Sales: (651) 415-2266 Service: (651) 482-8718

Penetration testing

Penetration testing that finds what actually gets you breached.

Automated scans flag theoretical issues. A penetration test proves what an attacker could really do with them — chaining weaknesses together to reach your data, your systems, and your money. Gryphon runs focused, manual-led penetration tests for Minneapolis and Twin Cities organizations, then hands you a clear plan to fix what matters.

Why it matters

A scan tells you what might be wrong. A test proves what an attacker can do about it.

Most organizations already run vulnerability scans, and scans are useful — but they produce long lists of "potential" issues with no sense of which ones actually put the business at risk. A penetration test answers the question leadership actually cares about: if someone tried to break in today, would they get to anything that matters?

Our testers work the way real attackers do. They don't stop at a flagged vulnerability; they exploit it, escalate, and pivot — turning a minor misconfiguration and a reused password into a path to your file server or your finance system. Then they show you exactly how they did it, so the fix is obvious and the priority is clear.

What it covers

Testing scoped to how you actually operate.

We size each engagement to your environment and your reason for testing — not a one-size package. Common scopes include:

01

External network testing

We attack your internet-facing systems the way a remote adversary would — exposed services, VPNs, email and web infrastructure, and anything else reachable from outside your walls.

02

Internal network testing

From an assumed-breach foothold, we test how far an attacker moves once inside: privilege escalation, lateral movement, credential theft, and the path to your most sensitive data.

03

Web application testing

Hands-on testing of your applications and portals for authentication flaws, access-control gaps, injection, and business-logic issues that scanners miss.

04

Wireless testing

Assessment of your wireless networks and segmentation — rogue access points, weak authentication, and guest-to-corporate crossover.

05

Social engineering

Controlled phishing and pretext testing to measure how your people and your defenses respond to the tactics that cause most real breaches.

06

Cloud & Microsoft 365 review

Configuration and identity review of your cloud and Microsoft 365 tenant — the misconfigurations and over-permissioned accounts attackers now target first.

How it works

A clear engagement, from scoping to retest.

No surprises, no black box. You know what we are testing, when, and what to do with the results.

01

Scope & rules of engagement

We define targets, timing, off-limits systems, and a direct line of communication before any testing begins.

02

Reconnaissance & discovery

We map your real attack surface — the systems, services, and accounts an attacker would find and target.

03

Exploitation & escalation

We safely validate findings, chain weaknesses together, and show how far an attacker could actually get.

04

Reporting & readout

You get an executive summary plus a technical report with severity, evidence, and reproduction steps — then a live walkthrough with your team.

05

Remediation support & retest

We help prioritize and fix what matters, then retest to confirm the gaps are closed.

What you get

A report you can act on — not a PDF that sits in a drawer.

Every engagement is built to drive decisions and fixes, with proof behind every finding.

  • An executive summary your leadership can act on
  • A technical report rating each finding by severity, with evidence and reproduction steps
  • Prioritized, practical remediation guidance
  • A live readout and Q&A with your team
  • An optional retest to confirm the fixes closed the gaps

Common reasons to test

Whether you have to test or you want to know, the goal is the same.

Many Minnesota organizations come to us because a requirement forces the question — CMMC and NIST SP 800-171, a SOC 2 or PCI audit, a HIPAA obligation, a cyber-insurance application, or a customer's vendor-security review. Others simply want an honest, outside answer before an attacker provides one. Either way, a penetration test turns "we think we're secure" into evidence — and a plan.

Because Gryphon also delivers cybersecurity services, managed IT, and vCISO guidance, we don't stop at the report. We can help you close the findings and keep them closed.

FAQ

Penetration testing questions, answered.

How is a penetration test different from a vulnerability scan?

A vulnerability scan is automated and produces a list of potential issues. A penetration test is led by a person who validates those issues, chains them together, and demonstrates what an attacker could actually reach — so you spend remediation effort on real, exploitable risk instead of theoretical noise.

How long does a penetration test take?

Most small and mid-sized engagements run one to two weeks from kickoff to readout, depending on scope — the number of external hosts, internal network size, and how many web applications are in play. Scoping is quick; we size the effort to your environment before you commit.

Will testing disrupt our operations?

Testing is planned around your business. We agree rules of engagement up front — targets, timing, off-limits systems, and a communication path — and we stop and call you immediately if we find anything that puts production or safety at risk.

How often should we test?

Annually is the common baseline, and many compliance frameworks and cyber-insurance policies expect it. You should also test after a major change: a new application, a network redesign, a merger or acquisition, or a move to the cloud.

What do we get at the end?

An executive summary your leadership can act on, a technical report with each finding rated by severity and backed by evidence and reproduction steps, prioritized remediation guidance, and a live readout with your team. We can also retest to confirm the fixes actually closed the gaps.

Do you help fix what you find?

Yes. Because Gryphon also delivers managed IT, cybersecurity, and vCISO services, we can help remediate findings — not just hand you a report and walk away. If you have an internal team, we work alongside them.

Next step

Make your next technology decision with better information.

Talk with an advisor about your current environment, risk, support model, and business priorities.

Start a conversation