Penetration Testing and Offensive Security Services
Most organisations find out about their security weaknesses from someone else. A customer sends a security questionnaire. An insurer asks for evidence. Occasionally the discovery is far worse and arrives as a ransom note.
A penetration test moves that discovery forward, to a point where you still control what happens next. We test your systems the way a real attacker would, inside an agreed scope and under written authorisation, then give you a report that says what we found, how we found it, and what to fix first.
We do not sell automated scans with a logo on the front page. A vulnerability scanner tells you that a port is open. A tester tells you that the open port leads to an admin panel with default credentials, and that the admin panel can read every customer record in your database. Those are very different pieces of information, and only one of them changes what you do on Monday morning.
What we test
Web applications
Authentication and session handling, access control between user roles, injection flaws, business logic abuse, file upload handling and everything else in the OWASP Top 10. Business logic is where the interesting findings usually live, because scanners cannot understand what your application is supposed to do.
APIs
REST, GraphQL and SOAP endpoints tested against the OWASP API Security Top 10. Broken object level authorisation remains the most common serious finding we expect to see in modern applications, and it is almost always invisible to automated tooling.
External network infrastructure
Everything an attacker can reach from the internet. Exposed services, unpatched systems, weak remote access, forgotten development environments and shadow infrastructure nobody remembers deploying.
Internal networks
Assumed breach testing. We start with the access a compromised employee laptop would provide and work towards domain administrator, mapping the path so you can break it.
Cloud environments
AWS, Azure and Google Cloud tested against provider specific attack paths rather than generic network methodology. Identity misconfiguration, over permissive roles, exposed storage and metadata service abuse.
Mobile applications
iOS and Android, covering local data storage, certificate handling, hardcoded secrets, and the backend services the app talks to.
People
Phishing simulation and social engineering assessment, measured by click rate, credential submission rate and reporting rate, followed by targeted training for the staff who need it.
How a test actually runs
Scoping. A conversation, not a form. We establish what matters to your business, what is in scope, what is explicitly out of scope, and what a worst case outcome would look like for you. This drives everything else.
Authorisation. Nothing begins without a signed engagement letter and rules of engagement. Where cloud providers require notification or have testing policies, we follow them. Testing without documented permission is illegal regardless of intent, and any firm willing to skip this step is telling you something important about how they work.
Reconnaissance and mapping. We build a picture of your attack surface, often finding assets the internal team had forgotten about. This stage alone frequently produces value before a single exploit is attempted.
Exploitation. Manual testing supported by tooling, not the reverse. We chain findings together, because attackers do not stop at one vulnerability. A medium severity information leak plus a medium severity access control gap can equal a critical compromise, and only a human tester will connect them.
Reporting and debrief. Written findings with reproduction steps and evidence, followed by a call where we walk your team through the results and answer questions. Developers get technical detail. Leadership gets a version they can act on.
Retesting. Once you have fixed the issues, we verify the fixes and reissue the report. This is included rather than billed separately, because a report full of unverified remediation is not much use to an auditor or a customer.
What you receive
A findings report with an executive summary written for people who do not work in security, and technical detail written for people who do. Every finding includes severity rating, business impact, evidence, reproduction steps and specific remediation guidance rather than a link to a generic advisory.
A prioritised remediation plan, ordered by real risk to your organisation rather than raw CVSS score. A high severity issue on an isolated internal system is often less urgent than a medium severity issue on your customer facing login page.
An attestation letter suitable for sharing with customers, insurers and procurement teams. This is frequently the reason a test was commissioned in the first place, and it needs to be a document you can send out without editing.
A retest report confirming what has been resolved.
Individual services
Standards and methodology
Testing follows recognised methodology rather than a private process nobody can inspect. We work to OWASP Testing Guide and OWASP API Security Top 10 for application work, and to the Penetration Testing Execution Standard and NIST SP 800 115 for infrastructure engagements. Findings are rated using CVSS and then adjusted for context, because a scoring system does not know which of your systems holds the data that would end your business.
Where a test supports a compliance requirement, the report is mapped to the relevant control so your auditor can use it directly. This matters most for SOC 2, ISO 27001 and PCI DSS, all of which expect regular testing and evidence that findings were addressed.
Who commissions this work
Software companies whose enterprise customers will not sign without a recent test report. Financial services and fintech firms under regulatory obligation. Healthcare organisations handling patient data. Ecommerce businesses processing card payments. Professional services firms holding client information that would be genuinely damaging to lose.
The common factor is rarely a security team asking for a test. It is usually a sales deal that has stalled, an insurance renewal, an audit, or a board that has started asking questions.
Scoping and pricing
Price depends on scope, and scope depends on complexity rather than company size. A single marketing website is a small engagement. A multi tenant platform with a large API surface, several user roles and third party integrations is not.
We scope from a short call and a few questions about your architecture, then provide a fixed price proposal with a defined start date and delivery date. No hourly billing, no scope creep, no invoice at the end that surprises you.
Emergency and short notice testing is available when a deal or audit deadline is driving the timeline.
Frequently asked questions
How long does a penetration test take?
Most engagements run between five and fifteen working days of testing, with the report delivered within a week of testing finishing. Small, well defined scopes complete faster.
Will testing disrupt our systems?
Testing is designed to avoid disruption. Denial of service testing is excluded unless you specifically request it and agree a maintenance window. We agree escalation contacts before starting so anything unexpected is handled immediately.
Should we test production or staging?
Production gives accurate results but requires care. Staging is safer but only useful if it genuinely mirrors production. We will recommend an approach during scoping based on how closely your environments match.
How often should we test?
Annually as a baseline, and after any significant change to your application or infrastructure. Most compliance frameworks expect at least yearly testing. Organisations shipping code frequently often move to a shorter cycle for their main application.
Is retesting included?
Yes. One round of retesting within an agreed window after the original engagement, with a reissued report confirming remediation.
Can you test our cloud environment?
Yes. Cloud testing follows each provider's acceptable use policy, and we handle any required notification. See Cloud Security for continuous posture work alongside point in time testing.
Find out what an attacker can already see
Book a scoping call and we will tell you what a test would cover, what it would cost and how long it would take. No obligation and no sales sequence afterwards.