Penetration testing for Texas organizations

Find the gaps before your auditor or your attacker does.

Manual penetration testing built on PTES and OWASP, delivered by a Texas security team. Every engagement is scoped and priced up front, and every report is written to satisfy TAC 202 reviews, cyber insurance questionnaires, and your own engineers.

Operated by safemode IT · Kyle, Texas · 24/7 SOC-backed

PENTEST-REPORT.pdf · EXCERPT CRITICAL
F-2026-04External RDP exposed with legacy auth
HOST. Verified via
IMPACTDomain credential capture within of initial access
FIX72 HRRestrict 3389 to VPN, enforce NLA + MFA
Retest: remediation verified 08/14. Finding closed. Attestation letter issued for insurance renewal.
TAC 202Documented control evidence
TX-RAMPAssessment-ready reporting
Cyber insuranceCarrier-accepted reports
HIPAASafeguard verification
PTES + OWASPManual methodology, not a scan
Scope options

What we test

A scanner tells you what software you run. A penetration test tells you what an attacker can actually do with it. Each engagement is scoped to the assets that matter for your compliance requirement or renewal.

External

External network

Everything reachable from the internet: firewalls, VPN portals, mail, exposed services. This is the test insurers and auditors ask about first, because it is the attack surface a stranger sees.

Internal

Internal network and Active Directory

Assumes a foothold and measures blast radius. We chase the path from one compromised workstation to domain admin, then document every hop so your team can cut the chain.

Application

Web applications

Manual testing against the OWASP Top 10 and beyond: authentication flaws, access control failures, injection, and business logic issues automated tools cannot reason about.

Cloud

Microsoft 365 and cloud tenants

Tenant configuration review plus attack simulation: conditional access gaps, legacy protocols, token abuse, and the mailbox rules attackers plant after phishing succeeds.

How an engagement runs

Scoped, tested, reported, retested

01

Scope

A 30-minute call to define targets, rules of engagement, and the compliance driver. You get a fixed price and a signed authorization before anything is touched.

02

Test

Manual testing by our security team against the agreed scope. You get a same-day heads-up on any critical finding rather than waiting for the report.

03

Report

An executive summary your board can read and a technical appendix your engineers can act on, with evidence, severity, and a prioritized fix list.

04

Retest

Once you remediate, we verify the fixes and issue an updated report and attestation letter. That is the document your insurer or auditor actually wants.

The deliverable

A report built for the people who will read it

Executive summaryPlain-language risk picture for leadership, boards, and commissioners. No jargon, no filler.
Technical findings with evidenceEvery finding includes reproduction steps, screenshots, affected assets, and a concrete fix.
Compliance mappingFindings cross-referenced to TAC 202 control families and common insurance questionnaire items, so the report drops straight into your audit file.
Retest attestationAfter remediation, a signed letter confirming verified fixes. Carriers and auditors accept it as documented evidence.
Pricing

Fixed fee, scoped before you sign

No hourly meters and no surprise change orders. The scoping call produces a firm price based on asset count and test type, and that price includes the retest.

Local government entities and appraisal districts: ask about interlocal-friendly terms and budget-cycle scheduling.

$ scope → fixed quote → authorization → test
Get started

Request a scoping call

Tell us what needs testing and what is driving it, whether that is a TAC 202 review, an insurance renewal, or a board mandate. We respond within one business day with available scoping slots.

Facing an active incident instead? Call us directly. Our helpdesk and SOC answer around the clock.

Submissions go to the safemode IT security team. No mailing lists, no resale.