Cybersecurity assessments & penetration testing / Lisbon

Find the weakness first

Independent, contract-based penetration testing and security audits for businesses that would rather prevent an incident than manage one.

SeniorTesters only
6Assessment services
EUTeam & data residency
engagement — scoped & authorised
# authorised engagement — signed statement of workanalyst@villainstrike:$ engagement --status client-project[1/4] scope agreed and authorised in writing[2/4] assessment completed within the agreed window[3/4] findings documented with remediation steps[+] report delivered · free retest scheduled

Legal & ethics

Rules of engagement

We are a contracted testing provider. Every engagement is authorised in writing by the organisation that owns the systems, before any testing begins.

01

Written authorisation first

Testing starts only after a signed statement of work naming the systems, the dates and the agreed limits. No signature, no testing.

02

Client-owned systems only

We test assets you own or can lawfully authorise, never third parties. Where infrastructure is hosted by someone else, we confirm their permission too.

03

Agreed scope, agreed limits

Targets are listed explicitly; anything else is out of scope. Denial-of-service, destructive actions and bulk data extraction are excluded unless separately agreed.

04

You can stop us at any time

Authorisation can be withdrawn at any point and testing halts immediately, with written confirmation of what had been performed.

05

Findings stay confidential

Results are yours. Nothing is published or referenced without your written agreement, and reports travel over encrypted channels only.

06

Work we decline

We do not access accounts or devices for third parties, test competitors, or leave access in place after an engagement ends — at any price.

Requests aimed at systems the requester does not own or control are declined. Authorised testing within a contractual scope is lawful under Portuguese and EU law; the same activity without authorisation is not.

Services

Six ways we harden your business

01

Penetration Testing

Manual, goal-driven testing of your apps, networks and cloud.

02

Vulnerability Assessment

Broad scanning and triage, ranked by real business risk.

03

Security Audits

Configuration, architecture and access reviewed against good practice.

04

Web Application Testing

Authentication, authorisation, business logic and API testing.

05

Employee Security Training

Awareness sessions and fair, consent-based phishing simulations.

06

Incident Response

Calm containment, investigation and hardening when it matters.

Method

How an engagement runs

Authorised in writing, scoped with you, run to agreed rules. No surprises.

01

Scope & authorise

Targets, timing and rules fixed in a signed statement of work.

02

Reconnaissance

We map what your organisation exposes, from the outside in.

03

Discovery

Manual and automated analysis surfaces the real weaknesses.

04

Controlled validation

We safely confirm which findings are genuinely reachable, and their impact.

05

Reporting

Prioritised findings, clear reproduction, concrete fixes.

06

Retest

We verify your fixes and confirm the issues are closed.

Why VillainStrike

Independent, evidence-led

A specialist testing company, not a reseller. We give you an honest picture of risk and a plan your engineers can act on — and we rate every finding on a clear scale.

  • Manual testing by experienced assessors
  • Reports for engineers and the board
  • Fixed scope and pricing up front
  • Free retest of remediated findings
  • EU-based team and data handling
CriticalHighMediumLow
ModelIndependent, contract-based
BaseLisbon, Portugal
FocusSecurity testing & audits
CoveragePortugal & the EU
EngagementsPoint-in-time & ongoing

Next step

Get an honest read on your security

Tell us what to assess. We scope it with you before any testing starts.

Start here

Request a security audit

A real assessor reads every request. No chatbots, no ticket queue.

We reply within one business day. Details are used only to answer your request.