Skip to main content
PTS Managed Services
Penetration Testing and Vulnerability Assessment in Hong Kong — PTS Managed Services

Penetration Testing and Vulnerability Assessment in Hong Kong

External penetration tests and vulnerability assessments for Hong Kong businesses: scoped and managed by PTS, carried out by accredited independent testing partners, with our engineers fixing what the test finds.

ISO 27001 · ISO 20000 certified Since 2001 20+ engineers HK · Singapore · Shanghai English · 廣東話 · 普通话

A penetration test is an authorised, simulated attack on your systems that shows which weaknesses a real attacker could exploit. PTS arranges external penetration tests and vulnerability assessments for Hong Kong businesses: we scope the test with you, an accredited independent testing partner carries it out, and our engineers fix what it finds and confirm the fixes with a retest. PTS is certified to ISO/IEC 27001 and ISO/IEC 20000 and has worked in Hong Kong since 2001.

Why the tester is independent. The people who run your security should not be the only people who test it. Keeping the testing with an accredited independent partner gives you an objective result that clients, auditors and insurers take seriously, while PTS takes care of everything around the test: the scope, the rules of engagement, the scheduling, reading the findings with you in plain English, and doing the remediation. You deal with one accountable partner, and the test itself stays independent.

This page is part of our managed security services. If you want to see where you stand before commissioning a test, the free Security Controls Audit takes about ten minutes and the Email Security Checker checks your domain’s SPF, DKIM and DMARC records in seconds.

What is penetration testing?

Penetration testing (a pen test) is a controlled attempt, with your written permission, to break into your systems the way an attacker would. A tester starts from what is visible on the internet (your websites, email and remote-access services, firewalls and cloud services), finds weaknesses, and then tries to exploit them to prove what an attacker could actually reach. The result is evidence rather than a list of possibilities: which doors are open, how far through them someone could get, and what to fix first.

A vulnerability assessment is the lighter, broader exercise that usually comes first: automated scanning of your internet-facing systems for known weaknesses such as missing patches, outdated software, exposed services and weak configurations, with the results checked and ranked by risk. It finds more issues than a pen test, faster, but it does not prove whether they can be exploited.

Penetration test, vulnerability assessment or security audit: which do you need?

The three are often confused, and buying the wrong one wastes money. Most Hong Kong SMEs benefit from all three over time, in this order: an audit to fix the basics, an assessment to find the known weaknesses, then a penetration test to prove what is left.

Security auditVulnerability assessmentPenetration test
What it answersAre the right controls in place across users, devices, policies and configuration?Which known weaknesses do our internet-facing systems have?What could an attacker actually break into, and how far could they get?
How it worksStructured review against practical security benchmarksAutomated scanning, checked and risk-rankedManual testing by a qualified tester, building on the scan
What you getPrioritised findings and a remediation planA ranked list of vulnerabilities and fixesProof of exploitable weaknesses, an executive summary and a technical report
Best usedFirst, to fix the basicsRegularly, and after significant changesOnce the basics are fixed, and when clients, auditors or insurers ask for it

What an external penetration test covers

The standard engagement tests what an attacker on the internet can see and reach. Typical scope for a Hong Kong business includes:

  • Websites and web portals that you host or that hold your data.
  • Email and remote access: webmail, VPN gateways and remote desktop services exposed to the internet.
  • Firewalls and network edge: open ports, exposed management interfaces and misconfigured rules.
  • Cloud services: internet-facing services in Microsoft 365 and Azure, and any other cloud platforms you run.
  • Exposed services and forgotten systems: the test server or old application nobody remembers is still online.

If your auditors, clients or insurer ask for internal network or application testing as well, we scope that with you at the start and tell you plainly whether it is needed. For Microsoft 365 specifically, a Microsoft 365 security review is usually the better first step: it checks the tenant’s configuration directly rather than attacking it from outside.

How often should you test?

Once a year is a common baseline, together with a retest after any significant change: a new website or portal, a firewall replacement, a cloud migration or an office move that changes your network. Regulated firms and many cyber insurers expect testing on a regular cycle; our guide to SFC cybersecurity requirements for Hong Kong fund managers explains what the SFC’s circulars say, and the Security Controls Audit shows where testing sits among the other controls.

The right frequency depends on how much you have exposed to the internet and how often it changes. We will recommend a cycle at scoping, not sell you more tests than your risk justifies.

Been asked for a penetration test?

Tell us who is asking and what you run. We will reply within two business days with the scope we recommend.

Scope a test →

How a PTS-managed penetration test works

1. Scoping

A short call to agree what is in scope (domains, IP addresses, applications), what is out of scope, the testing window and who needs to know. If a client, auditor or insurer asked for the test, we check their requirements so the report answers their question the first time.

2. Authorisation

You sign a written authorisation and rules of engagement before any testing starts. Testing without it is an attack, not a test.

3. Testing

Our accredited testing partner carries out the vulnerability assessment and penetration test within the agreed window. PTS coordinates with your team and any hosting or cloud providers, and keeps you informed if the tester finds anything that needs immediate attention.

4. Report

You receive an executive summary for management and a technical report for whoever will fix the issues, with every finding rated by risk. We go through it with you in plain English, in English, Cantonese or Mandarin.

5. Remediation

Our engineers fix the findings, or hand a clear plan to your own IT team, or split the work. For managed IT clients, remediation runs through the same engineers who already look after your systems.

6. Retest

Once the fixes are in, the tester checks them again, so you can show clients, auditors and insurers that the issues found are closed, not just reported.

What you receive

  • An executive summary that explains the overall risk and the priorities in business terms.
  • A technical report with each finding, how it was found, its risk rating and how to fix it.
  • A prioritised remediation plan with owners and timelines.
  • A retest letter confirming which findings are fixed, for your clients, auditors or insurer.

Fixing what the test finds

A penetration test report on its own changes nothing. The value is in closing the gaps, and that is where most testing-only firms step back and most businesses stall: the report goes into a folder, and next year’s test finds the same issues.

Because PTS runs IT and security for businesses every day, fixing is part of the engagement: patching and upgrading exposed systems, tightening firewall rules, removing forgotten services, hardening remote access and email, and enforcing multi-factor authentication. If the test shows a wider problem, the natural next step is ongoing managed security, so the same doors do not reopen.

How penetration testing is priced

We do not publish prices, because no two scopes are the same. Penetration testing is a fixed-fee piece of work agreed after scoping, and the proposal sets out exactly what is tested, what you receive and what the retest covers.

What moves the price:

  • The size of the target: how many internet-facing IP addresses, domains and services are in scope.
  • Applications: web applications and portals take more testing time than a network edge.
  • Depth: a vulnerability assessment alone, or a full penetration test built on it.
  • Remediation: whether our engineers make the fixes, or your team does.
  • Retesting: how many rounds of verification you need.

Request a proposal and we will recommend the scope your risk actually needs.

Penetration testing FAQs

What is a penetration test?

A penetration test is an authorised, simulated attack on your systems that finds weaknesses and proves which of them an attacker could actually exploit. You get evidence of what is exploitable, a report with risk ratings, and a plan to fix it.

Who carries out the testing?

Accredited independent testing partners carry out the tests, managed by PTS. We scope the test with you, manage the tester, go through the findings with you and fix what the test finds. Keeping the tester independent of the team that runs your security gives you an objective result.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan (or assessment) automatically checks your systems for known weaknesses and ranks them by risk. A penetration test goes further: a qualified tester tries to exploit the weaknesses to prove what an attacker could reach. Scans are broader and faster; penetration tests are deeper and prove impact.

How often should we run a penetration test?

Once a year is a common baseline, with a retest after significant changes such as a new website, a firewall replacement or a cloud migration. Regulated firms and some cyber insurers expect a regular cycle. We recommend a frequency at scoping based on how much you expose to the internet and how often it changes.

Will testing disrupt our systems?

Testing is planned to avoid disruption: the scope, the timing and the rules of engagement are agreed in writing before it starts, and anything that could affect live services is discussed first. If the tester finds something serious during the test, we tell you straight away rather than waiting for the report.

Do you fix the vulnerabilities the test finds?

Yes. PTS engineers can carry out the remediation, hand a clear plan to your own team, or split the work, and the tester then retests to confirm each fix. That is the main difference between PTS and a testing-only firm.

Do SFC-licensed firms need penetration testing?

The SFC expects licensed corporations to test and review their cybersecurity controls, and many firms use regular penetration testing as part of meeting that expectation. Our SFC cybersecurity guide sets out what the circulars say; take compliance advice on your firm’s specific obligations.

Can you test our Microsoft 365 tenant?

The internet-facing parts of Microsoft 365 can be in scope, but most Microsoft 365 risk sits in configuration: sign-in policies, admin roles, sharing settings and email protection. A Microsoft 365 security review checks those directly and is usually the better first step.

Do you offer penetration testing in Chinese?

Yes. We can run the scoping, the read-out of the findings and the remediation in English, Cantonese or Mandarin. See our 網絡安全服務 page in Traditional Chinese.

Get a costed proposal

Answer a few quick questions below.

ISO 27001 · ISO 20000 certified  ·  In Hong Kong since 2001  ·  Critical issues acknowledged within 30 minutes  ·  See an award-winning rollout →

Tell us a bit about your setup and we'll reply within two business days with a practical, costed proposal, or with a few questions first if we need to see more. No obligation, no sales pitch.

1 How many staff?*
2 What are you looking for?*Select all that apply
3 Where do your servers live?
4 Where are your offices?Select all that apply
5 On-site or remote support?
6 Do you have an IT provider now?
7 Do you have in-house IT?

Practical, costed proposal · No obligation · Runs to your inbox, not a database

Call Request a proposal