Penetration testing in Switzerland: Syslifters as pentest provider
Syslifters GmbH is a boutique Austrian pentest provider with a clear focus on Microsoft-heavy enterprise environments, the Microsoft cloud, and web security. We run pentest projects in Austria and internationally. We place the highest value on quality and a partnership-oriented collaboration with our clients. Our assessments are hands-on and manual. They are conducted by experienced experts and are not based on automated scans alone.
Why Syslifters
Four qualities that define us:
- With a clear focus on internal infrastructures, the Microsoft cloud, and web security, we work efficiently where expertise delivers the most value for you.
- Deep know-how combines study and IT security certifications with years of pentest practice, European security community exchange, ECSC successes, and international exercises such as NATO Locked Shields.
- A strong team with experience across industry, banking and finance, the public sector, universities, healthcare, retail, and more.
- Sustainable cooperation means handshake quality, close exchange, and personal contact. We aim to improve security in your organization over the long term.
Services
We provide penetration tests for internal infrastructures and Microsoft-heavy enterprise environments (e.g., Active Directory, Entra ID & Azure) as well as web security. See the linked service areas for details.
Our approach
Pentest efficiency mainly depends on two factors: time and knowledge. We choose a reasonable timeframe for the scope and build a knowledge advantage through collaboration (e.g., credentials, documentation, business impact).
Our goal is a predictable, transparent pentest with ongoing alignment and a written report that truly supports remediation.
- With the timebox principle, more tester time usually finds more issues, though returns diminish over time. If an attacker has significantly more time than the test allows, they may find gaps we do not see in a limited window.
- Knowledge creates a time advantage: documentation, access, business context, and source code help us test more efficiently and assess findings faster.
- We typically recommend tests between grey-box and white-box. Pure cloud environments are often most efficient as white-box. Large external perimeters with many heterogeneous systems may suit a black-box approach.
- Experienced pentesters run our tests hands-on and manually, expert-led rather than as automation or scan-only.
- Together we define clear goals, transparent scope boundaries, and a focused test plan during scoping.
- We stay in close contact during the test and report critical findings promptly through agreed channels.
- Reports are structured for clarity, prioritize actions, include reproducible steps, and offer practical remediation guidance.
- We retest remediated issues once at no charge if fixes are completed within eight weeks of report delivery.
How we work
In six steps we guide you from the first conversation through retest and beyond.
- We gather your requirements: In a scoping call we define the scope and framework of the pentest together. We agree on what is in scope and what is explicitly excluded.
- We prepare your offer: Based on your requirements we prepare a tailored offer. You receive it promptly, with a clear breakdown.
- We clarify all prerequisites: After you engage us, we prepare the pentest in a kickoff. We align on access, test accounts, time windows, and communication channels.
- We deliver the best pentest for you: We test within the agreed scope and timeframe. During the engagement we stay in contact and report critical findings through the agreed channels. When testing is complete, you receive the report as a secured PDF.
- We discuss the results: Pentest reports are often extensive. After delivery we remain your point of contact and are happy to walk through the results and priorities with you.
- We retest for free: So you can act on the report, we retest remediated vulnerabilities once at no charge if fixes are completed within eight weeks of report delivery.
Sample reports
Our public sample reports show how we document findings, assess risks, and formulate recommendations. You can see structure, depth, and quality of our reporting.
Pricing and typical ranges
If an attacker has more time than the pentester in the test, they may find issues that do not surface in a limited time window. That is why we bill pentests by effort in person-days: scope stays transparent, and you can choose tester time to match the scope.
- Day rate: € 1,600 per person-day.
- From 20 person-days: 15% discount (then € 1,360 per person-day).
- Typical ranges: Web application € 5,000 to 16,000, Microsoft Active Directory € 12,000 to 20,000, External infrastructure € 8,000 to 11,000.
- We estimate exact effort in a scoping call beforehand.
- Academia day rate: € 1,200. We also offer a pro bono programme.
- More details are in our handbook under Pricing and typical ranges.
Our products
Two internationally recognized products grew out of our daily pentest work, which we run as separate services:
Our public handbook
Transparency matters to us. For more detail on us, our services, and how we work, we maintain an extensive public Handbook. It is our central resource for services, delivery, organization, and technical knowledge. There you will find who we are, what we offer, how we deliver, and information on our organization and internal processes. We encourage our employees to use it actively in daily work. It also includes a deep technical pentesting manual and resources for clients and other pentesters.
For a broader market overview we maintain curated provider lists for Austria, Germany, and Switzerland.
Ready to work with us ?
We go on the offensive for you and uncover vulnerabilities in your applications and infrastructure so attacks never get a chance.