IT Security Testing

Let us find security vulnerabilities before others do.

Which security tests are offered?

Penetration tests are security audits in which vulnerabilities in systems and applications are identified. Such vulnerabilities could be exploited by hackers and lead to serious consequences. Whoever carries out penetration tests of their own IT systems can preempt attackers and remediate vulnerabilities.

Depending on the system or application, there are various variants of penetration tests:

Find out more about the offered Penetration Tests.

Targeted hacker attacks often take place silently. Cybercriminals use any means available, they exploit the social behavior of people and discover serious gaps in complex IT infrastructures.

In a Red Teaming Assessment, a realistic attack on a company is simulated. Security experts take on the role of the attackers – the so-called Red Team –, who attempt to compromise a company's IT infrastructure over a longer period of time. The company's so-called Blue Team is responsible for protecting the organization and attempts to detect the Red Team and successfully fend off attack attempts.

Red Teaming is a realistic view of attacks by cybercriminals. Find out how you can effectively defend yourself against hackers through a Red Teaming Assessment.

The availability of some IT systems is particularly important. If they come to a standstill, this can have far-reaching effects. But how many requests can a system withstand and is it easy for hackers to shut down a system?

Stress tests simulate a high number of simultaneous user accesses to a system. They can show how systems and applications behave under load and at what point the maximum load failure point is reached.

Find out more about the services offered by Load Testing and Service Outage Testing.

A large part of the attacks on IT systems are carried out automatically via the internet. In doing so, criminals mostly exploit known security gaps in standard software. Protection against this type of attack can also be carried out automatically via security scans. aramido puts together a security check suitable for your environment from various vulnerability scanners, some of which are developed in-house, carries out the scans, and helps you to close the discovered security gaps. The scanners are divided as follows:

  • Web scan
  • Infrastructure scan

Find out more about the services offered in the area of Vulnerability Scanning.

What is the result of a security audit?

We are often asked how the quality of a security audit can be evaluated. Similar to other audits and stress tests, there are established standards for IT security tests from organizations such as BSI or OWASP. When conducting a security audit, we orient ourselves towards these standards, making the audit comparable and reproducible. Furthermore, especially when finding unknown security vulnerabilities, the creativity of the security testers is crucial. All auditors at aramido have a sound background in software development and therefore know which errors can occur when programming complex software. Finally, as a result of an aramido security audit, you receive a transparent test report documenting all tests performed, regardless of whether the test had a positive or negative outcome.

  • Risk-based audits
  • Security audits according to recognized standards
  • Detailed and understandable test report
  • Maximum confidentiality

Who needs a security audit?

Our clients have in common that they generate a substantial proportion of their turnover on the internet or supported by IT systems. We support them in winning the trust of their customers, employees, and partners. They should all have the certainty that their data is in good hands.

aramido GmbH is BAFA accredited. Under the "Förderung Unternehmerischen Know-hows" program, small and medium-sized enterprises can receive up to 50% of the project sum of a consulting project as a grant.

Medical practices, educational institutions, e-commerce, hotels, Industry 4.0, online marketplaces, medical technology, lawyers and notaries, Software-as-a-Service providers (SaaS), tax and business consultants.

Do you want to protect your business secrets? Find out how an attacker would proceed and how you can protect yourself.

Testimonials for aramido

Dr. Herzig, CEO SearchHaus GmbH

The consultants from aramido convinced me with their extensive expertise and concrete recommendations for measures.

— Dr. Herzig, CEO SearchHaus GmbH

Current articles on IT Security Testing
Andreas Sperber

Published on 01.08.2026 published.

Hacking AI: Loss of Control Instead of Controlled Tests

During an evaluation, OpenAI models autonomously broke out of their test environment and successfully infiltrated Hugging Face's infrastructure. (read more)


Valerie Erhard

Published on 31.07.2026 published.

Agentic AI Changes the Rules of Cybersecurity

From helpful advisor to autonomous actor: The evolution of agentic AI forces a paradigm shift in our IT security. (read more)


Valerie Erhard

Published on 22.07.2026 published.

AI Models Break Out and Hack Hugging Face

During an evaluation, OpenAI models autonomously broke out of their test environment and successfully infiltrated Hugging Face's infrastructure. (read more)


Andreas Sperber

Published on 14.09.2020 published.

Security Advisory: 1CRM Insufficient Data Protection (CVE-2020-15958)

A security vulnerability in the 1CRM software allowed unauthorized users to access sensitive files and system backups. (read more)


Hannah Schneider

Published on 17.02.2020 published.

Save the Date: Cooling Spray, Popcorn, and Live Hacking at the IT Cinema

aramido demonstrates the Cold Boot attack at the BWG IT Cinema, showing how a disk encryption can be bypassed. (read more)