prioritized findings, and a re-test once you have fixed them.

A penetration test is a controlled, authorized attack simulation against a defined scope — a web application, an API, your infrastructure — to find exploitable weaknesses before real attackers do. MAWT runs pentests through proven senior security specialists, with a clear contractual scope, a prioritized and actionable report, and a re-test after remediation. One point of contact throughout.

Target

For Swiss SMEs that need an independent, evidence-based view of their exposure — because a large client or contract requires it, because they handle sensitive data, or because they are about to launch a product and want it tested before attackers do it for free.

Details

A penetration test gives you what no checklist can: independent evidence of what a skilled attacker could actually achieve against your web application, API or infrastructure. It is the proof large clients ask for before signing, and the reality check every internet-facing product deserves before launch.

MAWT runs pentests through proven senior security specialists, under a single point of contact. The scope is contractual and agreed before anything starts; the report separates management priorities from developer detail; and the re-test after your fixes is part of the engagement. No fear-selling, no absolute guarantees — a rigorous snapshot you can act on and share.

When a pentest is the right tool

A penetration test answers a specific question: can a motivated attacker, starting from a defined position, actually get in — and how far? That makes it the right tool when you need independent evidence: a large client requires it before signing, a partner demands it in a contract, or you are about to expose a new product to the internet.

It is not the right first step for everyone. If you have never reviewed your basics — MFA, backups, access rights — a pentest will mostly confirm what a cheaper assessment would have told you. We say so when that is the case, and suggest starting with our cybersecurity assessment or application security testing instead.

A clear scope, agreed before anything starts

Every engagement starts with a written scope: which systems are targeted, from what position (external, internal, authenticated or not), during which window, with which methods, and what is explicitly off-limits. This protects your production systems, your data and your legal position — testing without documented authorization is not something serious professionals do.

We coordinate timing with your team, agree on an emergency stop procedure, and define how sensitive findings are communicated. Production stays safe: destructive techniques are excluded by default, and anything potentially disruptive is agreed case by case.

  • Written scope and rules of engagement, signed before testing begins
  • Defined testing windows coordinated with your operations
  • Explicit exclusions to protect production and third-party systems
  • Emergency contact and stop procedure on both sides
  • Confidential handling of findings and any data encountered

Senior testers, honest methodology

MAWT operates penetration tests through a network of proven senior security specialists — people selected for track record, not certificates on a wall. Each engagement is matched to the right profile: web application specialists for your customer portal, infrastructure specialists for your network perimeter.

We are equally honest about limits. A pentest is a snapshot of a defined scope during a defined window. It does not prove the absence of vulnerabilities, and no serious provider will claim otherwise. What it proves is what a skilled attacker could achieve against that scope, at that time — which is exactly the evidence clients and auditors ask for.

The report is the product — and the re-test closes the loop

A pentest that ends with a PDF nobody can act on has failed. Our reports separate what management needs — risk, business impact, priorities — from what developers need: reproduction steps, affected components, concrete remediation guidance. Findings are ranked by actual exploitability in your context, not by raw scanner scores.

Then we close the loop: once your team (or ours — our developers can implement fixes directly) has remediated, we re-test the affected findings and update the report. You end with a document that shows not just what was found, but what was fixed — the version a client's security team actually wants to see.

What it includes
  • Web application and API penetration tests
  • External and internal infrastructure tests
  • Clear contractual scope, rules of engagement and authorization
  • Findings prioritized by real-world exploitability and impact
  • A report readable by both management and developers
  • Re-test after fixes, included in the engagement
Deliverables
  • A signed scope and rules of engagement before any testing
  • A report with an executive summary and detailed technical findings
  • Findings prioritized by exploitability and business impact, with remediation guidance
  • A debrief session with your technical team and management
  • A re-test of remediated findings, with an updated report you can share
Takeaways
  • A pentest provides independent evidence: what an attacker could actually achieve.

  • The scope is contractual — no testing without written authorization.

  • Findings are ranked by real exploitability, not scanner scores.

  • The re-test after fixes is included: the loop gets closed.

  • A pentest is a snapshot, not a guarantee — anyone claiming more is selling.

You might also need

Cybersecurity

Pragmatic cybersecurity for Swiss SMEs: risk assessment, MFA and backup hardening, team awareness and a rehearsed incident response plan. One contact.

Compliance Services

nLPD and GDPR compliance for Swiss SMEs: processing registers, data protection documentation, ISO 27001 preparation and solid answers to client security questionnaires.

Frequent questions

How much does a penetration test cost in Switzerland?

It depends on scope and depth: a focused test of one web application is typically measured in days of senior work; broader scopes cost more. Beware of very cheap offers — they are usually automated scans dressed up as pentests. We quote a fixed price after scoping, so there are no surprises.

How long does a pentest take?

For a typical SME scope: one to three weeks from kickoff to report, including scoping, the testing window and report writing. The re-test after your fixes adds a short follow-up, scheduled when you are ready. If you have a contractual deadline, tell us early — scoping is the step that benefits most from lead time.

Will the test disrupt our production systems?

Engagements are designed to avoid that: destructive techniques are excluded by default, testing windows are agreed with your team, and an emergency stop procedure exists on both sides. Where a technique carries any operational risk, we discuss it beforehand or test against a staging environment instead.

What is the difference between a pentest and a vulnerability scan?

A scan is automated: it lists known weaknesses, with false positives and no context. A pentest adds human expertise: verifying what is genuinely exploitable, chaining weaknesses together, and assessing real impact on your business. Scans are useful hygiene; a pentest is evidence. Clients and auditors who ask for a pentest will not accept a scan report.

How often should we run a pentest?

A common rhythm for SMEs is annually, plus after major changes: a new customer-facing application, a significant architecture change, a migration. Between pentests, continuous security testing in your CI keeps quality from drifting — that combination is more effective than more frequent pentests alone.

What happens after we receive the report?

We walk through it with your team, answer questions and help plan remediation in a realistic order. Your developers can fix the findings, or ours can — MAWT builds and modernizes software, so remediation does not have to wait for free capacity on your side. Once fixes land, we re-test and issue the updated report.
Next steps

Better to read it in our report than in an incident post-mortem.