RESOLV

Secure · Cyber & Networks

Penetration testing

Controlled, evidence-led attacks on your applications, networks and cloud estate, reported in terms your engineers and your board can both act on.

The challenge

Automated scanners report what is visible from the outside. They do not chain a weak password reset flow to an over-privileged API to reach a customer database, and that chain is what an attacker will look for.

Many organisations commission a test to satisfy an auditor, receive a long list of unranked findings, and fix the easy ones. The exploitable path to sensitive data often survives the cycle untouched.

We test the way an adversary would, within agreed rules, and report each finding with the evidence, the business impact and a fix your team can implement. Then we come back and confirm the fix works.

Our method

How the work is done.

  1. 01

    Scoping and rules of engagement

    We agree targets, exclusions, testing windows, credentials, escalation contacts and the handling of any sensitive data encountered, recorded in a signed rules-of-engagement document before any testing starts.

  2. 02

    Reconnaissance

    We map the attack surface: exposed hosts and services, application routes, authentication flows, third-party dependencies and publicly available information about the environment.

  3. 03

    Vulnerability analysis

    Automated discovery is combined with manual review of business logic, access control and configuration, guided by OWASP WSTG for applications and established methodology for infrastructure.

  4. 04

    Exploitation

    Candidate weaknesses are exploited in a controlled manner to prove real impact, chaining findings where possible, and stopping at agreed boundaries to protect live services and data.

  5. 05

    Reporting

    Each finding is rated with CVSS, mapped to the affected asset, supported by reproduction steps and evidence, and paired with specific remediation guidance. We walk both technical and leadership audiences through the results.

  6. 06

    Retest

    Once fixes are deployed we retest each finding and issue a retest letter confirming which issues are closed and which remain open.

Deliverables

What you receive.

  • Signed rules-of-engagement and scope document
  • Executive summary written for leadership and audit committees
  • Technical report with CVSS-rated findings, evidence and reproduction steps
  • Prioritised remediation plan tied to each finding
  • Attack-path narrative showing how findings combine
  • Debrief workshop with engineering and security teams
  • Retest letter confirming the status of each finding

Engagement options

Ways to buy it.

  1. 01

    Targeted assessment

    A single application, API, external perimeter or cloud account, tested in depth.

    1 to 3 weeks
  2. 02

    Programme of testing

    A planned calendar of tests across the estate, aligned to release cycles and audit dates.

    6 to 12 months
  3. 03

    Pre-release assurance

    Testing scheduled into a delivery programme before a major launch, with retest before go-live.

    2 to 4 weeks

Standards

Frameworks we work to.

  • OWASP WSTG
  • OWASP ASVS
  • CVSS
  • PCI DSS
  • NIST SP 800-115
  • MITRE ATT&CK

Questions

What buyers ask us.

Will testing disrupt our live services?

Testing windows, rate limits and prohibited techniques are agreed in the rules of engagement. Destructive or high-risk actions are only performed with explicit approval, and we keep a named contact informed throughout.

Do you test in production or a staging environment?

Either. Production gives the truest picture; staging allows more aggressive techniques. We often recommend staging for depth with a lighter production check for configuration differences.

How is a test different from a vulnerability scan?

A scan lists potential weaknesses. A test proves which ones are exploitable, how they combine, and what an attacker could actually reach.

Is the retest included?

Yes. One retest of the reported findings is part of every engagement, and the retest letter is issued once it is complete.

Can the report be shared with auditors or regulators?

Yes. The executive summary and retest letter are written to be shared; the technical report is suitable for auditors under your normal confidentiality arrangements.

Discuss penetration testing.

A senior engineer reviews every enquiry and replies within one business day.