// penetration testing & cybersecurity — cyprus

We break in.
Before they do.

CyprusPentest is a Limassol-based offensive security team. We test the way real attackers work — across web, API, cloud, network and AI systems — so Cyprus businesses find and fix critical weaknesses before they become a breach or a GDPR fine.

// 01

services

Every engagement is hands-on and exploit-driven: real attacks, reproducible proof and fixes your team can action — delivered by testers based in Cyprus, not an outsourced scan.

Application Security./all →
SVC_01

Web Application Penetration Testing

Web application penetration testing in Cyprus. Manual, exploit-led testing for Limassol & island-wide businesses — OWASP-aligned, GDPR &…

  • Broken access control & IDOR
  • SQL, NoSQL & command injection
  • Authentication & session management flaws
./open →
SVC_02

API Penetration Testing

API penetration testing in Cyprus for REST & GraphQL. OWASP API Top 10, BOLA/BFLA and token testing for…

  • Broken object-level authorization (BOLA)
  • Broken function-level authorization (BFLA)
  • Mass assignment & excessive data exposure
./open →
SVC_03

Mobile Application Penetration Testing

Mobile app penetration testing in Cyprus (iOS & Android). Static + dynamic analysis and backend API testing for…

  • Hardcoded secrets, keys & token extraction
  • Insecure local & keychain storage
  • Certificate-pinning & root/jailbreak bypass
./open →
SVC_04

GraphQL Security Testing

GraphQL security testing in Cyprus — introspection, resolver authorization and query-depth abuse for Limassol SaaS & fintech APIs.

  • Introspection & schema disclosure
  • Per-resolver authorization (IDOR) gaps
  • Alias/batching rate-limit bypass
./open →
SVC_05

Secure Code Review

Secure code review in Cyprus. Manual source audit plus SAST for Limassol software teams — find vulnerabilities at…

  • Taint & data-flow analysis
  • Injection and unsafe deserialization
  • Authentication & authorization logic flaws
./open →
Network & Infrastructure./all →
SVC_06

External Network Penetration Testing

External network penetration testing in Cyprus. We test your internet-facing perimeter for Limassol & island-wide businesses — validated,…

  • Attack-surface & service enumeration
  • Exposed admin panels & default credentials
  • Exploitable service vulnerabilities
./open →
SVC_07

Internal Network Penetration Testing

Internal network penetration testing in Cyprus. Assumed-breach testing of lateral movement & segmentation for Limassol offices and data…

  • Lateral movement & privilege escalation
  • Credential harvesting & reuse attacks
  • Network segmentation validation
./open →
SVC_08

Wireless Network Penetration Testing

Wireless (Wi-Fi) penetration testing in Cyprus. On-site WPA2/WPA3, rogue-AP and segmentation testing for Limassol offices, hotels and retail.

  • WPA2/WPA3 authentication attacks
  • Rogue AP & evil-twin susceptibility
  • Client isolation & de-authentication
./open →
SVC_09

Firewall & Configuration Review

Firewall and configuration review in Cyprus. CIS-benchmark rule-base audit and hardening for Limassol businesses — shrink your attack…

  • Firewall rule-base & any-any audit
  • Network segmentation & zoning review
  • CIS benchmark configuration gaps
./open →
SVC_10

IoT Device Penetration Testing

IoT & embedded device penetration testing in Cyprus. Firmware, hardware and cloud testing for Cyprus product makers and…

  • Firmware extraction & analysis
  • Hardware interfaces (UART/JTAG/SPI)
  • Wireless protocol attacks (BLE/Zigbee)
./open →
Cloud & Container Security./all →
SVC_11

AWS Penetration Testing

AWS penetration testing in Cyprus. IAM privilege paths, S3 exposure and misconfiguration review for Limassol cloud-native businesses.

  • IAM privilege escalation paths
  • S3 and storage exposure
  • SSRF-to-instance-metadata (IMDS) abuse
./open →
SVC_12

Azure Penetration Testing

Azure & Entra ID penetration testing in Cyprus. Identity attack-path and misconfiguration review for Microsoft-based Limassol firms.

  • Entra ID role & consent abuse
  • Managed identity & service principal attacks
  • Subscription privilege escalation
./open →
SVC_13

GCP Penetration Testing

GCP penetration testing in Cyprus. Service-account abuse and IAM privilege-escalation review for Cyprus businesses on Google Cloud.

  • Service account impersonation & key abuse
  • IAM privilege escalation paths
  • Cloud Storage bucket exposure
./open →
SVC_14

Kubernetes Penetration Testing

Kubernetes penetration testing in Cyprus. Container escape, RBAC and cluster-takeover testing for cloud-native Limassol businesses.

  • Container escape & privileged pods
  • RBAC & service-account misconfiguration
  • Exposed API server, etcd & kubelet
./open →
SVC_15

Cloud Configuration Review

Cloud configuration review in Cyprus across AWS, Azure & GCP. CIS-benchmark posture audit and remediation roadmap for Cyprus…

  • CIS benchmark configuration gaps
  • IAM hygiene & over-privileged access
  • Public exposure of storage & services
./open →
SVC_16

Container Security Assessment

Container & Docker security assessment in Cyprus. Image, registry and supply-chain review for Cyprus DevOps and product teams.

  • Image layer & dependency analysis
  • Secrets in build args & layers
  • Registry exposure & access control
./open →
Red Team & Adversary Simulation./all →
SVC_17

Red Team Operations

Red team operations in Cyprus. Stealthy, objective-driven attack simulation testing detection & response for mature Limassol organisations.

  • Objective-based full kill-chain attack
  • Initial access via phishing & exposure
  • Command-and-control & evasion
./open →
SVC_18

Social Engineering Assessment

Social engineering assessment in Cyprus. Authorised phishing, vishing and pretext testing of your people for Limassol businesses.

  • Targeted spear-phishing campaigns
  • Vishing (voice) pretext calls
  • Payload delivery & credential capture
./open →
SVC_19

Phishing Simulation

Phishing simulation in Cyprus. Realistic, authorised email campaigns measuring click and reporting rates for Limassol businesses.

  • Tailored phishing lure design
  • Click and credential-entry tracking
  • Reporting-rate measurement
./open →
SVC_20

Physical Penetration Testing

Physical penetration testing in Cyprus. Tailgating, badge cloning and on-site access testing for Limassol offices and facilities.

  • Tailgating & social entry
  • RFID/badge cloning & bypass
  • Lock picking & door bypass
./open →
SVC_21

Assumed Breach Assessment

Assumed breach assessment in Cyprus. Start from a compromised foothold to measure blast radius and detection for Limassol…

  • Post-compromise lateral movement
  • Privilege escalation to critical systems
  • Credential harvesting & reuse
./open →
Identity & Access./all →
SVC_22

Active Directory Penetration Testing

Active Directory penetration testing in Cyprus. Kerberos, delegation and path-to-domain-admin testing for Limassol enterprises.

  • Kerberoasting & AS-REP roasting
  • Unconstrained & constrained delegation abuse
  • ACL and object-permission escalation
./open →
SVC_23

Entra ID (Azure AD) Security Assessment

Entra ID / Azure AD security assessment in Cyprus. Role, consent and conditional-access review for Microsoft-based Limassol firms.

  • Directory role & PIM configuration
  • OAuth app consent & permission abuse
  • Conditional access policy gaps
./open →
SVC_24

OAuth, OIDC & SAML SSO Security Testing

SSO security testing in Cyprus for OAuth, OIDC & SAML. Redirect, token and assertion testing to prevent account…

  • redirect_uri & state parameter abuse
  • Authorization code & PKCE flaws
  • JWT/id_token validation weaknesses
./open →
AI & LLM Agent Security./all →
SVC_25

AI Agent Penetration Testing

AI agent penetration testing in Cyprus. Tool-abuse, goal-hijack and sandbox-escape testing for Cyprus companies deploying autonomous AI.

  • Tool-use & function-calling abuse
  • Goal hijacking & instruction override
  • Privilege escalation through agent tools
./open →
SVC_26

Prompt Injection Testing

Prompt injection testing in Cyprus. Direct and indirect injection testing across every untrusted input for Cyprus AI products.

  • Direct prompt injection
  • Indirect injection via RAG & documents
  • Tool-output & web-content injection
./open →
SVC_27

LLM Jailbreak & Guardrail Testing

LLM jailbreak and guardrail testing in Cyprus. Systematic safety-control and content-filter bypass testing for Cyprus AI products.

  • Guardrail & content-filter bypass
  • Policy evasion techniques
  • Harmful-output elicitation
./open →
SVC_28

RAG Pipeline Security Assessment

RAG security assessment in Cyprus. Vector-store poisoning, leakage and access-control testing for Cyprus AI knowledge-base products.

  • Vector-store & document poisoning
  • Retrieval-based prompt injection
  • Cross-tenant context leakage
./open →
SVC_29

MCP Server & Tool-Chain Security Testing

MCP server security testing in Cyprus. Tool-schema, confused-deputy and credential-scope testing for Cyprus AI tool-chains.

  • MCP server & tool abuse
  • Tool schema tampering & poisoning
  • Confused-deputy & privilege paths
./open →
SVC_30

AI Supply Chain Security Audit

AI supply chain security audit in Cyprus. Model provenance, plugin and dataset-integrity review for Cyprus AI and ML…

  • Model provenance & integrity
  • Plugin & extension risk review
  • Dataset integrity & poisoning exposure
./open →
SVC_31

LLM Application Penetration Testing

LLM application penetration testing in Cyprus. Full-stack testing of AI apps against the OWASP LLM Top 10 for…

  • Prompt injection & output handling
  • Insecure plugin & tool integration
  • Sensitive information disclosure
./open →
SVC_32

Agentic AI Threat Modeling

Agentic AI threat modeling in Cyprus. Design-phase security analysis of autonomous AI workflows for Cyprus product teams.

  • Agent workflow & data-flow mapping
  • Trust boundary identification
  • Abuse-case & threat enumeration
./open →
// 02

engagement flow

One clear methodology, from first recon to a free retest — aligned with OWASP, PTES and the standards Cyprus auditors expect.

01

Scope & Recon

Agree objectives and rules of engagement, then map your full attack surface across in-scope assets.

02

Exploit

Hands-on, chained exploitation that proves genuine business impact — never a list of theoretical findings.

03

Report

Clear reporting with reproducible proof, honest severity ratings and prioritised fixes for your developers.

04

Retest

A complimentary retest confirms every fix genuinely closes the attack path.

// 03

built for cyprus

From CySEC-regulated brokers and fintech in Limassol to shipping, iGaming and SaaS companies — we understand the compliance drivers and threats Cyprus businesses face.

// compliance

gdpr_and_nis2

Regulators and clients increasingly demand evidence of security testing. Our reports support GDPR, the EU NIS2 Directive and ISO 27001 assessments, with a formal attestation letter.

// local

on_the_ground

We are based in Cyprus and work in your timezone. Fixed-price scoping, fast turnaround and a named point of contact throughout — not an offshore ticket queue.

./request_engagement

Ready to see your systems the way an attacker does? Scope a penetration test of your web app, infrastructure or cloud with a Cyprus-based team today.

Get in touch