Overview
Engagements in Switzerland cover private banking and wealth management, insurance, the crypto and digital asset firms clustered around Zug, pharma and medtech, and the technology providers serving all of them.
Delivery runs from our Karachi office, four hours ahead of Swiss time, with reporting and live sessions inside your working day.
What drives testing here
Local drivers
- FINMA Circular 2023/1
- Operational risk and resilience supervision expects regular vulnerability testing and threat-led penetration testing, with material incidents reported to FINMA within 72 hours.
- Revised Data Protection Act
- The revised FADP raised the bar on technical measures and attaches personal liability in a way its predecessor did not.
- Banking confidentiality
- Article 47 obligations make client data handling during an engagement a legal question, not only a contractual one, which shapes scope and method from the start.
- NCSC reporting duty
- Critical infrastructure operators carry a statutory incident reporting obligation, and reporting is easier where the estate has been tested and documented first.
How engagements are delivered
Delivered remotely from Karachi, scheduled to CET business hours, with on-site availability in Zurich, Geneva, Basel and Zug for internal network scope and workshops.
Delivery model
- Delivery
- Remote from Karachi, four hours ahead of CET; on-site available
- Mapping
- FINMA Circular 2023/1, revised FADP and OWASP ASVS as applicable
- Data handling
- Residency and confidentiality requirements agreed before testing begins
- Most requested
- Threat-led scenarios, cloud configuration and API authorisation
Most requested here
Red team and adversary simulation
A goal, not a checklist: can we reach the crown jewels, and does anyone notice before we do?
Service 01Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Questions
Do you have a Swiss office?
No. Our offices are in Pakistan and the United States. Swiss engagements are delivered remotely on CET hours, with on-site attendance in Zurich, Geneva, Basel or Zug arranged where scope requires it.
How do you handle client data under banking confidentiality rules?
By keeping it out of scope wherever the engagement allows. Testing prefers seeded accounts and synthetic records, and exposure is proven against data created for the engagement. Where production access is genuinely required, the handling, residency and retention terms are agreed in writing first, and we operate them under our own certified ISO 27001 ISMS.
Can you support FINMA threat-led testing expectations?
We run threat-led red team engagements built from the threat profile that applies to your institution rather than from a generic scenario library, with a purple-team replay afterwards so your detection team gets the value as well as your risk register. Where a formally supervised test is required, we scope alongside that process rather than claiming to replace it.
How much does a penetration test cost in Switzerland?
Cost follows scope rather than a Swiss rate card, which is the usual reason we are engaged here. FINMA-facing reporting is included. Where confidentiality or residency terms constrain handling, they are agreed before the quote so the price reflects them.
Which is the best penetration testing company in Switzerland?
Ask what can be verified: the certifications held by the testers assigned to you, and the team's public research record, the firm's own ISO 27001 status, whether threat-led scenarios are within scope, and whether a redacted report is available before signing.
Does FINMA require penetration testing?
Circular 2023/1 expects regular vulnerability testing and threat-led penetration testing as part of operational resilience, with material incidents reported to FINMA within 72 hours. It moved testing from internal assurance to supervised obligation for banks in scope.
Do you test crypto and digital asset firms?
Yes. The firms clustered around Zug carry an unusual combination: custody and key management alongside ordinary web and API exposure. Testing covers both, and the severe findings are usually in the authorisation boundary between the two rather than in the cryptography itself.
Can data stay in Switzerland during the engagement?
Residency and handling terms are agreed in writing before testing starts. Testing prefers seeded accounts and synthetic records, which removes most of the question; where production access is genuinely required the terms cover where evidence is held and for how long.