Overview
Engagements in Ireland cover banks, insurers and payment institutions, the EU headquarters and data centres of international technology companies, medtech and pharma manufacturing, and the SaaS companies selling into all of them.
Delivery runs from our Karachi office, five hours ahead of Irish time, with our United States office covering the Irish afternoon. Between the two, your working day is covered end to end.
What drives testing here
Local drivers
- Central Bank of Ireland
- Cross-industry guidance on IT and cybersecurity risk sets board-level accountability and expects independent assurance over control effectiveness.
- DORA
- Financial entities and their critical ICT providers face testing, incident reporting and third-party risk obligations, which reach suppliers as contract terms.
- GDPR one-stop-shop
- The Data Protection Commission is lead supervisory authority for much of the sector, so a breach here is examined against Article 32 in front of a regulator with the largest EU caseload.
- NIS2
- The Irish transposition widens scope across digital infrastructure, managed service providers and their supply chains.
How engagements are delivered
Delivered across both offices for full coverage of Irish business hours, with on-site availability in Dublin, Cork and Galway for internal network scope and workshops.
Delivery model
- Delivery
- Pakistan covers your morning, the United States covers your afternoon
- Mapping
- CBI guidance, DORA, GDPR Article 32 and OWASP ASVS as applicable
- Coverage
- Dublin, Cork, Galway, Limerick and remote nationwide
- Deliverables
- Technical report, regulator-facing summary and retest attestation
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Service 02API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Questions
Are you based in Ireland?
No. Our offices are in Pakistan and the United States. Irish engagements are covered across both, which gives a full working-day overlap, with on-site attendance arranged where scope requires it.
We are the EU entity of a US parent. Whose scope applies?
Both, usually, and the report is written for both. The technical findings are the same; the framing differs, so the deliverable covers GDPR Article 32 and the applicable CBI or DORA expectations alongside whatever the parent needs for SOC 2 or its own audit chain.
Can you test infrastructure hosted in an Irish data centre?
Yes, with written authorisation from the party entitled to grant it. Where the infrastructure belongs to a cloud provider rather than to you, testing stays inside what their acceptable use policy permits, which covers your workloads and configuration rather than their underlying platform.
How much does a penetration test cost in Ireland?
Cost follows scope rather than a Dublin rate card. A fixed quote follows a short scoping call, and where both an Irish entity and an overseas parent need reporting, that is covered in one engagement rather than two.
Which is the best penetration testing company in Ireland?
No single name is honest. Check the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether retesting is included, and whether you can review a redacted sample report before signing.
Do you test for Central Bank of Ireland regulated firms?
Yes. Cross-industry guidance on IT and cybersecurity risk sets board accountability and expects independent assurance over control effectiveness, and reports are written to serve both the board summary and the technical remediation plan.
Can you provide GDPR Article 32 evidence?
Yes. Article 32 requires a process for regularly testing and evaluating the effectiveness of technical measures. A dated independent test, tracked to closure and retested, is that process evidenced. The Data Protection Commission's caseload makes this a practical concern here rather than a theoretical one.
Do you work with medtech and pharma manufacturers?
Yes. The estate usually spans corporate IT, manufacturing systems and cloud platforms, and the interesting exposure is typically at the joins. Manufacturing and control systems are tested in a controlled environment rather than live.