Frequent Asked Questions
FAQ
Do you have questions about your company's security?
Explore our FAQs to learn how to secure your systems and patch every vulnerability.
We already did a pen test last year. Why should i repeat it?
A penetration test provides a snapshot of a specific point in time; however, the attack surface and exposed vulnerabilities can change with every update, new integration, or code and configuration change.
The preliminary Security Posture Assessment identifies what has changed since the last evaluation and directs effort to where actual risk has increased, avoiding repeated testing on unchanged assets.
Qual è la differenza tra Vulnerability Assessment e Penetration Test? When to choose one over the other?
A Vulnerability Assessment identifies known vulnerabilities mostly through automated means, whereas a Penetration Test demonstrates if and how they can be exploited. The two activities can be combined to achieve the best balance between cost and coverage of the most critical attack surfaces.
The modular approach allows you to start with a VA to map the attack surface and scale to a PT on critical components, without paying for exploitation on low-risk assets.
How do I know if my SOC actually detects an attack?
Attack Response Testing is designed around agreed scenarios, but its execution is unannounced to the SOC. This allows efforts to focus not merely on detecting vulnerabilities, but on evaluating the effectiveness of the deployed detection and response measures.
Defensive layer independence: Secure Network does not sell SOC services. It evaluates anyone’s defenses without any conflict of interest.
We are a small-to-midsize bank: is TLPT under DORA really mandatory for us?
DORA (in force since January 2025) extends TLPT obligations to financial entities classified as ‘significant’. The threshold depends on the Supervisory Authority’s classification. Regardless of regulatory obligations, for cybersecurity-mature organizations, a TLPT or Red Teaming exercise provides an end-to-end evaluation of the organization’s overall resilience.
Secure Network can act as both a Red Team Provider and a Threat Intelligence Provider within the TIBER-IT framework, backed by direct experience in engaging with Supervisory Authorities.
Why perform a penetration test on in-house software that only we use?
Only our employees’ isn’t necessarily true: VPNs, ZTNA, remote access, and compromised workstations are frequently the initial entry points for the most severe attacks. In-house software is often the least tested, and vulnerabilities within it could lead to the compromise of corporate and personal data.
Secure Network provides end-to-end application security across all tiers, including legacy and custom applications using black, grey, or white-box approaches tailored to asset criticality.
MILAN:
Via dei Valtorta, 48
20127 Milan
Tel: +39.02.8596171
CETMA-DIHSME is the Digital Innovation Hub coordinated by CETMA and funded by the Ministry of Economic Development and the EU Commission to provide innovation services to SMEs and public administrations in Puglia and Basilicata.
Finanziato dall’Unione europea – Next Generation EU
Secure Network S.r.l. | Via dei Valtorta 48, 20127 Milano (MI) Tax code and VAT number 04205230966 - securenetwork@legalmail.it




