Every test.
One source
of truth.
Cerberos Nexus is where pentest companies run every engagement, from pentests to PCI ASV quarters, and where their clients follow every finding through to a verified fix.
Built for pentest companies.
Open to their clients.
Pentest companies run the work in the Team Console. The companies they test follow it in the Client Portal. Both work from the same record, so nothing is chased by email or lost in a PDF.
Run every engagement from one console.
- Pentests, VA, PCI ASV, segmentation and red team in one console
- Methodology checklists from OWASP, PTES and NIST templates that gate reporting
- Findings scored with CVSS 3.1, with evidence and scanner imports
- Quality checks built in: checklist gates, ASV QA and two-person publishing
- Reports on your own templates, delivered as password-protected PDFs
- Milestones, timesheets, leave and a weekly digest for delivery managers
Follow every finding to a verified fix.
- Findings as they are published, with evidence and a recommended fix
- SLA due dates and overdue counts on a live dashboard
- Accept, dispute or comment on findings, with evidence
- Retests requested from the portal when a fix is ready
- Reports and evidence to download, including PCI ASV deliverables
- Client admins invite their own team, with MFA on every account
Every engagement.
One platform.
Penetration tests, continuous projects, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements, each managed from scope to report with the client in the loop.
Penetration tests
A scoped project for web apps, APIs, networks, cloud, mobile and more. It runs from planning through testing, reporting and remediation to delivery, and the methodology checklist must be complete before it moves to reporting.
Explore penetration tests →- Scope, milestones and the team, on a timeline
- Methodology checklists from OWASP, PTES and NIST templates
- Findings scored with CVSS 3.1, with evidence and scanner imports
- Reports on your own templates, delivered as protected PDFs
Continuous projects
Recurring vulnerability assessment and PCI ASV work, run as cycles on a set cadence instead of one-off projects. Scope is decided for each cycle, findings are tracked across every scan, and overdue cycles are flagged.
Explore continuous projects →- VA or PCI ASV projects, monthly to annual
- Scope decided for each cycle
- Primary, verification and ad hoc scans
- Scheduled scans that start on their own
Vulnerability assessments
Scanner output turned into findings a client can act on. Scans are launched from the platform or imported, each issue is tracked across hosts and repeat scans, and verification scans show what looks fixed.
Explore vulnerability assessments →- Scans launched in Nessus, Nexpose or Burp Pro
- Imports from Nessus, Nexpose, Burp, Acunetix and CSV
- Findings tracked across hosts and repeat scans
- Verification scans that flag likely fixes
PCI ASV scanning
Quarterly external scanning with the ASV rules built in. A quarter passes only when its scan covers the whole scope with no failing findings, and only a passing, QA-approved quarter can be attested.
Explore PCI ASV scanning →- Quarterly cycles with the pass and fail rules built in
- Disputes for false positives, compensating controls and scope
- Independent QA sign-off, cleared if the quarter changes
- Attestation by someone other than the QA reviewer
Segmentation tests
Proof that networks are isolated the way the policy says. Zones and the allowed, prohibited or conditional paths between them are defined once, and every test run checks what is actually reachable against them.
Explore segmentation tests →- Zones with their address ranges
- A zone-to-zone policy: allowed, prohibited or conditional
- Results from nmap, Nessus, CSV or manual entry
- Pass or fail per path, each reachable service triaged
Red team engagements
An objective-led engagement with its authorisation, rules of engagement and attack plan in one record. Activity is mapped to MITRE ATT&CK, and findings are published only after review, by someone other than their author.
Explore red team engagements →- Objectives, starting scenario and rules of engagement
- Authorisation letters and NDAs on file
- Attack maps from playbooks, with step approvals
- Findings reviewed, then published by a second person
No finding left
in a PDF.
Clients see each finding as it is published, with its evidence, SLA due date and every retest, in one place instead of a folder of PDFs.
Scope to verified,
in six steps.
Every step is timestamped and attributed in an append-only audit trail.
Scope
Assets, scope and the team on it.Test
Checklists worked, findings logged.Report
Quality-checked, on your template.Remediate
SLA due dates, comments, disputes.Retest
Requested by the client in the portal.Verified
Closed with the evidence on record.One-time pentest or continuous project. Same platform.
Run a scoped pentest when a release or an audit needs a point-in-time answer, and continuous VA and PCI ASV projects for the scanning that comes round every month or quarter. Both reach the client in the same portal.
One-time
Scope, test, report and retest, closed with a delivered report.Continuous
Cycles on a cadence, scheduled scans and verification scans.Questions buyers ask.
Straight answers about Cerberos Nexus, for pentest companies and the clients they work with.
Pentest companies and the clients they test. The pentest company runs its engagements in the Team Console, and its clients follow findings, disputes, retests and reports in the Client Portal.
Penetration tests, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements. Vulnerability assessments and PCI ASV scanning run as continuous projects, in cycles. Every type reaches the client in the same portal.
The pentest company sets up the client and invites its first users. Client admins can then invite the rest of their team, and every account signs in with multi-factor authentication.
Yes. Reports are generated from HTML or Word templates set up for your company, and delivered as password-protected PDFs.
Scans can be launched in Nessus, Nexpose and Burp Pro, and results imported from Nessus, Nexpose, Burp, Acunetix and CSV. Segmentation tests also take nmap results.