Skip to content

Services / Test

Penetration Testing

Manual, adversary-simulated testing of your networks, applications and infrastructure by testers who do incident response the rest of the year — so findings reflect how systems are actually breached.

What you receive

  • Black, grey or white box to agreed rules of engagement
  • Risk-ranked findings with reproduction steps
  • Remediation retest included in scope
  • Attestation letter for customers and auditors

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A customer's security review has stalled

    Enterprise procurement and banking counterparties increasingly ask for an independent test report before they sign, and a completed questionnaire will not stand in for one. What their reviewer reads is the scope statement and the findings: what was tested, when, by what method, and what was found.

  • 02

    You are about to expose something new

    A new customer portal, payment API or VPN concentrator has the shortest gap between going live and being found. Testing before the DNS record is public means the first person to probe the authentication logic is working for you.

  • 03

    The people who built it also tested it

    Developers test what they expected the system to do; an attacker tests what it permits. An independent tester with no authorship of the code will chain a weak session token to an unfiltered object reference in a way the build team has already discounted.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.

  2. 02

    Written proposal

    Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.

  3. 03

    Delivery

    Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.

  4. 04

    Readout and retest

    A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • A test is announced, time-boxed and aimed at an agreed target list — it does not measure whether your SOC noticed. That is red teaming.

  • A test covers the targets on the scope list as they stood on the test dates. Assets that appear afterwards, or that nobody listed because nobody knew they existed, are found by attack surface management.

  • We report findings and retest the fixes — we do not implement the remediation, patch the systems or rewrite the code for you.

Measured against

PCI DSS 4.0.1 Req. 11.4
Requires internal and external penetration testing at least annually and after significant change, using an industry-accepted method.
NIST SP 800-115
The public methodology most scopes are written against: planning, discovery, attack and reporting, with evidence retained at each phase.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

How is this different from a scan someone wrote up?

A scanner matches versions and signatures against a database; a tester chains findings — an exposed backup, a reused credential, a missing authorisation check — into the access an attacker would really obtain. The write-up is the smaller half of the work.

Will the report satisfy our auditor?

It states scope, dates, method and findings, which is what an assessor asks to see. Whether it satisfies them depends on whether the scope you bought covers what the standard requires — PCI DSS, for one, expects the cardholder data environment and its segmentation.

Can you test production?

Usually, with agreed rate limits, a named contact reachable throughout and a stop condition in writing. Some techniques carry real availability risk — password spraying into a lockout policy, deserialisation attempts — and those are flagged before they are run.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.