One health check covering penetration testing, web and host vulnerability scanning, secure code review, and phishing simulation — delivered as an audit-ready Chinese report with remediation tracking, for regulator requirements, customer audits, and cyber-insurance assessments.
Annual security health check covering penetration testing, vulnerability scanning, code review, and phishing simulation
They differ in purpose and breadth. A penetration test digs deep into the exploitability of specific systems; a health check is a breadth-first review across four layers — scanning, penetration validation, code, and people — suited to building an annual baseline and audit-ready evidence. If you have already done a penetration test, a health check fills in the remaining layers.
It depends on asset scale. Initial testing and reporting typically complete in about 2–4 weeks; a full cycle including remediation and retest takes about 6–8 weeks. We run a scope inventory before kickoff and commit to a clear schedule.
We can schedule off-peak windows, throttle scan intensity, and set allowlists; potentially disruptive items (such as stress testing) are always agreed separately in advance and never run without consent.
Yes. The report is written in Chinese with an executive summary, technical appendix, and a statement of methodology and scope, usable as audit and submission evidence; if the recipient specifies a format or checklist, we align the report accordingly.
No. Under the appendices to the Regulations on Classification of Cyber Security Responsibility Levels, the statutory health check under Taiwan's Cyber Security Management Act applies to government agencies and designated non-government agencies, with a fixed set of six items: network architecture review, network malicious activity review, client endpoint malicious activity review, server host malicious activity review, directory service system and firewall connection configuration review, and — added in the January 2026 amendment — core system database security review, typically procured through government channels. ThunderShield's Enterprise Security Health Check is designed for private-sector exposure and application security, covering penetration testing, vulnerability scanning, code review, and phishing simulation — a different scope and audience. If you need the statutory health check, first confirm your organization's cybersecurity responsibility tier and review cycle before engaging a provider.
Contact ThunderShield for a consultation · View pricing plans