Audit & pentest

At Oxydian, we carry out comprehensive cybersecurity audits and penetration tests (pentests) to identify and fix the vulnerabilities in your systems before they can be exploited.

Whether you are an SME, a mid-sized company or a large enterprise, our expertise guarantees an accurate diagnosis and a concrete action plan.

What is an intrusive audit or pentest?

An intrusive audit is a proactive security assessment involving controlled penetration tests to identify the vulnerabilities and risks of a system, network or application.

Our experts simulate a targeted attack in order to identify potential security flaws that could be exploited by malicious actors.

Objectives

Our approach involves examining your information systems in depth to uncover any vulnerability, whether technical, organisational or user-related.

Drawing on methodical analysis and realistic scenarios, we measure the potential impact of each weakness and prioritise the risks.

Every assessment is tailored to the actual configuration and operation of your infrastructure, providing you with fast, effective solutions to reduce threats and strengthen your security for the long term.

Types of audit

Discover our main types of audit, suited to every environment and security level.

Internal audit

Detection of flaws on the assets of the company’s internal network, attempts to compromise accounts or the Active Directory system, and searches for sensitive data.

Web application audit

Detection of application flaws in a web application. Attempts at injection, privilege escalation, authentication bypass, and more.

External audit

Mapping and search for vulnerabilities on the information system’s internet-facing assets (public IPs, APIs, showcase website, etc.).

Architecture audit

Review of the technical architecture of an application or network to assess its resilience against cyber threats (good practice, segmentation, data flows).

Code audit

Study of an application’s code in search of security flaws, poor development practices, exposed secrets or logic errors that could compromise security.

Configuration audit

Verification that the configurations of the information system’s hardware, software and cloud components comply with the latest security requirements.

Red Team engagement

Simulation of a targeted, realistic attack by experts stepping into an attacker’s shoes to challenge the organisation’s detection and response capabilities.

Physical intrusion

Testing of the physical security of your premises to identify human or physical weaknesses (access, badges, surveillance).

Retest

Targeted verification that the vulnerabilities detected by a previous audit have been properly fixed, to validate the effectiveness of the measures put in place.

Our audit and pentest methodology

Oxydian applies a proven approach based on international standards (OWASP, PTES, NIST).

01

1 – Planning
Defining the objectives and scope of the cybersecurity audit to align the tests with your priorities.

02

2 – Reconnaissance
Mapping assets and gathering information to identify the attack surface.

03

3 – Exploration
Manual investigation combined with the innovative tools developed by Oxydian to detect exploitable vulnerabilities.

04

4 – Exploitation
Controlled attack simulation to validate the presence and impact of the identified flaws, as well as the resilience of the targets.

05

5 – Report & action plan
Delivery of a report detailing the actions carried out, the identified vulnerabilities ranked by criticality, and personalised recommendations to improve security.

Audit profiles

Depending on your needs, we offer three distinct audit profiles, ranging from real-world testing to full-access analysis.

Black box

Profil d'attaque en boite noire, représenté par une boite noire avec le logo oxydian dessus

The auditor has no prior access to any information, just like an external attacker.

Grey box

Profil d'attaque en boite grise, représenté par une boite grise avec le logo oxydian dessus

The auditor only has access to certain information. This scenario represents the case of a compromised account.

White box

Profil d'attaque en boite blanche, représenté par une boite blanche avec le logo oxydian dessus

The auditor has full (admin) knowledge in order to carry out an in-depth audit.

Our audit reports

Our audit reports are clear, detailed and actionable, designed for both technical teams and decision-makers. They provide a comprehensive view of the current state of your cybersecurity, with concrete, personalised fixes to make remediation easier.

Contents (around 100 pages):

Frequently asked questions

Why carry out a pentest?

To detect vulnerabilities before an attacker does, to meet regulatory requirements (HDS, ISO 27001, GDPR…), or to reassure your clients and partners about the security of your systems.

How long does an audit take?

From 3 days to 3 weeks, depending on the size of your infrastructure or the scope being audited.

Will the audit disrupt my operations?

No, our tests are designed not to disturb your production environment and to avoid any impact. The most intrusive actions, which could cause disruption, are only carried out with your prior agreement or in a dedicated test environment.

Do you provide support after the audit?

Yes. Our experts remain available to advise you while you fix the flaws, carry out a retest to validate the fixes, or support you in improving your overall security.

Do we have to give you access for the audit?

It depends on the type of audit chosen. In black box, we have no initial access. In grey box, we have limited access. In white box, you provide us with complete technical information.

Audit certificate

At the end of every audit, you receive an official certificate confirming that the audit of your information system has been carried out.

This concise one-page document presents the main findings without disclosing any sensitive data.

It is issued via our secure exchange platform, electronically signed, and its authenticity can be verified at any time through a dedicated online portal.

Book a 30-minute appointment

Enjoy a one-to-one conversation with a cybersecurity expert and gain an outside perspective on the protection of your information system. Together, we will identify your challenges, your priorities and the first areas for improvement.

In 30 minutes, discover our methodology, our deliverables, our advanced analysis tools and benefit from personalised advice from one of our experts.

Contact us

Free Audit

Get a FREE AUDIT, no strings attached!

Oxydian gives you the opportunity to quickly assess your cybersecurity maturity level during a 15- to 30-minute video call.

Speak directly with an expert, identify your needs, and receive 100% personalized recommendations with a prioritized action plan.

Want to assess yourself independently?

An online self-assessment is also available to give you an initial overview of your security level by calculating your cyber score.