TSR Solutions Managed IT & security

Penetration testing

A scoped, human-led attack on your network, web applications and APIs so you find the gaps before someone else does.

What changes for you

You know which gaps matter

A ranked list of what an attacker could actually reach from outside and from inside, not a scanner dump.

Evidence for your insurer and auditors

A dated report in the format cyber-insurance questionnaires and PCI DSS, HIPAA and SOX reviews ask for.

A fix plan your team can run

Each finding comes with a remediation recommendation, so the report turns into tickets rather than a shelf document.

What's included

  • Scoping call to agree IP ranges, domains, application count, test window and rules of engagement
  • External network test against your internet-facing systems
  • Internal network test from an assumed-breach position
  • Web application and API testing where in scope
  • Choice of production or staging environment
  • Findings ranked by exploitability and business impact
  • Executive summary and technical report with remediation recommendations
  • Walkthrough call to go through the findings with your team
  • Retest of remediated findings after you fix them

How it works

From the first call to steady state.

  1. 1

    Scope

    We agree what is in bounds (external, internal, web app, API), how many IPs and applications, whether we test production or staging, and who to call if something trips.

  2. 2

    Test

    Engineers test manually, using scanners only to cover ground, inside the agreed window.

  3. 3

    Report

    You get ranked findings, a walkthrough call and a fix plan your team or ours can run.

  4. 4

    Retest

    Once fixes land, we confirm they hold and issue an updated report.

Why TSR

1991
Serving Wisconsin businesses since
24×7
Detection and response in Guardian and Sentinel
One rate
Per user, per month. No add-on invoices inside a package

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Questions we get asked

Will testing take systems down?

No. Denial-of-service is out of scope by default and anything disruptive is agreed in writing first. You can also choose a staging environment instead of production.

How is this different from a vulnerability scan?

A scan lists known weaknesses. A pentest chains them the way an attacker would and tells you what they could reach. Guardian and Sentinel already include continuous scanning; a pentest is the human step on top.

What do you need from me to quote?

The types of testing you want, roughly how many IP addresses and applications, the ranges or domains involved, any compliance driver (PCI DSS, HIPAA, SOX) and your preferred timeline.

How fast can you start?

Timelines range from as soon as possible to within three months. Tell us your deadline and we will schedule around it.

Do I need a separate web application test?

Only if you want the deeper, role-based application test. Basic web app and API coverage can be part of a network engagement; see the web application penetration testing service for the full treatment.

Request a pentest quote

Tell us a little about your environment and an engineer will reply within one business day with next steps, not a brochure.

Prefer to talk? Call 262-292-2000 or email sales@tsrsolutions.com.

Or open the full quote form: Get a quote for Pentest