Managed Vulnerability: Vonahi (Penetration Testing)

What’s Included

Managed Solution shall conduct regular network penetration tests using the Vonahi vPenTest platform to proactively identify and remediate security vulnerabilities across Client’s designated systems and networks. Subject to Client’s selected subscription, managed penetration testing services may include structured reconnaissance, exploitation testing, vulnerability analysis, and detailed reporting to assess Client’s security posture and resilience against real-world attack scenarios. Prior to each test, the Parties shall mutually agree upon the scope of systems and networks to be tested, permitted testing methods, testing duration and schedule, and any other parameters or restrictions necessary to ensure a controlled, safe, and duly authorized testing process.
Depending on the selected subscription, the penetration testing process will generally include:
  • Prior to each engagement, Managed Solution will coordinate with Client to identify in-scope targets, discuss specific concerns or objectives (e.g., compliance requirements or threat scenarios to simulate), establish communication protocols for critical findings discovered during testing, and obtain written authorization to proceed. Testing will be scheduled to minimize disruption to Client’s operations.
  • Managed Solution will perform comprehensive reconnaissance and vulnerability scanning on in-scope systems using automated tools and manual techniques to identify security weaknesses, including open ports, misconfigurations, outdated software, known security flaws, and other potential points of entry.
  • Where permitted, Managed Solution will systematically attempt to exploit identified vulnerabilities to verify their impact and demonstrate associated risks. This may include network penetration attempts, application-level testing (e.g., SQL injection, cross-site scripting), wireless network security testing, and limited social engineering or phishing simulations (if in scope). We will employ safe and controlled methods during exploitation and will immediately halt testing and notify Client if critical systems are at risk of impact.
  • Managed Solution will document all identified vulnerabilities and assess the risk level of each finding (categorized as Critical, High, Medium, or Low), taking into account ease of exploitation, potential impact on the confidentiality, integrity, and availability of Client’s systems and data, and any existing mitigating controls.
  • Upon completion of testing, Managed Solution will deliver a Penetration Test Report to Client, including an executive summary of overall security posture and key findings in non-technical terms, detailed descriptions of each finding with supporting evidence (e.g., screenshots or logs), severity ratings, recommended remediation steps or risk mitigation strategies, and a prioritized list of actions to address the highest-risk issues.
  • Following delivery of the report, Managed Solution will conduct a debrief session with Client’s relevant stakeholders to present findings, address questions, and provide clarification on recommended remediation measures. We may assist Client in developing a remediation plan or roadmap to address identified vulnerabilities, subject to the scope of the service or as otherwise agreed by the Parties. Ongoing remediation assistance beyond the scope of this service may necessitate a separate services agreement.