Secure · Cyber & Networks
Penetration testing
Controlled, evidence-led attacks on your applications, networks and cloud estate, reported in terms your engineers and your board can both act on.
The challenge
Automated scanners report what is visible from the outside. They do not chain a weak password reset flow to an over-privileged API to reach a customer database, and that chain is what an attacker will look for.
Many organisations commission a test to satisfy an auditor, receive a long list of unranked findings, and fix the easy ones. The exploitable path to sensitive data often survives the cycle untouched.
We test the way an adversary would, within agreed rules, and report each finding with the evidence, the business impact and a fix your team can implement. Then we come back and confirm the fix works.
Our method
How the work is done.
- 01
Scoping and rules of engagement
We agree targets, exclusions, testing windows, credentials, escalation contacts and the handling of any sensitive data encountered, recorded in a signed rules-of-engagement document before any testing starts.
- 02
Reconnaissance
We map the attack surface: exposed hosts and services, application routes, authentication flows, third-party dependencies and publicly available information about the environment.
- 03
Vulnerability analysis
Automated discovery is combined with manual review of business logic, access control and configuration, guided by OWASP WSTG for applications and established methodology for infrastructure.
- 04
Exploitation
Candidate weaknesses are exploited in a controlled manner to prove real impact, chaining findings where possible, and stopping at agreed boundaries to protect live services and data.
- 05
Reporting
Each finding is rated with CVSS, mapped to the affected asset, supported by reproduction steps and evidence, and paired with specific remediation guidance. We walk both technical and leadership audiences through the results.
- 06
Retest
Once fixes are deployed we retest each finding and issue a retest letter confirming which issues are closed and which remain open.
Deliverables
What you receive.
- Signed rules-of-engagement and scope document
- Executive summary written for leadership and audit committees
- Technical report with CVSS-rated findings, evidence and reproduction steps
- Prioritised remediation plan tied to each finding
- Attack-path narrative showing how findings combine
- Debrief workshop with engineering and security teams
- Retest letter confirming the status of each finding
Engagement options
Ways to buy it.
- 011 to 3 weeks
Targeted assessment
A single application, API, external perimeter or cloud account, tested in depth.
- 026 to 12 months
Programme of testing
A planned calendar of tests across the estate, aligned to release cycles and audit dates.
- 032 to 4 weeks
Pre-release assurance
Testing scheduled into a delivery programme before a major launch, with retest before go-live.
Standards
Frameworks we work to.
- OWASP WSTG
- OWASP ASVS
- CVSS
- PCI DSS
- NIST SP 800-115
- MITRE ATT&CK
Questions
What buyers ask us.
Will testing disrupt our live services?
Testing windows, rate limits and prohibited techniques are agreed in the rules of engagement. Destructive or high-risk actions are only performed with explicit approval, and we keep a named contact informed throughout.
Do you test in production or a staging environment?
Either. Production gives the truest picture; staging allows more aggressive techniques. We often recommend staging for depth with a lighter production check for configuration differences.
How is a test different from a vulnerability scan?
A scan lists potential weaknesses. A test proves which ones are exploitable, how they combine, and what an attacker could actually reach.
Is the retest included?
Yes. One retest of the reported findings is part of every engagement, and the retest letter is issued once it is complete.
Can the report be shared with auditors or regulators?
Yes. The executive summary and retest letter are written to be shared; the technical report is suitable for auditors under your normal confidentiality arrangements.
Related services
Often delivered together.
Train
Secure development
Practical training for developers on writing, reviewing and testing code that withstands real attacks and passes security review.
Secure
Governance, risk & compliance
Gap assessments, risk registers, policies and audit readiness against ISO 27001, SOC 2, PCI DSS and NIST CSF, built to be used rather than filed.
Run
DevSecOps & SRE
Security in the delivery pipeline and site reliability practices that keep critical services within defined service levels.
Discuss penetration testing.
A senior engineer reviews every enquiry and replies within one business day.