Security Testing & Compliance

Penetration Testing & Managed Compliance

We attack your network the way an intruder would, before an intruder does - at onboarding, and on a schedule after that. Then we keep the policies, evidence, and risk assessments current for HIPAA, CMMC, PCI DSS, SOC 2, the FTC Safeguards Rule, and your cyber insurance carrier, so an audit or a renewal questionnaire is a report you pull, not a fire drill.

What's Included

External Penetration Testing

Your firewall, VPN, remote access portals, exposed services, and sign-in pages, tested from the internet the way an attacker sees them. We find what is reachable before a scanner in someone else's botnet does.

Internal Assumed-Breach Testing

We start from one compromised laptop and see how far it gets: lateral movement, privilege escalation, stale admin accounts, flat networks, and file shares open to everyone. This is where most real incidents are won or lost.

Wireless and On-Site Testing

We come to your office and test from the inside: wireless networks, guest and staff Wi-Fi separation, rogue access points, and what a visitor could reach by plugging into an open network jack in a conference room.

Remote Access Tool Sweep

Unauthorized remote access tools are how intruders stay in. SentryOwl, our own early-access endpoint tool from Parliament Labs, looks for them on every Windows machine we test.

Findings You Can Act On

A plain-English summary for leadership and a technical detail section for whoever fixes it, with every finding ranked by real-world risk - not a 200-page scanner export.

Fix, Then Retest

Findings should not sit in a PDF. For managed clients we remediate them ourselves; for standalone engagements your team or provider does. Either way, we retest to prove each one is actually closed, and the retest result goes in your evidence file.

Framework Mapping

HIPAA, CMMC and NIST 800-171, PCI DSS, SOC 2, and the FTC Safeguards Rule, mapped to the controls you actually run, so you can see which requirements are met, which are partial, and which are open.

Policies That Match Reality

Written security policies drafted against how your environment is really configured, and kept current when it changes. A policy that describes controls you do not have is a liability, not a defense.

Evidence Collected as You Go

Patch status, MFA coverage, backup restores, EDR health, and access reviews, captured from the tools we already run. When an auditor or carrier asks, the answer already exists.

How It Works

  • Scope and Written Authorization We agree in writing what is in scope, what is off limits, and the testing windows. Nobody tests anything without signed authorization - that line is what separates a pen test from an attack.
  • Baseline Test at Onboarding Before we take over an environment, we test it. You learn what a previous provider left behind, and we start from facts instead of assumptions.
  • Report and Remediation Plan Risk-ranked findings with a prioritized fix list, walked through with you in a meeting rather than emailed and forgotten.
  • Remediate and Retest We close the findings and retest each one. The before-and-after becomes evidence for your framework, your auditor, or your insurer.
  • Ongoing Testing and Compliance Recurring tests on an agreed cadence and after significant changes, with policies, risk assessments, and evidence kept current between them.

Why We Test Before We Take Over

A new managed IT relationship with us normally starts with a penetration test. Not a questionnaire, not a scan you never see the results of – an actual attempt to get in from outside, and an actual attempt to move around once inside. Pen testing has been part of our managed services from the start, because the alternative is taking responsibility for an environment we have not looked at properly.

What turns up is rarely exotic. A remote access tool a former vendor installed and nobody removed. An admin account belonging to someone who left years ago. A firewall rule opened for a weekend project that is still open. Each one is small. Chained together, they are how most breaches actually happen.

Testing Shows Where You Stand. Compliance Keeps You There.

A pen test is a snapshot. The week after it finishes, someone adds a user, changes a firewall rule, or installs a new application, and the snapshot starts to age. Compliance is the discipline that keeps the picture current between tests: written policies, scheduled risk assessments, and evidence that the controls you say you have are still working.

Most businesses do compliance in a panic once a year, the week before an audit or an insurance renewal. Because we already run the systems the evidence comes from, we collect it as we go. When your auditor, a client’s security questionnaire, or your cyber insurance carrier asks a question, the answer is a report we can pull, not a project.

Frameworks we support

  • HIPAA – risk analysis, safeguards, and documentation for healthcare and dental practices. See HIPAA-compliant IT.
  • CMMC and NIST 800-171 – control implementation, SSP and POA&M upkeep, and assessment readiness for defense suppliers. See CMMC compliance.
  • PCI DSS – segmentation, access control, and the annual and after-change testing the standard requires, ahead of your QSA or self-assessment.
  • SOC 2 – readiness and continuous evidence for the controls your CPA firm will examine.
  • FTC Safeguards Rule – the written information security program, risk assessment, and testing it requires of financial service businesses.
  • Cyber insurance – accurate, evidence-backed answers on carrier questionnaires and renewals.

Built by Our Own Software Team

Parliament Labs is the software arm of ROI Technology. It exists because running a managed security practice kept exposing gaps no off-the-shelf tool covered. SentryOwl, now in early access, came out of exactly this work: it finds unauthorized remote access tools on Windows endpoints, which is one of the first things we look for in every test. We are building our own compliance platform the same way, so the evidence trail behind your program is something you can see rather than something you have to take on trust. See our brands.

Who This Is For

Healthcare and dental practices

HIPAA expects a documented risk analysis and safeguards you can show. Testing proves the safeguards work; the evidence file proves you checked.

Learn more →

Defense suppliers

CMMC and NIST 800-171 assessments go far better when every control already has an owner, a policy, and evidence behind it. We get you assessment-ready and keep you there.

Learn more →

Businesses facing an insurance renewal

Carriers now ask detailed questions about MFA, backups, EDR, and testing. Answer them with evidence instead of optimism - a wrong answer can void the policy you are paying for.

Learn more →

Financial, legal, and payment-handling firms

The FTC Safeguards Rule, PCI DSS, and client security questionnaires all ask the same thing in different words: prove it. We keep the proof current.

Learn more →

ROI Technology by the Numbers

Est. 2014 Serving Washington
Zero Voluntary Churn
$0 Ransomware Losses
7+ yrs Avg. Client Tenure

Frequently Asked Questions

Find out what an attacker would find

Tell us about your environment and the framework or insurer you answer to. We will scope a test and come back with a written, fixed quote.