Cybersecurity assessments & penetration testing / Lisbon
Find the weakness first
Independent, contract-based penetration testing and security audits for businesses that would rather prevent an incident than manage one.
Legal & ethics
Rules of engagement
We are a contracted testing provider. Every engagement is authorised in writing by the organisation that owns the systems, before any testing begins.
Written authorisation first
Testing starts only after a signed statement of work naming the systems, the dates and the agreed limits. No signature, no testing.
Client-owned systems only
We test assets you own or can lawfully authorise, never third parties. Where infrastructure is hosted by someone else, we confirm their permission too.
Agreed scope, agreed limits
Targets are listed explicitly; anything else is out of scope. Denial-of-service, destructive actions and bulk data extraction are excluded unless separately agreed.
You can stop us at any time
Authorisation can be withdrawn at any point and testing halts immediately, with written confirmation of what had been performed.
Findings stay confidential
Results are yours. Nothing is published or referenced without your written agreement, and reports travel over encrypted channels only.
Work we decline
We do not access accounts or devices for third parties, test competitors, or leave access in place after an engagement ends — at any price.
Requests aimed at systems the requester does not own or control are declined. Authorised testing within a contractual scope is lawful under Portuguese and EU law; the same activity without authorisation is not.
Services
Six ways we harden your business
Penetration Testing
Manual, goal-driven testing of your apps, networks and cloud.
Vulnerability Assessment
Broad scanning and triage, ranked by real business risk.
Security Audits
Configuration, architecture and access reviewed against good practice.
Web Application Testing
Authentication, authorisation, business logic and API testing.
Employee Security Training
Awareness sessions and fair, consent-based phishing simulations.
Incident Response
Calm containment, investigation and hardening when it matters.
Method
How an engagement runs
Authorised in writing, scoped with you, run to agreed rules. No surprises.
Scope & authorise
Targets, timing and rules fixed in a signed statement of work.
Reconnaissance
We map what your organisation exposes, from the outside in.
Discovery
Manual and automated analysis surfaces the real weaknesses.
Controlled validation
We safely confirm which findings are genuinely reachable, and their impact.
Reporting
Prioritised findings, clear reproduction, concrete fixes.
Retest
We verify your fixes and confirm the issues are closed.
Why VillainStrike
Independent, evidence-led
A specialist testing company, not a reseller. We give you an honest picture of risk and a plan your engineers can act on — and we rate every finding on a clear scale.
- Manual testing by experienced assessors
- Reports for engineers and the board
- Fixed scope and pricing up front
- Free retest of remediated findings
- EU-based team and data handling
Next step
Get an honest read on your security
Tell us what to assess. We scope it with you before any testing starts.
Start here
Request a security audit
A real assessor reads every request. No chatbots, no ticket queue.