Penetration testing Switzerland: find attack surfaces before attackers do
A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.
What a pentest is and what it is not
A pentest is a manual, targeted simulation of realistic attack paths against a defined scope. It is not the same as an automated vulnerability scan that lists known CVEs without assessing exploitability or chaining. Both have a place but answer different questions: the scan asks 'what is exposed?', the pentest asks 'what does an attacker reach with it?'
Cyber insurers routinely accept a pentest report as evidence of documented security maturity, not a scanner CSV. The insurance-side requirements sit on [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).
Typical scopes
| Scope | Methodology reference | When it fits |
|---|---|---|
| Web application | OWASP ASVS, OWASP Top 10 | Before go-live, on major releases or annually for exposed applications. |
| API | OWASP API Security Top 10 | For public or partner-exposed APIs with business logic. |
| Cloud (Azure, AWS, GCP) | CIS Benchmarks, cloud-native threat model | After landing-zone rollout, before production customer go-live or for audits. |
| Active Directory / internal networks | MITRE ATT&CK paths, PTES | For complex AD environments, hybrid with Entra ID. |
| Assumed breach | TIBER elements, MITRE ATT&CK | For testing lateral movement after initial access. |
How an ANOMAL pentest runs
- Scoping workshop: clear target systems, rules (time windows, blackout lists, data handling), success criteria.
- Threat modelling: which attacker goals are realistic for the tested application, which paths get priority.
- Testing phase: manual exploitation, chained attack paths, continuous contact with the customer point of contact on critical findings.
- Report: executive summary, technical detail per finding, CVSS and business impact, prioritised recommendations with effort ranges.
- Retest: no-cost verification of critical and high findings within a defined window after the initial report.
If the test phase surfaces actual compromise evidence, it moves into the same process as a real incident, see Incident Response 72h. This applies even for customers without an ANOMAL SOC.
How this compares to scanning, red teaming and audit
| Activity | Goal | Outcome |
|---|---|---|
| Vulnerability scan | Broad, automated detection of known weaknesses. | List of potential issues, without proven exploitability. |
| Pentest | Deep, manual test of a defined scope. | Demonstrated attack paths with business impact and prioritisation. |
| Red team | Goal-based attack simulation without narrow scope boundaries. | Statement on end-to-end detection and response capability including the SOC. |
| Audit / certification | Compliance check against standard or regulation. | Certificate or attestation without an attacker's perspective. |
A pentest does not replace SOC operations. It answers 'what could an attacker achieve?' at a point in time. The SOC answers 'what is happening in our environment right now?' continuously. See SOC as a Service Switzerland for context.
Frequently asked questions
How often should we pentest?
Test exposed applications and regulated areas annually, and after major architecture changes or the introduction of new external interfaces. Test internal networks and AD every 12 to 24 months, depending on the frequency of changes.
Does a pentest make sense without a managed SOC?
Yes, a pentest has value on its own, and a SOC increases that value. Without detection capability, the report remains a document. A SOC translates prioritised findings directly into detection rules and hardening measures.
Does a pentest satisfy cyber-insurance requirements?
A pentest is not a substitute for baseline controls such as MFA, EDR, backups and an IR plan. Insurers recognise it as evidence of documented maturity, and it often reduces premiums. The baseline requirements still apply. See [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland) for an overview of requirements.
Do we get raw data or only the report?
We provide both, with the report as the primary deliverable. We supply test artefacts (screenshots, requests, payloads) according to customer instructions or delete them after the retest through a controlled process. We document the chain of custody.
Do you test production systems?
Yes, we test production systems. When test environments are not close to production, testing production is often the only meaningful option. We agree rules, time windows and abort criteria contractually during scoping.
Related terms
- Vulnerability Management Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.
- CVE CVE is the global directory of publicly known security vulnerabilities where each vulnerability receives its own identifier.
- Red Team A Red Team simulates a realistic attack to test an organisation's detection and response capabilities under real-world conditions.
- Exploit An exploit is code or a method that deliberately exploits a security vulnerability to compromise a system or gain higher privileges.