DSE Cybersecurity · Penetration testing

Prove the path works. Not just that it might.

Penetration testing is hands-on exploitation against an agreed scope, under a written rules-of-engagement and authorization letter: DSE tries to get in, moves the way an attacker would, and hands you reproducible evidence of what actually happened, not a scanner report. DSE is booking scoping calls now, and DSE is currently scheduling roughly two weeks out from a signed statement of work.

For security and engineering leaders who need exploitation evidence, not just a findings list. Quote only, confirmed in writing after scoping: no published price ranges. Internal network and assumed-breach testing are not offered this wave.

Wave 1 · three scopes

Start with the surface that matters most.

DSE is launching penetration testing with three focused scopes. Each is its own engagement with its own rules-of-engagement and authorization letter; buyers who need more than one can scope them together.

External

Network & web application

Externally reachable infrastructure and web applications: exposed services, authentication, session handling, injection, and access-control failures an outside attacker could reach today.

Cloud & identity

Configuration & attack-path testing

Cloud configuration and identity attack-path testing across AWS, Azure, or Microsoft 365: privilege-escalation chains, misconfigured trust, and the paths that turn one compromised identity into standing access.

AI / LLM

Deployed application exploitation

Prompt injection, tool abuse, and data-exfiltration paths exploited against a deployed AI application, not just identified. Extends LLM security testing from review into exploitation.

Method

Scope it. Test it. Prove it. Retest it.

Four phases, in order, under a written rules-of-engagement and authorization letter agreed before any testing starts.

01

Scope & authorization

Target systems, testing window, rules-of-engagement, and explicit exclusions, confirmed in writing and signed before any testing begins.

02

Execution

Hands-on testing against the agreed scope: reconnaissance, exploitation attempts, and, where authorized, chaining findings into a proven path.

03

Evidence & severity

Findings ship with reproducible evidence, a severity rating, and the specific control it maps to, so engineering can act without guessing at intent.

04

Retest

After remediation, we confirm the fix actually closes the finding, where a retest window is scoped into the engagement.

Delivery model

DSE scopes and leads. Every engagement.

DSE scopes and leads every penetration testing engagement. Execution is performed by DSE testers or by a partner firm DSE has vetted for the engagement; DSE requires OSCP, GPEN, PNPT, or an equivalent credential of any tester it assigns. DSE remains accountable for scope, quality, and the final report on every engagement, regardless of who performs the hands-on testing. Where a partner firm executes, that role is disclosed in the statement of work.

Conflict policy

We will not test our own work.

DSE will not penetration test an environment that DSE operates or administers as a managed service. A conflict check runs before every statement of work is signed. Where DSE holds an operational or administrative role in the target environment, the engagement is scoped to an independent tester instead, and that routing is disclosed to you.

Timing

Booking scoping calls now.

DSE is booking scoping calls now. DSE is currently scheduling roughly two weeks out from a signed statement of work, depending on scope and current calendar. Tell us the scope, the target environment, and your preferred testing window, and we will return fit and a fixed-price statement of work, not a number on a page.

Common questions

What buyers ask before scoping.

What does wave 1 of DSE's penetration testing cover?

Three scopes: external network and web application testing, cloud configuration and identity attack-path testing across AWS, Azure, or Microsoft 365, and AI/LLM application penetration testing that exploits prompt injection, tool abuse, and data exfiltration paths on a deployed AI application.

Is internal network or assumed-breach testing available?

Not this wave. DSE is not offering internal network or assumed-breach penetration testing in wave 1. That is a boundary, not a hedge: ask about the three wave-1 scopes above, and we will tell you plainly if what you need falls outside them.

How much does a penetration test cost?

DSE does not publish price ranges for penetration testing. Scope and fixed price are confirmed in writing after a scoping call, once we know the target environment, its size, and the scope you need. Every engagement starts with the contact form.

Who actually performs the testing?

DSE scopes and leads every engagement. Execution is performed by DSE testers or by a partner firm DSE has vetted for the engagement; DSE requires OSCP, GPEN, PNPT, or an equivalent credential of any tester it assigns. DSE remains accountable for scope, quality, and the final report on every engagement, regardless of who performs the hands-on testing.

Will DSE test an environment it manages for us?

No. DSE will not penetration test an environment DSE operates or administers as a managed service. A conflict check runs before every statement of work, and where DSE holds an operational or administrative role in the target environment, the engagement is scoped to an independent tester instead.

How is this different from the LLM security testing review?

LLM security testing reviews an AI application for prompt injection, data leakage, and tool-abuse risk and hands back findings. The AI/LLM penetration testing scope in wave 1 extends that review into exploitation: proving the path actually works against the deployed system, not just identifying that it might. Buyers who want both can scope them together.

Clear boundaries

Exploitation evidence, not assurance.

Penetration testing is a point-in-time test of the systems in the agreed scope, executed under a written rules-of-engagement and authorization letter. It is not a SOC 2 or ISO 27001 attestation, not a legal opinion, and not a certification of compliance: independent attestation and certification bodies retain those roles. It does not guarantee the absence of every vulnerability, and it is not internal network or assumed-breach testing, which DSE does not offer this wave. Pricing is quote only, confirmed in writing after a scoping call; DSE publishes no price ranges for this service.