Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Penetration testing for the systems your organisation actually runs.

F Creative Studio 360 carries out authorised testing of networks, web applications, APIs, cloud, mobile and wireless environments, so you can see what is exploitable and fix it first.

A test is an authorised attack on your own systems.

Automated scanning finds known issues. It does not show whether those issues chain together, or what a person could do with them. Penetration testing, sometimes called ethical hacking, is the manual work that answers that question.

F Creative Studio 360 delivers this work for organisations in any country. Every engagement is scoped before testing starts, and a client environment is only touched when that organisation has authorised the work.

Find what can actually be used
A scan lists weaknesses. A penetration test tries them, within an agreed scope, so you see what an attacker could reach.
Spend on the risks that matter
Findings are rated by impact on the business, so remediation effort goes to the issues that change the outcome.
Evidence for boards and auditors
A written record of what was tested, what was found and what was fixed supports PCI DSS, ISO 27001, SOC 2, NIST and the local rules that apply where you operate.
Check the controls you already pay for
The test shows whether firewalls, identity, monitoring and application controls hold up against a realistic attempt.

What we test

Engagements are scoped to the estate you have. A typical programme draws from the following. Web application work is assessed against the OWASP Top 10. Cloud work covers Amazon Web Services, Microsoft Azure and Google Cloud.

Network
Internal and external testing of servers, workstations, firewalls and network devices. External work starts from outside. Internal work assumes someone is already in.
Web applications
Testing against the OWASP Top 10, plus business-logic flaws, authentication weaknesses and injection issues in the applications your customers and staff use.
APIs
REST, SOAP and GraphQL interfaces checked for weak authentication, excess data exposure and injection.
Cloud
Configuration and access review of environments on Amazon Web Services, Microsoft Azure and Google Cloud.
Mobile
iOS and Android applications, including the app itself, the APIs it calls and how data is stored on the device.
Wireless
Wireless networks checked for weak encryption, poor segmentation and access points that should not be there.
Connected devices
Devices, the protocols they speak and the systems behind them, where that estate is in scope.
Social engineering
Authorised phishing, voice and message exercises that show how staff respond. Physical pretexting is only included when it is explicitly in scope.
Testing through delivery
Assessments placed at agreed points in design, build and release, so issues are found before a system is in production.
Ongoing testing
A recurring programme of manual and targeted testing, rather than a single annual exercise.

How an engagement runs

Testing follows a written scope. We do not wander into systems, client environments or availability tests that were not agreed.

  1. 1

    Scoping and planning

    Agree the systems, the rules, the access we will have and the window for the work.

  2. 2

    Reconnaissance

    Learn how the in-scope environment is exposed, using only the access the scope allows.

  3. 3

    Vulnerability identification

    Combine review and testing to find weaknesses worth proving.

  4. 4

    Exploitation

    Confirm which weaknesses can be used, and stop at the point needed to show impact.

  5. 5

    Analysis and reporting

    A report for leadership and a technical record for the people who will fix it.

  6. 6

    Remediation and retesting

    After fixes, we retest the findings so you have evidence the issue no longer works.

What the report contains

  • An executive summary written for people who will not read the technical detail.
  • Findings for the security and engineering teams, with proof that each issue is real.
  • A rating on every finding, from critical through to informational.
  • Remediation guidance that says what to change, why it matters and what to do next.
  • A retest of the items you have fixed, when that is part of the engagement.

Standards the work can align to

F Creative Studio 360 plans each test around the obligations that apply where you operate. The common references are OWASP, NIST, PTES, OSSTMM, PCI DSS, ISO 27001 and SOC 2. Country or sector rules are added when they apply, including DORA in the European Union and CPS 234 in Australia. Some buyers also ask for CREST-accredited providers. Tell us the requirement and the engagement is scoped to it.

The useful difference is manual analysis. Chained issues, the ones a scanner lists as separate low findings, are where a real intrusion usually sits. The report is written so a non-technical reader can see the risk and a technical reader can reproduce and fix it.

Common questions

What is penetration testing?+

It is an authorised test of your own systems. F Creative Studio 360 uses the same classes of technique a real attacker would, against the network, applications, cloud and infrastructure you put in scope. You receive a risk-rated report of what was found and how to fix it.

When is it required?+

It depends on where you operate and what you must show. PCI DSS expects testing at least annually and after significant change. ISO 27001 and SOC 2 expect evidence that controls work. NIST is widely used as the reference model. Local rules also apply, such as DORA in the European Union, CPS 234 and the Essential Eight in Australia, or a sector regulator in your own country. Many insurers ask whether regular testing is in place before they issue or renew a policy.

How is this different from a vulnerability assessment?+

A vulnerability assessment identifies and prioritises known weaknesses. A penetration test goes on to confirm which of those weaknesses can be used and what that would allow. Many organisations use both: the assessment for coverage, the test for proof.

How long does it take?+

A focused web application test is often a few days. A network test is often one to two weeks. A broader adversary-style exercise can run several weeks. F Creative Studio 360 scopes the work first, so the timeline matches your environment rather than a generic estimate.

What is the difference between black box, grey box and white box?+

Black box starts with no inside information, closer to an outsider. Grey box includes some context, such as a user account or documentation, closer to an attacker who already has a foothold. White box includes source, architecture and credentials, closer to a thorough internal review. Grey box is often the most useful balance of realism and depth.

What is the difference between authenticated and unauthenticated testing?+

Unauthenticated testing looks at what is reachable with no credentials. Authenticated testing looks at what is possible after access is obtained, which is where serious impact usually sits. Where the scope allows, we recommend providing credentials so that part of the risk is examined.

Is denial-of-service testing included?+

No. It is not part of a standard engagement. Many cloud providers restrict it, and an uncontrolled test can disrupt the service. If resilience of that kind is a requirement, we scope it separately and only with the right approvals in place.

Can you retest after we fix the findings?+

Yes. Once your team has applied fixes, we retest the findings that were in scope and document whether they still work. That record is what most audit and compliance conversations ask for.

How much does it cost?+

It depends on the systems, the type of test and how much information we are given. A scoping conversation with F Creative Studio 360 is the way to get a quote for your environment. There is no obligation to proceed.

Talk through what should be in scope.

F Creative Studio 360 will look at the systems, the constraints and the reason for the test, then tell you what a sensible engagement looks like.