Penetration testing & vulnerability assessment
Find your gaps before someone else does. You get a tested, evidenced view of what an attacker can actually reach in your environment, ranked by what it would cost your business, with fixes your team can start on this quarter.
Four reasons teams come to us first.
Preparing for a certification
ISO 27001 or SOC 2 both require evidence of testing — not just a policy that says you do it.
A client or regulator asked
Some contracts and audits require a penetration test report on file, not just a vulnerability scan.
You shipped something new
A new platform went live and nobody outside the build team has tried to break it.
It's been over a year
In practice, that means you have not been tested. Threats and your environment have both moved on.
Six angles. One coordinated test.
- 01External testing. Everything an attacker can see from the internet: perimeter, exposed services, forgotten subdomains, and credentials of yours already circulating in breach data.
- 02Internal testing. What happens after one laptop is compromised — lateral movement, privilege escalation, and how far a foothold travels before something stops it.
- 03Web & API testing. Against the OWASP Top 10 and the OWASP API Security Top 10, including business logic flaws that scanners never find.
- 04Mobile application testing. Android and iOS, including how the app stores data and talks to your backend.
- 05Cloud configuration review. Identity, storage exposure, network segmentation, and logging across AWS, Azure, and Google Cloud.
- 06Social engineering, on request. Phishing and pretexting, scoped and authorised in writing before anything is sent.
A report built to be checked, not taken on faith.
- 01An executive summary your board can read in five minutes, written in business risk rather than CVE numbers.
- 02A technical report with reproduction steps, evidence, and CVSS scoring for every finding.
- 03A remediation roadmap ordered by exploitability and business impact, with effort estimates so your team can plan sprints against it.
- 04A free retest of every critical and high finding, at no extra cost, within 90 days.
- 05An attestation letter you can send to clients, auditors, and regulators.
One test, several obligations satisfied.
Findings are mapped to ISO 27001 Annex A controls and, where relevant, to the national requirements that apply in your market — so one test feeds several compliance obligations instead of one.
How long it takes, by scope.
| Scope | Typical duration | Report delivered |
|---|---|---|
| External perimeter | 5 working days | Within 5 working days of test close |
| Web application or API | 5 – 10 working days | Within 5 working days |
| Internal network | 10 – 15 working days | Within 7 working days |
| Full-scope programme | 15 – 25 working days | Within 10 working days |
Testing windows are agreed around your operating hours. Where infrastructure will not tolerate load, we say so at scoping and adjust the method rather than risk your production environment.
Straight answers, before you ask.
What's the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment scans for known weaknesses. A penetration test has an engineer actively try to exploit them, the way a real attacker would. Ours combines both in one engagement.
How long does a penetration test take?
An external perimeter test typically takes 5 working days. A full-scope programme — external, internal, web/API, and cloud — runs 15 to 25 working days, depending on scope.
Do you test production environments?
Yes, on request, with testing windows agreed around your operating hours. Where infrastructure will not tolerate load, we say so at scoping and adjust the method rather than risk your production environment.
What do we receive at the end of the test?
An executive summary for your board, a technical report with reproduction steps and CVSS scoring, a prioritised remediation roadmap, a free retest of every critical and high finding within 90 days, and an attestation letter for clients, auditors, and regulators.
Which standards do you test against?
OWASP Top 10, OWASP ASVS, PTES, NIST SP 800-115, and MITRE ATT&CK — with every finding mapped to ISO 27001 Annex A and the national framework that applies in your market.
See what an attacker can reach.
Same NDA, same named engineer, same report format described above — scoped to penetration testing and vulnerability assessment. No cost, no obligation.
Penetration testing & vulnerability assessment.
Request received.
A named engineer will reply within one business day to scope the NDA and the test window.