NIS2 checkContact

Penetration testing and phishing

Tested the way an attacker would

A black box penetration test of your internet-facing infrastructure, and a phishing campaign aimed at your staff. Our testers start with nothing but your name and the address ranges you confirm in writing. The result shows what an outsider can actually reach, and what happens when an outsider emails your staff.

Black boxno credentials, no prior knowledge
OWASPguidance and NIST SP 800-115 as the method
CVSSevery finding rated, every asset named
100% EUtesters, data and reports

The approach

Only what an outsider can see

A black box test starts from the position of a real external attacker. We receive no internal documentation, no credentials and no architecture diagrams. What we do receive is a written confirmation of the public address ranges and domains in scope, and an authorisation letter signed by both parties. Nothing outside the agreed scope is touched.

The testing is carried out by certified testers from our delivery centres in Sofia, Varna and Stara Zagora, under the same certified management systems as the rest of our services. You contract with Think Smart Europe B.V. in Amsterdam. Critical findings are escalated on the day they are confirmed, not at the end of the engagement, and the same testers stay on from the first scan to the retest.

One named engagement leadThe same person from scoping to the final walkthrough, and the escalation point for critical findings.
Weekly written progressA short written update every week and status meetings with your IT team while the test runs.

Coverage

What we test at the perimeter

Twelve standard activities, grouped into six areas. Every finding is rated with CVSS and tied to a named asset, so your IT team knows what to fix first.

Perimeter and routing

Routers, switches, firewalls and intrusion detection and prevention devices, and the rules that hold them together.

Remote access and VPN

VPN endpoints, exposed management interfaces and the password resilience of every login reachable from the internet.

Exposed services

Web, mail, DNS and DHCP services, with service fingerprinting and the version information they give away.

Known vulnerabilities

Reachable hosts and services checked against known issues, then verified by hand, so the report contains confirmed findings rather than scanner output.

Cryptography

TLS configuration, certificate management and the use of weak ciphers or outdated protocols on every reachable service.

Layer 2 and layer 3

Spoofing, poisoning and protocol weaknesses, inside the agreed boundary only.

Testing follows OWASP guidance and NIST SP 800-115. Connections to group IT and the segregation from the wider estate are tested at the boundary only.

Method

How a black box test runs

Five stages, in a fixed order. You know at every moment which stage the test is in and what it produces.

01

Scoping

Targets, test windows and contacts are agreed in writing. The public address ranges are confirmed, the authorisation letter is signed by both parties and the escalation route for critical findings is in place before the first packet is sent.

02

Reconnaissance

Passive discovery from public sources. What your organisation exposes about itself before anyone has touched your systems.

03

Enumeration

Port, service and version mapping across the confirmed ranges, so every reachable service is known by name and version.

04

Exploitation

Controlled attempts on the findings, to establish what is actually reachable rather than what a scanner suggests might be. Critical findings are escalated immediately.

05

Reporting

An executive summary for the board and a technical report for IT, followed by a walkthrough with your team.

We work from the agreed scope only. No internal documentation, no credentials and no architecture detail, so the result reflects what a real external attacker can actually reach.

What the campaign measures

Six figures, one campaign

The phishing campaign is a separate test with its own report. No email addresses are handed over: the testers build the recipient list from public sources, the way an outsider would. Six measures come out of one campaign, reported by team and never by named employee, so the outcome serves the awareness programme rather than blame.

Delivery and open

How many messages reached a mailbox, and how many were opened where that can be measured.

Click-through

Who followed the link, as a share of the messages actually delivered to the target group.

Submission

Who entered details on the simulated page. Nothing entered there is kept or reused.

Reporting rate

Who recognised the message and raised it through the normal internal reporting route. This is the figure you want to see rise.

Compromise rate

Who went beyond the first interaction. This gives the overall exposure figure per site or per organisation.

Result by team

Figures per department or group, so awareness effort can be aimed where it does most good.

No malware is deployed, no service is disrupted and no employee account is accessed. Anything entered on the simulated page is neither kept nor reused.

Deliverables

What you receive

Every engagement ends with the same set of documents, written for different audiences.

Deliverables of a Think Smart Europe penetration test and phishing campaign
DeliverableWhat it containsWho it is for
Executive summaryThe overall risk position, the most important findings and the recommended order of remediation, in plain language.Board, management and audit committee
Technical reportEvery finding with its CVSS score, the affected asset, the evidence, the steps to reproduce it and a concrete recommendation.IT and security team
Phishing analysisThe six measures per team, anonymised examples and advice for the awareness programme.IT, HR and whoever runs awareness training
WalkthroughA session with your team to go through the findings, answer questions and agree who fixes what.Everyone involved in remediation
Retest, where agreedAfter remediation the findings are tested again and the report is updated, so you can show which findings were resolved.Auditor, insurer, customer

Weekly written progress reporting and status meetings with your IT team run throughout the engagement. Where several sites are in scope, each site is scoped and reported separately, with one consolidated report on top, and the tests can run in parallel.

NIS2

Which of the ten measures it supports

A penetration test and a phishing campaign are not measures in themselves. They are the evidence that three of the ten measures do what they are supposed to do.

e

System lifecycle

Article 21(2)(e) asks for vulnerability handling across the life of every system. A penetration test shows which vulnerabilities are actually reachable from outside, and in which order to close them.

f

Effectiveness assessment

Article 21(2)(f) asks you to assess periodically whether the measures have the intended effect. An independent test is the most direct form of that assessment, and the report is the evidence.

g

Cyber hygiene and training

Article 21(2)(g) asks for training across the organisation. A phishing campaign measures whether the training has landed, and where to aim the next round.

Frequently asked

Frequently asked questions

Can a test disrupt our production environment?

The test runs inside agreed windows, exploitation is controlled and no denial of service is attempted. Nothing outside the agreed scope is touched.

A critical finding is escalated on the day it is confirmed, to the contact you named at scoping, so your team can act before the report is written.

Will our employees be named in the phishing report?

No. Results are reported per team or department, never per named employee. Anything entered on the simulated page is neither kept nor reused. The purpose is to aim the awareness programme, not to single anyone out.

Who does the testing?

Certified testers from our delivery centres in Sofia, Varna and Stara Zagora, inside the European Union and under the certified management systems of our parent organisation in Bulgaria. Certifications held across the team include OSCP, OSWE, OSCE, OSWP, CREST CPSA and CRT, CISSP, CISA, CEH and eWPTX. Anonymised CVs are available on request.

Where Think Smart Europe runs the environment itself, we advise having it tested by another party. Independence is the point of the exercise, and our Managed CISO will say the same thing.

Is a penetration test a NIS2 requirement?

The directive does not name it. It does ask for vulnerability handling, for a periodic assessment of whether the measures work and for training across the organisation, in Article 21(2)(e), (f) and (g). A test report is the most direct evidence for all three, and it is what an auditor, an insurer or a customer questionnaire asks for by name.

Scope your test with our CISO

In the call we go through your internet-facing estate, the number of sites, the target group for the phishing campaign and the test window. You then receive a fixed scope and a fixed fee per site.

Cyber Incident