Web application pentesting for Canadian SMBs
Customer portals and admin consoles are where the money sits. Testing them is not the same as scanning the office firewall.
ITSIGN Administrator · January 22, 2025 · 2 min read
If customers log in, if staff approve invoices, if an API talks to your ERP, that application is in scope whether or not it lives in Azure.
Unauthenticated scans stop at the login form. Real testing uses a normal user and an admin, then looks for broken access control, injection, and the forgotten debug endpoint from last year's contractor.
What we ask for
A staging copy if you have one. Two roles. A rules of engagement that says we stop before we delete data. A developer on the call for the readout.
That work lives under penetration testing. If the app is the business, do not bury it inside a generic network test.
Related reading
When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
2 min read
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
2 min read
Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
