The software your business runs on — client portals, line-of-business applications, the logins your team uses every day — holds a great deal of trust and a great deal of data.
Testing the business software running on your servers and devices looks for the exploitable weak points attackers go for: open ports, weak authentication and known vulnerabilities. The exact scope is agreed up front, so you only test what's useful to you.
We're expanding this into a full guide.
In the meantime, see Penetration testing & vulnerability scanning, or talk to us about your setup.