OSCP · OWASP · PTES · Pentest

Penetration Testing Switzerland · Web, App & Network Pentest

A penetration test, often called a pentest or ethical hacking for short, is a simulated, manual attack on your critical systems. SIDD testers work to OWASP, PTES and OSSTMM, with a named lead tester and a traceable report. No scanner output, but real business-logic findings.

from CHF 1,490 · fixed price Report in 5 days OSCP-certified testers OWASP · PTES · OSSTMM
Penetration testing Switzerland - manual testing to OWASP/PTES/OSSTMM
CREST-trained · OSCP-certified
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Manages pentest mandates from scoping through the rules of engagement to remediation sign-off. A direct point of contact for executive management and IT.

LinkedIn profile

Pentest, penetration test, ethical hacking, what do we mean?

Synonyms for the same process: an authorised attack on your critical systems in order to find real vulnerabilities before real attackers do.

  • Improved security, Identification and prioritisation of the risks to confidentiality, integrity and availability.
  • Avoiding data loss and reputation risk, protecting sensitive data (customers, finances, trade secrets) from hacker attacks.
  • Compliance, Evidence towards ISO 27001, PCI DSS, GDPR, NIST, DORA, NIS2.
  • Improved efficiency, Bottlenecks, errors or configuration issues are identified along the way.

Why automated tests are not enough

Simple, low-cost pentests are often (partly) automated and use off-the-shelf tools to scan for known vulnerabilities. They identify surface-level issues but miss business-logic flaws, design flaws or zero-days. Manual penetration tests are carried out by certified pentesters who develop tailored attack scenarios, penetrate more deeply and provide concrete remediation recommendations, including a complete, business-readable report.

For pure vulnerability scans, we offer the separate Vulnerability scan from CHF 5'000.

Our methodology

We test in line with the three leading industry standards.

  • OWASP Web Security Testing Guide for web apps and APIs (incl. OWASP Top 10, ASVS).
  • PTES (Penetration Testing Execution Standard) for a structured approach from pre-engagement to reporting.
  • OSSTMM for network and infrastructure.
  • MITRE ATT&CK as a reference for attack techniques and detection mapping.

Which systems we test

We cover the full scope, individually or combined:

  • Web applications and portals (OWASP Top 10, business logic)
  • Network and infrastructure (external and internal)
  • Cloud environments (Microsoft 365, AWS, Azure)
  • APIs and interfaces (REST, GraphQL)
  • Mobile apps (iOS and Android)

What does a pentest cost? Honest pricing

Pentests are not off-the-shelf products, but we provide you with transparent price ranges per test type. Final price after scoping.

Test typeTypical durationPrice range
Web app (medium)5–10 daysCHF 12'000 – 25'000
External network3–7 daysCHF 8'000 – 18'000
Internal network5–10 daysCHF 12'000 – 28'000
API (REST/GraphQL)4–8 daysCHF 10'000 – 22'000
Mobile app (iOS/Android)6–10 daysCHF 14'000 – 26'000

The final price depends on the scope, the number of endpoints/hosts, the desired depth (black/grey/white box) and retest requirements.

Fixed-price pentest packages

Web-app pentest

from CHF 1,490

One web application tested against the OWASP Top 10 and business logic. Audit-ready report with CVSS rating, retest included.

Full scope

on request

Web, API, cloud and network combined. For certifications, FINMA audits and due diligence.

How does a pentest work at SIDD?

Six phases, transparently documented.

Contract & RoE

Digital service agreement and Rules of Engagement.

Kick-off

Define objectives, scope, methodology and schedule. Grant authorisations.

Reconnaissance

Gathering information on target systems, IP addresses and applications.

Vulnerability analysis

Manual and automated tests identify attack vectors and assess risks.

Exploitation

Vulnerabilities are exploited, access, data extraction, privilege escalation, all documented.

Report & debrief

Detailed report with findings, CVSS scores, remediation recommendations and lessons learned. Debrief call included.

Why SIDD?

A pentest is only as good as the person carrying it out, and only as credible as the firm behind it: at SIDD, certified testers, in-house engineering and legal confidentiality come together.

Named lead tester

You know who is attacking your systems: a named, certified lead tester (OSCP, CREST-trained) remains your dedicated point of contact from scoping through to remediation sign-off. No rotating subcontractors, no anonymous reports.

In-house engineering team

Our CTO Oliver Stutz leads an in-house InfoSec and software engineering team. Those who build applications themselves recognise business logic flaws and auth/authZ weaknesses that pure scanners and pure consultants overlook.

Findings under professional secrecy

Where Dr Staiger acts as your lawyer, your vulnerabilities fall under Swiss professional secrecy pursuant to Art. 321 SCC. Findings are shared exclusively with the persons you designate, a level of confidentiality that purely technical providers cannot offer.

The assessment stays independent

We do not first sell you the gap and then the product that closes it. The penetration test remains an independent assessment, which keeps the report audit-credible against ISO 27001, DORA or NIS2.

Contract before the first attack

Rules of engagement, commissioned processing and liability questions are clarified by lawyers holding doctorates while the InfoSec team conducts the testing. This way, contract, authorisation and data protection are properly settled before the first attack is launched.

Testing across multiple jurisdictions

SIDD has operated as a Swiss brand since 2017, with a first response within 24 hours and a dedicated contact person. Mandates in CH, EU, UK and US allow penetration tests to span multiple locations and jurisdictions.

Pentest for SMEs, Fixed-Price Packages

For SMEs we offer penetration tests as a fixed-price package with a clearly defined scope: one web application, the external perimeter or a delimited network segment. You receive the same manual testing approach and the same traceable report as our corporate clients, at a predictable price.

IT Security Audit Switzerland

Beyond the penetration test itself, our IT security audit assesses your technical and organisational measures against recognised frameworks such as ISO 27001 and the Swiss ICT minimum standard. You receive a prioritised list of measures with which risks can be demonstrably reduced.

What your report looks like

You receive an audit-ready report: management summary, technical findings with CVSS score, reproduction steps and concrete remediation recommendations. After remediation, a retest is included.

Report accepted for ISO, FINMA and FADP

Our report is accepted by the bodies that matter to you:

ISO 27001
FINMA
FADP / revised DSG
Cyber insurance

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the pentest report, concretely: LexCommand ties each finding to the specific obligation it breaches with a cited source and, via the framework crosswalk, surfaces which ISO 27001, DORA, NIS2 and revFADP requirements the same gap touches at once, keeping the report audit-credible.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

How long does a penetration test take?

Depending on the scope, 3–10 tester-days. Including reconnaissance, test execution, reporting and debrief, the calendar duration is 2–4 weeks from kick-off.

Black box, grey box or white box?

We usually recommend grey box (limited prior information, possibly a standard account). Black box is realistic but time-consuming. White box uncovers the most vulnerabilities per day, well suited to internal audits.

Is a retest included?

On request, yes. A retest after your remediation typically costs 20–30 % of the initial effort and is agreed as part of many mandates.

Which report, executive or technical?

Both. The report contains an executive summary for executive management/the board of directors and a technical detail section for your IT/developers, each with CVSS scores and remediation recommendations.

Vulnerability scan or penetration test, which do I need?

If you want to check regularly for known vulnerabilities, the Vulnerability Scan. To validate business logic, auth/authZ and manual attack paths, you need a penetration test. Many clients combine the two (scan quarterly, penetration test annually).

Are findings subject to professional secrecy?

Yes. Findings are shared exclusively with the persons you designate. Enquiries are subject to professional secrecy under Art. 321 SCC.

Ready for an honest, manual penetration test?

30-minute scoping call. We will give you the price and timeframe immediately afterwards.