# Penetration Testing Services | Novacoast

> Network, web, API, cloud, identity, wireless, physical and social engineering tests, plus red and purple team exercises. Findings ranked by exploitability, retest included.

Canonical: https://novacoast.com/penetration-testing/

NCAT Novacoast Attack Team

# Penetration testing by the team whose job is to get in.

Network, web application, API, cloud, identity, wireless, physical and social engineering testing, plus red and purple team exercises. We call the team NCAT, the Novacoast Attack Team. They follow the paths an attacker would take, chain what they find, and show you how to close it.

Continuous, AI-driven pentesting. Frontier models probe at machine speed. NCAT testers turn that into a real way in, or prove there isn't one.

[Scope a test](https://novacoast.com/contact-us/)What we test

## The penetration tests we run.

NCAT / penetration testing services

### External & internal

Find a way in from outside, then test how far an attacker could move inside.

- External: test the perimeter for a foothold in your network.
- Internal: check whether segmentation stops access to other systems.

### Web, mobile & API

Test how your web apps, mobile apps and APIs handle access and data.

- Authentication and sessions: check for ways to sign in as someone else.
- Injection: test whether inputs can change what the application executes.
- Business logic: try to bypass the steps and permissions your workflows depend on.

### Cloud & identity

Find cloud misconfigurations and accounts with more access than they need.

- Check what exposed resources and configuration mistakes make reachable.
- Follow user and service-account permissions to see where they lead.

### Wireless & physical

Test access through your wireless networks and physical entry points.

- Check whether a guest wireless connection can reach internal systems.
- Test badge readers and building access within the agreed scope.

### Social engineering

Test how staff respond to phishing, phone calls and impersonation.

- Phishing: test requests sent by email.
- Vishing and pretexting: use calls and a cover story to test how requests are verified.
- Agree on the targets and ground rules first.

### Red & purple team

Run an adversary exercise or work alongside your SOC to test detection.

- Red team: follow an attacker’s path through the agreed targets.
- Purple team: work with your SOC to see what gets detected and improve what gets missed.

## Your report and retest

### What’s in the report

- Findings prioritized by how they can be exploited in your environment
- Step-by-step instructions to reproduce each attack chain
- Supporting screenshots, payloads and timestamps
- An executive summary for leadership and board review
- Mapping to PCI, HIPAA and SOC 2 requirements when needed

### Review the results with your tester

Every finding is manually verified. You’ll review the results with the tester who found the issues and can walk you through them.

Once your team has made the fixes, we retest them. That retest is included in the original price.

## Ranked by what we actually reached, not what a scanner scored.

finding 03 of 11illustrative

FIN-03 · CRITICAL reproducible

external web · auth bypass · chained to internal

1 Password reset token predictable from timestamp recon

2 Reset admin, log in, reach the internal API gateway exploit

3 Gateway trusts internal origin; reached HR export pivot

→ Fix: sign tokens, expire in 10 min, gateway auth on internal origin retest booked

time to reach: **41 min** severity: **what it exposed**

Every penetration test finding reads like this. The chain we took, step by step, with the evidence. The fix, written for the engineer who will ship it. The retest, included, so the finding is closed by us failing to get in again, not by a ticket being marked done.

Illustrative example. These details do not describe a customer engagement.

## What buyers ask first.

What types of penetration testing do you offer?

External and internal network penetration testing, web application and API testing, cloud and identity testing, wireless and physical testing, social engineering and phishing, and red and purple team exercises. Most engagements combine two or three.

What does a penetration test cost?

It depends on scope, and scope is a thirty-minute conversation with a tester. You get a fixed price and rules of engagement after that call.

Is the retest included?

Yes. A finding is closed when we fail to get in again, not when a ticket is marked done.

How is a penetration test different from a vulnerability scan?

A scan lists what might be exploitable. A penetration test shows the exact chain we took, reproducible, and what we reached. Findings are ranked by real exploitability, not scanner severity.

Do you test production systems?

With rules of engagement agreed in advance, including what is off-limits and who to call at 2 a.m. Most engagements test production because that is what an attacker would.

## Tell us what you're most worried about. We'll start there.

Scoping is a conversation with a tester. Thirty minutes and you'll have rules of engagement and a fixed price.

[Scope a test](https://novacoast.com/contact-us/)
