Contact
HOP 00 · THE OPEN INTERNET

Penetration Testing Singapore

An attacker does not need every door open — just one unbroken path from the open internet to the folder that matters. Penetration testing Singapore businesses can act on walks that path the way a real attacker would, then hands you the hop where it breaks, in writing.

Web, mobile, network and cloud. Scope and method agreed before we start, severity-ranked findings with reproduction steps, and a retest once you have fixed them — delivered under a CSRO licence.

Scoped in writingMethod and fee before we start
Human testingScanners support, never replace
Retest included in the feeClosure evidence for auditors
Scope & method signed first
Reproduction steps per finding
Retest included
ATTACK PATH · ONE ENGAGEMENTSG
  1. 01Recon
  2. 02Phish
  3. 03Foothold
  4. 04Escalate
  5. 05Move
  6. 06Exfiltrate
/finance/2026-paymentsTAP A HOP
• scoped in writing • retest included

TAP ANY HOP — IT OPENS THAT HOP ON THE PATH BELOW

The path, not the checklist

Penetration Testing Singapore — six hops from the internet to your finance folder

A finding on its own is a line in a report. A chain is a business problem. Flip the controls you actually have and watch how far the attacker gets before the path breaks — then read what the test proves at that hop.

Reach · self-reported
Hop 06CHAIN COMPLETE

Nothing on this path is closed yet: recon to exfiltration runs end to end. That is the state most SMEs are in before their first test.

Book the test that walks this path
Engineer working through the external footprint an attacker would map first
Hop 01 · RECON

What the test does here

External footprinting and OSINT, exactly as an attacker builds it — you get the asset list you did not know you had.

What breaks the chain

Attack-surface review and decommissioning of what should not be public.

Phishing email opened on a phone, the way most real chains begin
Hop 02 · PHISH

What the test does here

A controlled phishing attempt against agreed accounts, measured rather than assumed.

What breaks the chain

MFA everywhere, external-sender banners and a payment-verification rule.

Security engineer working through exploitation chains on multiple screens
Hop 03 · FOOTHOLD

What the test does here

Exploitation of what we found: weak authentication, injection, an old CVE still listening.

What breaks the chain

Patch discipline with dates, and no shared logins on anything internet-facing.

Two engineers reviewing privilege and access on a Singapore client system
Hop 04 · ESCALATE

What the test does here

Privilege-escalation testing on the agreed hosts, with the exact steps written down.

What breaks the chain

Least privilege, admin accounts separated from daily accounts.

Neatly patched fibre network switch in a Singapore office comms room
Hop 05 · MOVE

What the test does here

Lateral-movement testing: what a single compromised device can reach next.

What breaks the chain

Segmentation between user devices, servers and finance systems.

Data centre aisle representing where exfiltrated data ends up
Hop 06 · EXFILTRATE

What the test does here

Proof of what could be taken and how, in a report your auditor and insurer can both read.

What breaks the chain

Detection that isolates rather than logs, plus backups an attacker cannot reach.

Four ways onto the path

VAPT Singapore — the four surfaces a chain starts on

Vulnerability assessment and penetration testing Singapore auditors accept covers four surfaces. Each is scoped, priced and reported separately, so you can start where the risk actually is rather than buying the whole estate at once.

0/4 IN SCOPE
Untested

Four surfaces, one path. Arm the ones you would actually put in scope this year - the quadrants show how much of the estate a test would really cover.

Choosing a penetration testing company Singapore auditors will accept

Two things decide whether a report is accepted: who tested, and against what standard. Our testing is delivered under a CSRO licence, scoped to the framework your regulator or client contract names, and the scope, method and retest are signed before any work begins.

Scope · method · retest — signed before any work beginsREZOLVA PTE LTD · SG
What lands on your desk

The report is the product — and it is written to be acted on

Every finding carries a severity, the exact steps to reproduce it, the business consequence in plain English, and a fix that fits what you actually run. There is an executive summary your board can read in five minutes and a technical section your engineers can work from — then a retest that closes the loop and produces the evidence auditors and insurers ask for.

Rezolva security engineer writing up findings in the Singapore office

One accountable team across all three — the same engineers enterprises like NTU, Prudential and China Telecom have trusted with their infrastructure since 2012.

Client and tester walking through the severity-ranked report togetherSeverity · steps · retest
Executive summaryWhich hop broke the chain, and what it would have cost
Technical findingsSeverity, evidence and reproduction steps per issue
Closure evidenceRetest result your auditor or insurer can file
How it works

Penetration Testing Singapore — how the four-stage engagement runs

Four stages, agreed in writing before we start. Open any stage to see what actually happens in it, what lands on your desk at the end of it, and roughly when.

Stage 01 · SCOPE

Which systems, applications and IP ranges are in play, which hops of the path are in scope, and which standard governs the work: OWASP, PTES or the annex your regulator names.

Deliverable — Signed scope document Scope and testing window agreed with the client before any system is touched
  • Systems, apps and IP ranges listed
  • Testing window and named contacts agreed
  • Destructive techniques excluded unless you ask for them
  • Fixed fee signed before day one
Stage 02 · TEST

A human tester walks the path against the agreed scope. Automated scanning supports the work; it never replaces it, because a scanner cannot chain two findings together.

Deliverable — Daily contact, agreed window Rezolva tester working the agreed scope from the Singapore office
  • Human testing to OWASP / PTES
  • Delivered under a CSRO licence
  • Daily contact — no radio silence
  • Anything critical is called the same day
Stage 03 · REPORT

Findings severity-ranked, each with reproduction steps, plus a plain-English summary that says which hop broke the chain and what it would have cost.

Deliverable — Report + executive summary Severity-ranked findings walked through with the client team
  • Severity, evidence and reproduction steps
  • Executive summary a board can read in five minutes
  • Fix guidance that fits what you actually run
  • Walkthrough call with your engineers
Stage 04 · RETEST

Once the fixes are in we verify them and issue the closure documentation your compliance reviewer, insurer or enterprise customer asks for.

Deliverable — Closure evidence pack Retest signed off and the closure documentation issued
  • Retest included in the fee
  • Closure documentation issued
  • Evidence pack for auditors and insurers
  • Next cycle scheduled if you want one
Stage 01 of 04 — nothing starts until this one is signed. Get a fixed quote

Standards are the rulebooks a report is written against — we use the one your auditor, client or regulator names, and say which one on the cover page.

PDPC · What an untested gap can costSG
S$1,000,000
— or, if higher —
10% of annual SG turnover

The ceiling a Singapore breach can reach. After an incident the regulator does not ask whether you felt secure — it asks what you had tested, when you tested it, and what you did about the findings.

Compliance

Vulnerability assessment and penetration testing Singapore — PDPA, MAS TRM, PCI DSS and the tender

Nobody buys a penetration test for fun. It gets asked for by a regulator, a customer contract, an insurer at renewal, or a tender that will not shortlist you without one — and we scope to whichever of those set the date.

PDPATesting evidence for anyone holding personal data here.
MAS TRMAnnual testing expectations for financial firms and their vendors.
PCI DSSScope-based testing wherever card data is handled.
OWASPThe application testing standard a web report is written against.
PTESHow the engagement itself is run, end to end.
Pricing

Penetration testing cost in Singapore — fixed before we start

Penetration testing cost in Singapore scales with scope: one web application is a smaller engagement than external-plus-internal network testing across two offices. Whatever the scope, the fee is fixed before day one and the retest is included.

Scope sheet · S-01VAPT

Single application

One web or mobile app — the typical first engagement for an SME.

Engagement feefrom S$4,500
  • OWASP-based scope
  • Severity-ranked findings report
  • Reproduction steps included
  • Retest after you fix
Get a fixed quote
Most requested
Scope sheet · S-02VAPT

Network engagement

External plus internal — hops 03 to 05 on the path above, one office.

Engagement feefrom S$8,500
  • External perimeter & internal lateral movement
  • Segmentation checked, not assumed
  • Executive summary for the board
  • Retest after you fix
Get a fixed quote
Scope sheet · S-03VAPT

Full programme

Applications, network and cloud on an annual cycle — for audit-heavy industries.

Annual programmefrom S$18,000
  • Applications, network & cloud
  • Annual retest cycle
  • MAS TRM / PCI DSS alignment
  • Recurring closure evidence
Talk to us

Indicative starting points for a Singapore SME. Defined scope, fixed quote — what you sign is what you pay, and the retest is already in it.

The debrief

Frequently asked questions

Vulnerability assessment plus penetration testing. The assessment scans broadly for known weaknesses; the penetration test has a human exploit what the scan found and chain findings together, which is what turns a list into a path. Most compliance frameworks expect both.

A scanner reports doors that look unlocked. A test walks through them, then tries the next door — and reports the hop where the chain actually breaks. That is the difference between 400 informational findings and one sentence your board understands.

Annually at minimum, plus after any major change: a new application, new infrastructure, an acquisition. Card-payment and financial-sector frameworks set their own clocks, and we align the schedule to the strictest one that applies to you.

Scope decides that. Destructive techniques are excluded unless you explicitly ask for them, testing windows are agreed in advance, and there is a named contact on both sides for the whole engagement.

Human testers working to OWASP or PTES, under a CSRO licence. Some financial-sector contracts name CREST penetration testing Singapore providers specifically — tell us if yours does and we will say plainly whether the scope can be met, rather than implying an accreditation we do not hold. Automated tooling supports the work but never replaces it, because a scanner cannot chain two findings into a path.

It scales with scope — one application is a smaller engagement than external-plus-internal network testing across two offices. The scope sheets above are indicative starting points; the quote is fixed in writing before day one and includes the retest.

Yes, and it is in the fee. You get closure documentation showing what was found, what was fixed, and what was verified — the evidence an auditor, insurer or enterprise customer actually asks for.

That is the most common reason SMEs call. Tell us which document set the deadline and what it names, and we scope to it rather than to a generic checklist.

Your move first

Book the test that walks this path

Tell us what needs testing and why — a tender, a regulator, an insurer, or the fact that nobody has ever tried. You get the scope, the method and the fee in writing before anyone touches a system.