Contact Us

Contact Us

Please get in touch using the form below

I prefer to be contacted by:
View our privacy policy
Learn about the best practices for developing SIEM use cases. Join our webinar on August 4th.

Overview

Regularly test security systems and processes in line with PCI DSS requirements

Regular assessment of systems and processes is among the key controls mandated by PCI DSS to protect cardholder data.

Requirement 11 of the standard outlines the need for organisations to perform internal and external penetration testing at least annually, or after any significant changes to infrastructure.

A range of security assessment services

Testing

What is a PCI DSS penetration test?

A penetration test is a type of cyber security assessment designed to identify, exploit and help address vulnerabilities.

PCI DSS penetration testing is designed to include assessment of network infrastructure and applications from both outside and inside an organisation’s network environment.

Scope

What needs to be assessed?

PCI DSS penetration testing must be performed on an organisation’s complete cardholder data environment (CDE) and includes any systems which may impact the security of the CDE.

A PCI pen test will help to identify:

  • Unsafe system and network configurations
  • Improper access controls
  • Rogue wireless networks
  • Coding vulnerabilities like XSS and SQL injection
  • Broken authentication and session management
  • Encryption flaws

Why Redscan?

Why choose Redscan for PCI DSS penetration testing?

Redscan is a CREST-accredited and award-winning provider of penetration testing services. Our ethical hacking engagements, including network penetration testing and web application testing, help organisations to achieve PCI DSS pen test standards by identifying weaknesses that could enable card payment details to be compromised by criminal attackers.

A Redscan employee shakes hands with a partner

Meet some of our team

“When choosing a pen test provider, you need to be confident they will deliver what they promise. At Redscan, as a CREST-accredited company, we always maintain the highest technical, legal and ethical standards. Transparency and integrity are key to everything we do.”
Jed
Head of pentesting
“Our remit is to think creatively to find solutions that will help keep your organisation more secure. We’re continually improving our knowledge of how adversaries think so that we can better identify security weaknesses and enhance detection of new and emerging threats.”
Faisal
Security Consultant
“We’re focused on delivering the best pen testing security outcomes for our clients. That’s why we’ll work with your organisation every step of the way – from initial scoping of requirements through to remediating vulnerabilities. Communication is a vital part of our approach and we’ll work hard to help you achieve the results you need.”
Nima
Security Consultant
“We aim to make sure that your organisation gets the best possible value from a pen test. We'll talk you through the assessment at every stage and answer any questions you might have along the way.”  

 

Philip
Security Consultant

More

More about PCI DSS compliance

For more information about PCI DSS compliance:

Get a quick quote

Complete the form for a prompt response from our team.

I prefer to be contacted by:
View our privacy policy

Resources

Discover our latest content and resources

From the blog
From the blog Case studies Latest news
26th July 2021
Survey reveals 86% of UK businesses expect cyber-attacks to increase in next 12 months
A new survey has revealed that 86% of UK companies anticipate an increase in cyber-attacks over the next 12 months with phishing attacks seen as the biggest threat.  
20th July 2021
IoT malware attacks rose 700% during the pandemic
A new study has revealed that IoT malware attacks increased by 700% during the pandemic. The research analysed IoT devices left on corporate networks when businesses changed to remote working.
12th July 2021
Cybercrime costing organisations around £1.29 million a minute
A new analysis of the volume of malicious activity on the internet has revealed that cybercrime costs organisations around $1.79m (£1.29m) every minute.
23rd June 2021
Disjointed and under resourced: cyber security across UK councils
Our UK council FOI report reveals a disjointed approach to cyber security across the sector, with councils reporting hundreds of data breaches annually and many failing to provide adequate security training for staff. Read our report here.