{"id":3589,"date":"2026-04-22T10:24:19","date_gmt":"2026-04-22T10:24:19","guid":{"rendered":"https:\/\/www.carmasec.com\/services\/offensive-security\/penetration-testing\/"},"modified":"2026-05-29T12:26:00","modified_gmt":"2026-05-29T12:26:00","slug":"penetration-testing","status":"publish","type":"page","link":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/","title":{"rendered":"Penetration Testing"},"content":{"rendered":"\n<section id=\"m-hero__container-block_8550c5efc2aa35e56b3e4aba900ac18f\" class=\"m-hero__container  u-color-white u-relative\"><figure class=\"u-absolute u-pos--top u-pos--left u-full--width u-full--height\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-1920x700.jpg\" width=\"1920\" height=\"700\" srcset=\"\" sizes=\"(max-width: 1920px) 100vw, 1920px\" alt=\"Blauer Hintergrund\" class=\"u-image--cover\"  \/>\n        <\/figure><div class=\"o-container u-relative u-index--1 u-pt-x20 u-pb-x20 u-pt-x40@md u-pb-x40@md\">\n        <div class=\"o-grid\">\n            <div class=\"o-grid__col u-6\/12@md u-mt-x6 u-mt-x0@sm\" data-aos=\"fade\">\n                <h1>Penetration Testing<\/h1>\n<p>Vulnerabilities exist in every system. We find them, document them precisely, and show concrete ways to close them. Our tests follow OWASP, PTES, and MITRE ATT&#038;CK, established standards that ensure complete and methodologically sound coverage of all relevant attack vectors.  <\/p>\n<p>&nbsp;<\/p>\n<p><a class=\"c-btn c-btn__primary u-mt-x3\" href=\"#form\">Request Pentest<\/a> <a class=\"c-btn c-btn--white u-mt-x3\" href=\"#leistungen\">Pentest Portfolio<\/a><\/p>\n\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-text__container-block_52b718217dc192556c489d06f7adacd0\" class=\"m-text__container u-pt-x8 u-pb-x12 u-pt-x20@md u-pb-x28@md u-bgcolor-gray-blue\"><div class=\"o-container u-relative\">\n        <div class=\"o-grid\">\n                <article class=\"o-grid__col u-10\/12@md\" data-aos=\"none\">\n                    <h2 style=\"text-align: left;\">Documenting security alone doesn&#8217;t prove it works<\/h2>\n<p style=\"text-align: left;\">Compliance reports document what is present. A penetration test shows whether it works. No audit replaces a controlled attack. Firewalls, EDR systems, IAM configurations, and access controls only hold up if they have been tested. Regulations make it mandatory for many.    <\/p>\n\n                <\/article>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-tiles__container-block_21154eca412b027627cda17c838866f5\" class=\"m-tiles__container u-pt-x0 u-pb-x0 u-pt-x0@md u-pb-x0@md u-mt--x20@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4><strong>Critical Infrastructure &#038; Regulated Industries<\/strong><\/h4>\n<p>NIS-2, ISO 27001, KRITIS, and DCRA. Approximately 30,000 companies in Germany must demonstrate the effectiveness of their security measures. A pentest report is the most direct way to do so.  <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4><strong>Payment &#038; Platforms<\/strong><\/h4>\n<p>SaaS with payment functions, e-commerce, payment service providers. PCI DSS 4.0.1 has been in effect since March 2025 and specifically mandates technical tests. Anyone processing card data is affected.  <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4><strong>Finance, Automotive &#038; Enterprise<\/strong><\/h4>\n<p>Financial institutions under DORA. Automotive suppliers under TISAX. And all who want to win enterprise customers or maintain their cyber insurance.  <\/p>\n<p>&nbsp;<\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-headline__container-block_677299473e18775aef3316c7e91bcb18\" class=\"m-headline__container u-pt-x8 u-pb-x0 u-pt-x20@md u-pb-x0@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid o-grid--center u-text-center\">\n            <div class=\"o-grid__col u-8\/12@md\" data-aos=\"none\"><h2>When a penetration test is the right step<\/h2><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-tiles__container-block_0382bb0af066cc695be5c6e0778948f6\" class=\"m-tiles__container u-pt-x4 u-pb-x8 u-pt-x12@md u-pb-x20@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>Before a Go-live<\/h4>\n<p>New web application, new API, new cloud environment. What hasn&#8217;t been checked before launch becomes an attack surface after launch. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-8\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>After infrastructure changes<\/h4>\n<p>Migration, new systems, architectural changes. Every change opens potential attack vectors that did not exist before. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-8\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>For compliance evidence<\/h4>\n<p>ISO 27001, NIS-2, CRA, EU AI Act, and DORA require technical security reviews. A pentest report is recognized proof. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>To validate existing protective measures<\/h4>\n<p>SIEM, EDR, access controls. Their effectiveness only becomes apparent under conditions that simulate attacks. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>Upon request from customers or partners<\/h4>\n<p>Service providers operating sensitive systems must be able to prove their security.<\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-8\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height u-bgcolor-gray-blue u-p-x4 u-p-x8@md\">\n                        \n                        <figcaption class=\"u-relative\"><h4>Regularly<\/h4>\n<p>Security is not a state. A penetration test is a snapshot. Those who test annually know their current status.  <\/p>\n<p><a class=\"c-btn c-btn__primary u-mt-x3\" href=\"#form\">Request Pentest<\/a><\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"services\" data-anchor-title=\"Services\" class=\"m-headline__container u-pt-x8 u-pb-x8 u-pt-x20@md u-pb-x20@md u-bgcolor-gray-blue\">\n    <div class=\"o-container\">\n        <div class=\"o-grid o-grid--center u-text-center\">\n            <div class=\"o-grid__col u-8\/12@md\" data-aos=\"none\"><h2>What we test<\/h2><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-tiles__container-block_e563201eed31ab372d72bd7c14053b38\" class=\"m-tiles__container u-pt-x4 u-pb-x8 u-pt-x8@md u-pb-x20@md u-bgcolor-gray-blue\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-globus-schloss-1.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Globus-mit-Schloss-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Web Application Pentest<\/h4>\n<p>Web applications according to OWASP Top 10: authentication failures, injection vulnerabilities, business logic errors, insecure session management. For single-page apps, multi-page apps, and admin interfaces. Black-box, grey-box, or white-box.  <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-security-offense.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Vernetztes-Schutzschild-mit-Haken-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Endpoint Pentest<\/h4>\n<p>Company notebooks and workstations: OS hardening, local privilege escalation, EDR\/AV configuration, application whitelisting, browser security. We check how far a standard user can get with a compromised device. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-api-key.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Schl\u00fcssel-mit-Bin\u00e4rcode-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>API Pentest<\/h4>\n<p>REST, GraphQL, and SOAP according to OWASP API Security Top 10: Broken Object Level Authorization, Mass Assignment, Rate Limiting, Broken Authentication. For internal and external APIs. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--gradient u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-radar-monitoring.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Zielscheibe-mit-Haken-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>AD Pentest<\/h4>\n<p>Active Directory: misconfigurations, Kerberoasting, Pass-the-Hash, delegation attacks, privilege escalation up to domain dominance. We test how far an attacker can get in the network once they have a foothold. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-netzwerk-schild.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Vernetztes-Schutzschild-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Network Pentest<\/h4>\n<p>External and internal network infrastructure: servers, firewalls, VPNs, switches. Identification of reachable systems, manual check for misconfigurations and vulnerabilities. External (Internet-facing) or internal (Assumed Breach).  <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-mfa-2fa.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Gesperrtes-Smartphone-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Mobile Pentest<\/h4>\n<p>iOS and Android apps according to OWASP MASVS: Client-Side Security, Reverse Engineering, Data Storage, Transport Encryption. Including backend API testing. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-cloud-schild.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"Cloud-Schutzschild-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Cloud Platform Pentest<\/h4>\n<p>AWS, Azure, and GCP: IAM misconfigurations, over-privileged roles, storage access, serverless functions, container security. We examine how an attacker escalates within a cloud environment. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-3\/12@md\" data-aos=\"none\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/icon-chip-ai.svg\" width=\"64\" height=\"64\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"KI-Chip-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>AI pentesting<\/h4>\n<p>AI applications and their interfaces: Prompt Injection, Jailbreaking, Model Inversion, insecure API connections. For LLM-based applications and AI systems in production environments. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-headline__container-block_1fed0b67772e1728adfd6d1eaf0a61f9\" class=\"m-headline__container u-pt-x8 u-pb-x0 u-pt-x20@md u-pb-x0@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid o-grid--center u-text-center\">\n            <div class=\"o-grid__col u-8\/12@md\" data-aos=\"none\"><h2>Deliverables of the Penetration Test<\/h2><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"services\" data-anchor-title=\"Services\" class=\"m-tiles__container u-pt-x0 u-pb-x8 u-pt-x4@md u-pb-x20@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"slide-left\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/icon-checkmark.svg\" width=\"66\" height=\"66\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"H\u00e4kchen-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Technical Report<\/h4>\n<p>Each vulnerability with description, risk assessment according to CVSS, reproduction steps, and concrete recommendations for action. Directly usable by technical teams. <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"slide-left\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/icon-checkmark.svg\" width=\"66\" height=\"66\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"H\u00e4kchen-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Executive Summary<\/h4>\n<p>For management and supervisory boards. Clear situation assessment and clear priorities. No technical prior knowledge required.  <\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n                <div class=\"o-grid__col u-mb-x4 u-6\/12@sm u-4\/12@md\" data-aos=\"slide-left\">\n                \n                    <figure class=\"c-card u-relative u-block u-full--height c-card--border u-bgcolor-white u-p-x4 u-p-x8@md\">\n                        <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/icon-checkmark.svg\" width=\"66\" height=\"66\" srcset=\"\" sizes=\"(max-width: 480px) 100vw, 480px\" alt=\"H\u00e4kchen-Icon\" class=\"u-image__icon u-mb-x5\"  \/>\n                        <figcaption class=\"u-relative\"><h4>Retest Report<\/h4>\n<p>After critical findings have been remediated, we verify the effectiveness of the measures and document the result.<\/p>\n<\/figcaption>\n                    <\/figure>\n                    \n                <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section\n    id=\"m-media-text__container-block_0c25a7882aa6544dab5d8918818c314a\"    class=\"u-relative m-media-text__container u-pt-x8 u-pb-x8 u-pt-x20@md u-pb-x16@md u-color-white\"\n>\n    <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-1024x570.jpg\" width=\"1024\" height=\"570\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-1024x570.jpg 1024w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-300x167.jpg 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-768x427.jpg 768w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero-1536x854.jpg 1536w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/background-image-hero.jpg 1920w\" sizes=\"(max-width: 1380px) 100vw, 1380px\" alt=\"Blauer Hintergrund\" class=\"u-absolute u-pos--top u-pos--left u-full--width u-full--height\"  \/>\n    <div class=\"o-container u-relative\">\n        \n                    <div class=\"o-grid o-grid--center o-grid--middle\">\n                <figure class=\"m-media-text__image o-grid__col u-6\/12@sm u-5\/12@md u-text-center u-mb-x6 u-mb-x0@sm\" data-aos=\"fade\">\n                    <img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/03\/Mookup_-Leadmagnet_Playbook_TID.jpg\" width=\"1000\" height=\"750\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/03\/Mookup_-Leadmagnet_Playbook_TID.jpg 1000w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/03\/Mookup_-Leadmagnet_Playbook_TID-300x225.jpg 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/03\/Mookup_-Leadmagnet_Playbook_TID-768x576.jpg 768w\" sizes=\"(max-width: 640px) 100vw, 640px\" alt=\"Vorschau des carmasec-Playbooks \"Threat-Informed Defense: Weniger Risiko, mehr Resilienz\" f\u00fcr CISOs und IT-Abteilungen\" class=\" u-image--rounded-large\"  \/>                <\/figure>\n\n                <article class=\"m-media-text__content o-grid__col u-6\/12@sm u-6\/12@md u-push-1\/12@md\" data-aos=\"fade\">\n                    <h2>Threat-Informed Defense<\/h2>\n<h2>Wie Organisationen aufh\u00f6ren, gegen Schatten zu k\u00e4mpfen.<\/h2>\n<p>Ein Playbook f\u00fcr IT-Verantwortliche und Entscheider:innen, die wissen wollen, wie echte Angriffe funktionieren und wie man sie gezielt stoppt. Threat-Informed Defense ist der Ansatz, der Verteidigung an realen Angreiferverhalten ausrichtet. Dieses Playbook erkl\u00e4rt, welche Techniken Angreifer tats\u00e4chlich einsetzen, wie MITRE ATT&amp;CK als Grundlage funktioniert und welche Ma\u00dfnahmen nachweisbar wirksam sind.<\/p>\n<p><a class=\"c-btn c-btn--white u-mt-x3\" href=\"https:\/\/www.carmasec.com\/de\/knowledge-center\/threat-informed-defense-echte-angriffstechniken\/\">Download<\/a><\/p>\n                <\/article>\n            <\/div>\n\n        \n            <\/div>\n<\/section>\n<section id=\"m-headline__container-block_35fcaca52cee79cd45f9709bd9ffb8fd\" class=\"m-headline__container u-pt-x8 u-pb-x0 u-pt-x20@md u-pb-x0@md u-bgcolor-gray-blue\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n            <div class=\"o-grid__col u-8\/12@md\" data-aos=\"flip-right\"><h4>FAQ<\/h4><h3>Questions? Answers. <\/h3><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-accordion__container-block_b88d14a6c9b95c192e9a6f1a01941561\" class=\"m-accordion__container u-pt-x4 u-pb-x8 u-pt-x12@md u-pb-x12@md u-bgcolor-gray-blue\">\n    <div class=\"o-container\">\n        <div class=\"o-grid\">\n            <div class=\"o-grid__col u-12\/12@md\">\n                <div class=\"m-accordion\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\">\n                         <div class=\"m-accordion__item u-bgcolor-white u-mb-x2\" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" data-aos=\"none\">\n                             <div class=\"m-accordion__header u-relative u-pv-x2 u-pv-x4@sm u-ph-x3 u-ph-x6@sm\">\n                                 <p class=\"h6 u-mb-x0\" itemprop=\"name\">\n                                     Which test method is right, Black-Box, Grey-Box, or White-Box?\n                                 <\/p>\n                             <\/div>\n                             <div class=\"m-accordion__body u-relative u-index--1\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n                                 <div class=\"u-ph-x3 u-ph-x6@sm u-pb-x2\" itemprop=\"text\"><p>It depends on the goal. Black-box simulates an attacker with no prior knowledge. White-box provides maximum test depth because we know the system structure. Grey-box is often the most efficient choice in practice: realistic attacker behavior with controllable effort. We recommend the method based on your specific scope, which we clarify in the scoping call.    <\/p>\n<\/div>\n                             <\/div>\n                         <\/div>\n                         <div class=\"m-accordion__item u-bgcolor-white u-mb-x2\" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" data-aos=\"none\">\n                             <div class=\"m-accordion__header u-relative u-pv-x2 u-pv-x4@sm u-ph-x3 u-ph-x6@sm\">\n                                 <p class=\"h6 u-mb-x0\" itemprop=\"name\">\n                                     What is the difference between a penetration test and a vulnerability scan?\n                                 <\/p>\n                             <\/div>\n                             <div class=\"m-accordion__body u-relative u-index--1\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n                                 <div class=\"u-ph-x3 u-ph-x6@sm u-pb-x2\" itemprop=\"text\"><p>A vulnerability scan is automated and provides a list of known vulnerabilities. A penetration test is manual, contextual, and shows whether and how these vulnerabilities can actually be exploited. Only a pentest can find logic errors, combined attacks, and complex attack paths.  <\/p>\n<\/div>\n                             <\/div>\n                         <\/div>\n                         <div class=\"m-accordion__item u-bgcolor-white u-mb-x2\" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" data-aos=\"none\">\n                             <div class=\"m-accordion__header u-relative u-pv-x2 u-pv-x4@sm u-ph-x3 u-ph-x6@sm\">\n                                 <p class=\"h6 u-mb-x0\" itemprop=\"name\">\n                                     TLPT and do we need it?\n                                 <\/p>\n                             <\/div>\n                             <div class=\"m-accordion__body u-relative u-index--1\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n                                 <div class=\"u-ph-x3 u-ph-x6@sm u-pb-x2\" itemprop=\"text\"><p>Threat-Led Penetration Testing is an intelligence-driven attack simulation based on real attacker profiles. Not a generic test, but a scenario tailored to your organization, your industry, and current threat landscapes. TLPT is mandatory under DORA for significant financial institutions, coordinated according to the TIBER-EU framework. For all others, it is the next level of maturity after a classic penetration test.   <\/p>\n<\/div>\n                             <\/div>\n                         <\/div>\n                         <div class=\"m-accordion__item u-bgcolor-white u-mb-x2\" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" data-aos=\"none\">\n                             <div class=\"m-accordion__header u-relative u-pv-x2 u-pv-x4@sm u-ph-x3 u-ph-x6@sm\">\n                                 <p class=\"h6 u-mb-x0\" itemprop=\"name\">\n                                     How often should a penetration test be performed?\n                                 <\/p>\n                             <\/div>\n                             <div class=\"m-accordion__body u-relative u-index--1\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n                                 <div class=\"u-ph-x3 u-ph-x6@sm u-pb-x2\" itemprop=\"text\"><p>Annually is the minimum. After significant changes and new systems, migration projects, or new applications, we recommend a targeted retest of the affected area. Those falling under DORA are obliged to conduct tests for critical systems every three years. ISO 27001 requires regular review without a fixed frequency.   <\/p>\n<\/div>\n                             <\/div>\n                         <\/div>\n                         <div class=\"m-accordion__item u-bgcolor-white u-mb-x2\" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" data-aos=\"none\">\n                             <div class=\"m-accordion__header u-relative u-pv-x2 u-pv-x4@sm u-ph-x3 u-ph-x6@sm\">\n                                 <p class=\"h6 u-mb-x0\" itemprop=\"name\">\n                                     Will our systems be affected during the test?\n                                 <\/p>\n                             <\/div>\n                             <div class=\"m-accordion__body u-relative u-index--1\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n                                 <div class=\"u-ph-x3 u-ph-x6@sm u-pb-x2\" itemprop=\"text\"><p>Generally not. In the scoping phase, we agree on which systems will be actively tested and which are excluded. Production systems with a high risk of failure are treated separately. Should we find critical vulnerabilities during the test, we will inform you immediately.   <\/p>\n<\/div>\n                             <\/div>\n                         <\/div>\n                 <\/div>\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-headline__container-block_0e0c7b2dc92bc804ec154e0ae29e1bdd\" class=\"m-headline__container u-pt-x8 u-pb-x0 u-pt-x20@md u-pb-x0@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid o-grid--center u-text-center\">\n            <div class=\"o-grid__col u-10\/12@md\" data-aos=\"none\"><h2>Whether start-up, mid-sized company, or corporation: We find the right solution<\/h2><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-slider__container-block_8a64cb40a31cb8775c2e3cb15c031248\" class=\"m-slider__container u-pt-x0 u-pb-x8 u-pt-x4@md u-pb-x16@md\"><div class=\"m-slider\" data-number=\"7\" data-rows=\"1\" data-autoslide=\"1\" data-indent=\"1\" data-arrows=\"true\"><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-barmenia.svg\" width=\"81\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Barmenia\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-bruker.png\" width=\"113\" height=\"60\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Bruker\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-deutsche-bahn.svg\" width=\"74\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Deutsche Bahn\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-fashionette.svg\" width=\"156\" height=\"25\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Fashionette\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-raisinbank.svg\" width=\"155\" height=\"36\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Raisin Bank\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-vorwerk.svg\" width=\"135\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Vorwerk\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-300x208.png\" width=\"300\" height=\"208\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-300x208.png 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-1024x712.png 1024w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-768x534.png 768w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-1536x1067.png 1536w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-2048x1423.png 2048w\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von eligo\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-barmenia-1.svg\" width=\"81\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Barmenia\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-bruker-1.png\" width=\"113\" height=\"60\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Bruker\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-deutsche-bahn-1.svg\" width=\"74\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Deutsche Bahn\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-fashionette-1.svg\" width=\"156\" height=\"25\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Fashionette AG\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-raisinbank-1.svg\" width=\"155\" height=\"36\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Raisin Bank AG\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-vorwerk-1.svg\" width=\"135\" height=\"52\" srcset=\"\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Vorwerk\" class=\"\"  \/><\/figure><figure class=\"u-flex u-ai-center u-jc-center u-relative u-p-x6 u-image__logo\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-300x87.png\" width=\"300\" height=\"87\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-300x87.png 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-1024x295.png 1024w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-768x222.png 768w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-1536x443.png 1536w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-2048x591.png 2048w\" sizes=\"(max-width: 400px) 100vw, 400px\" alt=\"Logo von Tyntec\" class=\"\"  \/><\/figure>\n\t    <\/div><div class=\"carousel__arrows\"><\/div>\n<\/section>\n<section id=\"m-headline__container-block_a7df5d6172acacdd6f6857b81a1de1fb\" class=\"m-headline__container u-pt-x8 u-pb-x0 u-pt-x20@md u-pb-x0@md\">\n    <div class=\"o-container\">\n        <div class=\"o-grid o-grid--center u-text-center\">\n            <div class=\"o-grid__col u-12\/12@md\" data-aos=\"none\"><h4>Trust is built through results<\/h4><\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<section id=\"m-quote__container-block_c9d422e1858007c0c632a3308b63c46f\" class=\"m-quote__container u-pt-x8 u-pb-x16 u-pt-x20@md u-pb-x40@md\">\n    <div class=\"o-container u-relative u-ph-x0\"><div class=\"m-slider__quote m-slider__quote--logo\">\n                <div class=\"m-slider__quoteInner u-ph-x6 u-ph-x0@md\">\n                    <div class=\"o-grid o-grid--center o-grid--middle\">\n                        <div class=\"o-grid__col u-5\/12@sm u-3\/12@md u-text-center u-text-left@sm u-mb-x6 u-mb-x0@sm\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-DKV.svg\" width=\"1770\" height=\"1229\" srcset=\"\" sizes=\"(max-width: 640px) 100vw, 640px\" alt=\"Logo von DKV\" class=\"u-full--width\"  \/>\n                        <\/div>\n                        <article class=\"o-grid__col u-5\/12@sm u-push-1\/12@md u-text-center u-text-left@sm\"><blockquote class=\"h4 u-weight-regular\">\u00bbMit Unterst\u00fctzung von carmasec haben wir KPIs definiert und einen h\u00f6heren Grad an Transparenz und Akzeptanz geschaffen.\u00ab<\/blockquote><p class=\"o-type-small\"><strong>DKV Mobility Services<\/strong><\/p><\/article>\n                    <\/div>\n                <\/div>\n                <div class=\"m-slider__quoteInner u-ph-x6 u-ph-x0@md\">\n                    <div class=\"o-grid o-grid--center o-grid--middle\">\n                        <div class=\"o-grid__col u-5\/12@sm u-3\/12@md u-text-center u-text-left@sm u-mb-x6 u-mb-x0@sm\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-bruker.png\" width=\"113\" height=\"60\" srcset=\"\" sizes=\"(max-width: 640px) 100vw, 640px\" alt=\"Logo von Bruker\" class=\"u-full--width\"  \/>\n                        <\/div>\n                        <article class=\"o-grid__col u-5\/12@sm u-push-1\/12@md u-text-center u-text-left@sm\"><blockquote class=\"h4 u-weight-regular\">\u00bbProfessionell, flexibel, nahbar und vor allem: erfolgreich. carmasec hat geliefert, was versprochen wurde.\u00ab<\/blockquote><p class=\"o-type-small\"><strong>Bruker Optics<\/strong><\/p><\/article>\n                    <\/div>\n                <\/div>\n                <div class=\"m-slider__quoteInner u-ph-x6 u-ph-x0@md\">\n                    <div class=\"o-grid o-grid--center o-grid--middle\">\n                        <div class=\"o-grid__col u-5\/12@sm u-3\/12@md u-text-center u-text-left@sm u-mb-x6 u-mb-x0@sm\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo.png\" width=\"2360\" height=\"1640\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo.png 2360w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-300x208.png 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-1024x712.png 1024w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-768x534.png 768w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-1536x1067.png 1536w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-eligo-2048x1423.png 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" alt=\"Logo von eligo\" class=\"u-full--width\"  \/>\n                        <\/div>\n                        <article class=\"o-grid__col u-5\/12@sm u-push-1\/12@md u-text-center u-text-left@sm\"><blockquote class=\"h4 u-weight-regular\">\u00bbMit carmasec fanden wir einen vertrauensw\u00fcrdigen Partner, der uns bei der Umsetzung unterst\u00fctzte und einen umfangreichen Ergebnisbericht lieferte. Wir empfehlen carmasec uneingeschr\u00e4nkt weiter.\u00ab<\/blockquote><p class=\"o-type-small\"><strong>ELIGO<\/strong><\/p><\/article>\n                    <\/div>\n                <\/div>\n                <div class=\"m-slider__quoteInner u-ph-x6 u-ph-x0@md\">\n                    <div class=\"o-grid o-grid--center o-grid--middle\">\n                        <div class=\"o-grid__col u-5\/12@sm u-3\/12@md u-text-center u-text-left@sm u-mb-x6 u-mb-x0@sm\"><img decoding=\"async\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec.png\" width=\"2360\" height=\"681\" srcset=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec.png 2360w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-300x87.png 300w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-1024x295.png 1024w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-768x222.png 768w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-1536x443.png 1536w, https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/Logo-Tyntec-2048x591.png 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" alt=\"Logo von Tyntec\" class=\"u-full--width\"  \/>\n                        <\/div>\n                        <article class=\"o-grid__col u-5\/12@sm u-push-1\/12@md u-text-center u-text-left@sm\"><blockquote class=\"h4 u-weight-regular\">\u00bbcarmasec leistete einen nennenswerten Beitrag zur Sicherheit unserer Dienste. Professionelle Beratung, saubere Durchf\u00fchrung. F\u00fcr Infrastruktur-Pentests empfehlen wir carmasec uneingeschr\u00e4nkt.\u00ab<\/blockquote><p class=\"o-type-small\"><strong>tyntec GmbH<\/strong><\/p><\/article>\n                    <\/div>\n                <\/div><\/div>\n    <\/div>\n<\/section>\n<section id=\"form\" data-anchor-title=\"form\" class=\"m-form-text__container u-pt-x8 u-pb-x8 u-pt-x20@md u-pb-x20@md u-bgcolor-secondary\">\n    <div class=\"o-container u-relative\">\n        <div class=\"o-grid o-grid--center\">\n            <article class=\"o-grid__col u-6\/12@sm u-4\/12@lg u-mb-x6 u-mb-x0@sm\" data-aos=\"none\">\n                <p class=\"h4 u-color-white\">Kontakt<\/p>\n<h2 class=\"u-color-white\">Scope definieren und Test starten<\/h2>\n<p class=\"u-color-white\">Scoping dauert 30 Minuten. Danach ist klar, was getestet wird, welche Methode passt und wann wir starten k\u00f6nnen. Wer KI-Systeme einsetzt oder unter den EU AI Act f\u00e4llt: auch das besprechen wir im Erstgespr\u00e4ch. Formular ausf\u00fcllen und abschicken, danach melden wir uns.<\/p>\n<div class=\"o-media o-media--res o-media--middle u-mt-x6\">\n<figure class=\"o-media__fixed\"><img decoding=\"async\" class=\"u-image--circle alignleft wp-image-1556 size-thumbnail\" src=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/TBoergers-150x150.jpg\" alt=\"Portr\u00e4tfoto von Timm B\u00f6rgers, Gesch\u00e4ftsf\u00fchrer bei der carmasec.\" width=\"150\" height=\"150\" \/><\/figure>\n<div class=\"o-media__fluid\"><strong class=\"u-color-white\">Timm B\u00f6rgers<\/strong><br \/>\n<span class=\"u-color-white\">Gesch\u00e4ftsf\u00fchrer<\/span><br \/>\n<a class=\"u-color-white\" href=\"tel:0049201426385905\" target=\"_blank\" rel=\"noopener\">+49 (0)201 426 385 905<\/a><br \/>\n<a class=\"u-color-white\" href=\"mailto:vertrieb@carmasec.com\">vertrieb@carmasec.com<\/a><\/div>\n<\/div>\n\n            <\/article>\n            <div class=\"o-grid__col u-6\/12@sm u-7\/12@lg u-push-1\/12@lg\" data-aos=\"none\">\n                <div class=\"c-card u-bgcolor-gray-blue u-p-x6 u-p-x12@md\">\n                    <script>hbspt.forms.create({portalId: \"144374369\", formId: \"d09e89f2-1068-45b6-a1bf-e23343ee221c\"});<\/script>\n                <\/div>\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>","protected":false},"excerpt":{"rendered":"","protected":false},"author":4,"featured_media":3588,"parent":3586,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3589","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Pentest Provider | Penetration Testing for Businesses | carmasec<\/title>\n<meta name=\"description\" content=\"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Penetration Testing\" \/>\n<meta property=\"og:description\" content=\"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/\" \/>\n<meta property=\"og:site_name\" content=\"carmasec\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-29T12:26:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1685\" \/>\n\t<meta property=\"og:image:height\" content=\"934\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/\",\"url\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/\",\"name\":\"Pentest Provider | Penetration Testing for Businesses | carmasec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.carmasec.com\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg\",\"datePublished\":\"2026-04-22T10:24:19+00:00\",\"dateModified\":\"2026-05-29T12:26:00+00:00\",\"description\":\"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.carmasec.com\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg\",\"contentUrl\":\"https:\\\/\\\/www.carmasec.com\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg\",\"width\":1685,\"height\":934,\"caption\":\"Flowchart of a pentest at carmasec. Technical image in blue and orange colors.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Services\",\"item\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Offensive Security\",\"item\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Penetration Testing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/\",\"name\":\"carmasec\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"Place\"],\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/#organization\",\"name\":\"carmasec GmbH & Co. KG\",\"alternateName\":\"carmasec\",\"url\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/\",\"logo\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#local-main-organization-logo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#local-main-organization-logo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/carmasec\\\/\"],\"description\":\"Die carmasec GmbH & Co. KG ist eine auf Cybersicherheit und Cyberresilienz spezialisierte Beratungsunternehmen mit Sitz in Essen. Das Leistungsspektrum verbindet zwei essenzielle Welten: strategische Compliance und dem Schutz vor Cyberangriffen. Mit einem klaren Fokus auf agile Sicherheitsprozesse unterst\u00fctzt carmasec Kunden branchenneutral und herstellerunabh\u00e4ngig. Das interdisziplin\u00e4re Team integriert langj\u00e4hrige Beratungserfahrung mit modernen Arbeitsweisen, um komplexe Anforderungen \u2013 von ISMS und Risikomanagement bis hin zu Cloud Security und Offensive Security \u2013 effizient umzusetzen. Zu den Kunden z\u00e4hlen der gehobene Mittelstand sowie internationale Konzerne, insbesondere aus Finanz- und Versicherungswesen, Fertigungsindustrie, Automotive sowie Kritischen Infrastrukturen. Mit der etablierten Veranstaltungsreihe \u201efriends of carmasec\\\" schafft das Unternehmen eine zentrale Plattform f\u00fcr den Branchen-Dialog und vernetzt regelm\u00e4\u00dfig Entscheidungstr\u00e4ger:innen und Expert:innen aus der Security-Community. carmasec bef\u00e4higt Organisationen, Risiken ganzheitlich zu managen und digitale Infrastrukturen proaktiv zu sch\u00fctzen.\",\"legalName\":\"carmasec GmbH & Co. KG\",\"foundingDate\":\"2018-12-18\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"11\",\"maxValue\":\"50\"},\"telephone\":[],\"openingHoursSpecification\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"Monday\",\"Tuesday\",\"Wednesday\",\"Thursday\",\"Friday\",\"Saturday\",\"Sunday\"],\"opens\":\"09:00\",\"closes\":\"17:00\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.carmasec.com\\\/en\\\/services\\\/offensive-security\\\/penetration-testing\\\/#local-main-organization-logo\",\"url\":\"https:\\\/\\\/www.carmasec.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/logo-carmasec.svg\",\"contentUrl\":\"https:\\\/\\\/www.carmasec.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/logo-carmasec.svg\",\"width\":299,\"height\":40,\"caption\":\"carmasec GmbH & Co. KG\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Pentest Provider | Penetration Testing for Businesses | carmasec","description":"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/","og_locale":"en_US","og_type":"article","og_title":"Penetration Testing","og_description":"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.","og_url":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/","og_site_name":"carmasec","article_modified_time":"2026-05-29T12:26:00+00:00","og_image":[{"width":1685,"height":934,"url":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/","url":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/","name":"Pentest Provider | Penetration Testing for Businesses | carmasec","isPartOf":{"@id":"https:\/\/www.carmasec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#primaryimage"},"image":{"@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg","datePublished":"2026-04-22T10:24:19+00:00","dateModified":"2026-05-29T12:26:00+00:00","description":"Looking for a Pentest Provider? We test your systems like real attackers. Manual, structured, and with clear results.","breadcrumb":{"@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#primaryimage","url":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg","contentUrl":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-22.-Apr.-2026-16_57_41.jpg","width":1685,"height":934,"caption":"Flowchart of a pentest at carmasec. Technical image in blue and orange colors."},{"@type":"BreadcrumbList","@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.carmasec.com\/en\/"},{"@type":"ListItem","position":2,"name":"Services","item":"https:\/\/www.carmasec.com\/en\/services\/"},{"@type":"ListItem","position":3,"name":"Offensive Security","item":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/"},{"@type":"ListItem","position":4,"name":"Penetration Testing"}]},{"@type":"WebSite","@id":"https:\/\/www.carmasec.com\/en\/#website","url":"https:\/\/www.carmasec.com\/en\/","name":"carmasec","description":"","publisher":{"@id":"https:\/\/www.carmasec.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.carmasec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","Place"],"@id":"https:\/\/www.carmasec.com\/en\/#organization","name":"carmasec GmbH & Co. KG","alternateName":"carmasec","url":"https:\/\/www.carmasec.com\/en\/","logo":{"@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#local-main-organization-logo"},"image":{"@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#local-main-organization-logo"},"sameAs":["https:\/\/www.linkedin.com\/company\/carmasec\/"],"description":"Die carmasec GmbH & Co. KG ist eine auf Cybersicherheit und Cyberresilienz spezialisierte Beratungsunternehmen mit Sitz in Essen. Das Leistungsspektrum verbindet zwei essenzielle Welten: strategische Compliance und dem Schutz vor Cyberangriffen. Mit einem klaren Fokus auf agile Sicherheitsprozesse unterst\u00fctzt carmasec Kunden branchenneutral und herstellerunabh\u00e4ngig. Das interdisziplin\u00e4re Team integriert langj\u00e4hrige Beratungserfahrung mit modernen Arbeitsweisen, um komplexe Anforderungen \u2013 von ISMS und Risikomanagement bis hin zu Cloud Security und Offensive Security \u2013 effizient umzusetzen. Zu den Kunden z\u00e4hlen der gehobene Mittelstand sowie internationale Konzerne, insbesondere aus Finanz- und Versicherungswesen, Fertigungsindustrie, Automotive sowie Kritischen Infrastrukturen. Mit der etablierten Veranstaltungsreihe \u201efriends of carmasec\" schafft das Unternehmen eine zentrale Plattform f\u00fcr den Branchen-Dialog und vernetzt regelm\u00e4\u00dfig Entscheidungstr\u00e4ger:innen und Expert:innen aus der Security-Community. carmasec bef\u00e4higt Organisationen, Risiken ganzheitlich zu managen und digitale Infrastrukturen proaktiv zu sch\u00fctzen.","legalName":"carmasec GmbH & Co. KG","foundingDate":"2018-12-18","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"11","maxValue":"50"},"telephone":[],"openingHoursSpecification":[{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday","Sunday"],"opens":"09:00","closes":"17:00"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.carmasec.com\/en\/services\/offensive-security\/penetration-testing\/#local-main-organization-logo","url":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-carmasec.svg","contentUrl":"https:\/\/www.carmasec.com\/wp-content\/uploads\/2026\/02\/logo-carmasec.svg","width":299,"height":40,"caption":"carmasec GmbH & Co. KG"}]}},"_links":{"self":[{"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/pages\/3589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/comments?post=3589"}],"version-history":[{"count":1,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/pages\/3589\/revisions"}],"predecessor-version":[{"id":3590,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/pages\/3589\/revisions\/3590"}],"up":[{"embeddable":true,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/pages\/3586"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/media\/3588"}],"wp:attachment":[{"href":"https:\/\/www.carmasec.com\/en\/wp-json\/wp\/v2\/media?parent=3589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}