
CYBERSECURITY RESILIENCE
Vulnerability Assessment & Penetration Testing
Vulnerability Assessment (VA) and Penetration Testing (PT) is the global security methodology designed to identify, evaluate, and safely exploit vulnerabilities across IT infrastructures, networks, and applications, regardless of where they are deployed, managed, or hosted.
01 - ABSTRACT
Vulnerability Assessment (VA) and Penetration Testing (PT) is the global security methodology designed to identify, evaluate, and safely exploit vulnerabilities across IT infrastructures, networks, and applications, regardless of where they are deployed, managed, or hosted. The threat landscape continues to escalate rapidly: ransomware is involved in 44% of breaches, over 30% of incidents originate from third-party supply chains, and it takes organizations an average of 241 days to identify and contain an attack. According to the IBM Cost of a Data Breach study, considered the prime global cybersecurity benchmark, the average cost of a data breach has reached 4.24M CHF, making proactive defense a financial necessity. To ensure strict alignment with today's stringent regulatory landscape, our methodology does not operate in a vacuum; it is deeply rooted in Risk Assessment and Business Impact Analysis (BIA). This business-centric approach ensures that our testing directly addresses your specific threat profile, mapping technical vulnerabilities to operational risks to achieve full compliance with major international frameworks, where in most cases regular VA & PT exercises are now legally mandated. Our service model comprises comprehensive assessments across three key focus areas: network and perimeter security, web applications, and API & cloud security testing. Furthermore, to guarantee the highest standards of confidentiality, data sovereignty, and privacy, all our operations, reporting, and client data are securely hosted and maintained within Switzerland.

02 - APPLICABILITY & ASSESSMENT FREQUENCY
Enterprises, Infrastructures & Networks
| REGULATION OR SECTOR | INVOLVED ENTITIES & SCOPE | VA & PT REQUIREMENTS & VALIDATION | CRITICAL ASSETS & FOCUS |
|---|---|---|---|
| PCI-DSS | All involved entities, i.e. those that store, process, or transmit payment card data (Merchants, Service Providers) | Internal and external Penetration Testing at least annually or after significant changes. Quarterly external Vulnerability Scans via an ASV (Approved Scanning Vendor) | Cardholder Data Environment (CDE), systems connected to the CDE, network segmentation |
| DORA (Digital Operational Resilience Act) | EU financial entities (Banks, Insurance) and critical third-party ICT service providers | Regular Vulnerability Assessments. For significant entities: Intelligence-based TLPT (Threat-Led Penetration Testing) mandatory every 3 years, including third-party testing | ICT systems supporting Critical or Important Functions (CBF), operational resilience, ICT supply chain |
| FINMA, SNB, and ECB | Systemic banks, financial market infrastructures, Swiss and European insurance companies | Periodic execution of Red Teaming (TLPT) based on real threat scenarios. Continuous security posture assessments and cyber stress tests | Core banking, interbank payment systems, account holder data protection, business continuity |
| SWIFT | Financial institutions and banks connected to the SWIFT interbank network | Independent annual assessment. Periodic penetration testing on SWIFT infrastructure perimeters and continuous Vulnerability Scanning of secure zones | SWIFT Secure Zone, Jump Servers, operator PCs, messaging interfaces |
| BASEL 4 | International credit institutions and banks | It is a fundamental audit measure to quantify and mitigate capital requirements linked to "IT Operational Risk" even though not technically prescribed | Risk calculation systems, financial process resilience, and fraud prevention mechanisms |
| NIS2 | "Essential" and "Important" entities (Energy, Transport, Water, Waste, Space, etc.) | Mandatory security policies and periodic effectiveness evaluation tests (VAPT) for cyber risk management. Rapid incident reporting | OT/ICS systems, SCADA, distribution networks, services critical to public safety and health |
| Cyber Resilience Act (CRA) & Software Maintenance | Developers, manufacturers (OEMs), and distributors of hardware/software ("products with digital elements") in the EU | "Secure by Design" requirements. Mandatory continuous Vulnerability Assessments throughout the lifecycle (DevSecOps), Pentesting before release, guaranteed vulnerability handling and patching for years | Software supply chain, SBOM (Software Bill of Materials), firmware, cloud interfaces of physical devices |
| Healthcare Sector | Hospitals, public/private clinics, laboratories, medical device manufacturers | Annual VAPT on clinical IT and OT networks, specific testing on connected medical devices, ransomware and data exfiltration attack simulations | Sensitive health data (PHI/EHR), continuity of care (Life-Saving Systems), IoMT (Internet of Medical Things) devices |
| Public Administration (PA) | Government bodies, ministries, municipalities, citizen service agencies | Penetration Testing for every newly exposed service, continuous Vulnerability Assessments for public exposure. Adherence to national cybersecurity requirements | Citizens' personal data, digital identities, public service delivery portals, national cloud infrastructures |
| Telco | Providers of electronic communications services and public networks | High-frequency penetration testing (quarterly/semi-annually) on core networks. Red Teaming to simulate state-sponsored attacks | 5G infrastructures, Core Networks, BGP/DNS routing systems, network data centers |
INVOLVED ENTITIES & SCOPE
All involved entities, i.e. those that store, process, or transmit payment card data (Merchants, Service Providers)
VA & PT REQUIREMENTS & VALIDATION
Internal and external Penetration Testing at least annually or after significant changes. Quarterly external Vulnerability Scans via an ASV (Approved Scanning Vendor)
CRITICAL ASSETS & FOCUS
Cardholder Data Environment (CDE), systems connected to the CDE, network segmentation
INVOLVED ENTITIES & SCOPE
EU financial entities (Banks, Insurance) and critical third-party ICT service providers
VA & PT REQUIREMENTS & VALIDATION
Regular Vulnerability Assessments. For significant entities: Intelligence-based TLPT (Threat-Led Penetration Testing) mandatory every 3 years, including third-party testing
CRITICAL ASSETS & FOCUS
ICT systems supporting Critical or Important Functions (CBF), operational resilience, ICT supply chain
INVOLVED ENTITIES & SCOPE
Systemic banks, financial market infrastructures, Swiss and European insurance companies
VA & PT REQUIREMENTS & VALIDATION
Periodic execution of Red Teaming (TLPT) based on real threat scenarios. Continuous security posture assessments and cyber stress tests
CRITICAL ASSETS & FOCUS
Core banking, interbank payment systems, account holder data protection, business continuity
INVOLVED ENTITIES & SCOPE
Financial institutions and banks connected to the SWIFT interbank network
VA & PT REQUIREMENTS & VALIDATION
Independent annual assessment. Periodic penetration testing on SWIFT infrastructure perimeters and continuous Vulnerability Scanning of secure zones
CRITICAL ASSETS & FOCUS
SWIFT Secure Zone, Jump Servers, operator PCs, messaging interfaces
INVOLVED ENTITIES & SCOPE
International credit institutions and banks
VA & PT REQUIREMENTS & VALIDATION
It is a fundamental audit measure to quantify and mitigate capital requirements linked to "IT Operational Risk" even though not technically prescribed
CRITICAL ASSETS & FOCUS
Risk calculation systems, financial process resilience, and fraud prevention mechanisms
INVOLVED ENTITIES & SCOPE
"Essential" and "Important" entities (Energy, Transport, Water, Waste, Space, etc.)
VA & PT REQUIREMENTS & VALIDATION
Mandatory security policies and periodic effectiveness evaluation tests (VAPT) for cyber risk management. Rapid incident reporting
CRITICAL ASSETS & FOCUS
OT/ICS systems, SCADA, distribution networks, services critical to public safety and health
INVOLVED ENTITIES & SCOPE
Developers, manufacturers (OEMs), and distributors of hardware/software ("products with digital elements") in the EU
VA & PT REQUIREMENTS & VALIDATION
"Secure by Design" requirements. Mandatory continuous Vulnerability Assessments throughout the lifecycle (DevSecOps), Pentesting before release, guaranteed vulnerability handling and patching for years
CRITICAL ASSETS & FOCUS
Software supply chain, SBOM (Software Bill of Materials), firmware, cloud interfaces of physical devices
INVOLVED ENTITIES & SCOPE
Hospitals, public/private clinics, laboratories, medical device manufacturers
VA & PT REQUIREMENTS & VALIDATION
Annual VAPT on clinical IT and OT networks, specific testing on connected medical devices, ransomware and data exfiltration attack simulations
CRITICAL ASSETS & FOCUS
Sensitive health data (PHI/EHR), continuity of care (Life-Saving Systems), IoMT (Internet of Medical Things) devices
INVOLVED ENTITIES & SCOPE
Government bodies, ministries, municipalities, citizen service agencies
VA & PT REQUIREMENTS & VALIDATION
Penetration Testing for every newly exposed service, continuous Vulnerability Assessments for public exposure. Adherence to national cybersecurity requirements
CRITICAL ASSETS & FOCUS
Citizens' personal data, digital identities, public service delivery portals, national cloud infrastructures
INVOLVED ENTITIES & SCOPE
Providers of electronic communications services and public networks
VA & PT REQUIREMENTS & VALIDATION
High-frequency penetration testing (quarterly/semi-annually) on core networks. Red Teaming to simulate state-sponsored attacks
CRITICAL ASSETS & FOCUS
5G infrastructures, Core Networks, BGP/DNS routing systems, network data centers

03 - THE FORFIRM SERVICE
Business Impact & Risk-First Scoping
We start with a Business Impact Analysis (BIA) and a custom Risk Assessment to map your critical assets. By understanding what matters most to your business, we narrow down the VAPT scope to focus strictly on real-world threat vectors, preventing wasted budget on irrelevant targets.
Targeted VA & PT
We execute precise, context-driven testing (automated scanning combined with deep manual ethical hacking) tailored to the identified risks. Rather than handing over a generic list of thousands of flaws, we target the vulnerabilities that actually pose a threat to your operations.
Business-Critical Remediation & Validation
We deliver a pragmatically prioritized remediation roadmap, focusing only on the fixes that are truly important and necessary. This risk-based remediation avoids wasted internal resources, guarantees maximum security ROI, and includes clean-up validation to verify your defense posture.
04 - WHY FORFIRM
Swiss-Based Delivery. FORFIRM is the first Swiss company authorized to perform, through its own Auditors, certifications in the PCIDSS domain. Offices in Lugano and Zürich.
Your data stays in Switzerland. Assessment materials and evidence handled locally, under Swiss confidentiality standards.
Proximity. Assessment activities conducted under Swiss confidentiality standards with local presence and multilingual support.
Swiss regulatory fluency. PCI DSS Certified Professionals.
Expertise across FINMA expectations, DORA and the Swiss financial ecosystem.
Consumer trust, less fraud. Certified payment security strengthens customer confidence and measurably reduces fraud exposure.

Book Your Assessment
First assessment or scoping: book your preliminary BIA session with our Team.
Book Your Assessment