Skip to content

Security Testing

Find and fix your weaknesses before attackers do. Penetration testing and vulnerability assessments across your apps, cloud, and networks, ranked by risk.

We probe your systems the way an attacker would, then hand you a prioritised, plain-English report: what we found, how serious it is, and exactly how to fix it, plus a retest once you have remediated.

What we test

Testing is scoped to what you actually run, not to a standard package.

  • Web applications and APIs. Authentication, access control, injection, business logic flaws, and the misconfigurations that come from shipping fast.
  • External infrastructure. Everything of yours that faces the internet, including the things nobody remembers exposing.
  • Cloud environments. AWS, Azure, Microsoft 365, and Cloudflare configuration, permissions, and the identity layer that ties them together.
  • Internal networks. What an attacker could reach after one person clicks one link, which is the scenario that most often turns into a real incident.

Why our reports read differently

The most common complaint about penetration test reports is that they are unreadable, and the second most common is that everything in them is marked critical. Both come from the same place: a report generated by a tool and lightly edited.

Ours is written for two audiences deliberately. The first section is for whoever signs off on the budget, and says what an attacker could achieve, what it would cost you, and what to do about it, in language that assumes no security background. The technical detail behind it is for whoever fixes it, with enough evidence to reproduce each finding and a specific remediation rather than a link to a vendor page.

Findings are ranked by what they mean for your business, not by a generic severity score. An issue that a scanner calls medium can be the most urgent thing in the report if it sits on the path to your customer data, and a critical that requires physical access to a locked comms cupboard usually is not.

The retest is included

A finding is not fixed when it is written down, it is fixed when it stops working. Once you have remediated, we retest the findings and reissue the report reflecting what has actually changed.

This matters more than it sounds. If you are testing because a client, an insurer, or a tender asked you to, a report full of open findings is not the document you want to hand over. A reissued report showing them closed is.

When testing is not the right answer

If your MFA coverage is patchy, your backups have never been restored, or you do not know what is exposed to the internet, a penetration test will find those things and charge you for the privilege. You would learn the same at lower cost from a security audit and some hardening work first.

We will say so during scoping. Selling you the more expensive engagement when the cheaper one is the right call is how firms get one client instead of ten.

Typical timeframe
Most engagements run 1 to 3 weeks end to end
Best for
Businesses facing a client security questionnaire, an insurance renewal, or a launch
What an external perimeter scan actually producesThe value is not the list of everything. It is the four things worth acting on.

The engagement

How it runs

Every engagement follows the same shape, so you always know which part you are in and what is coming next.

  1. 1

    Scope

    We agree what is in scope, what is explicitly off limits, and when testing runs. You get a written rules-of-engagement document before anything starts.

  2. 2

    Test

    We probe your systems the way an attacker would, combining tooling with manual testing. Automated scanners find the obvious; the findings that matter usually need a person.

  3. 3

    Report

    You get findings ranked by real-world risk to your business, each with evidence, a plain-English explanation, and the specific steps to fix it.

  4. 4

    Debrief

    We walk you and your team through the report, answer questions, and help you decide what to tackle first and what can wait.

  5. 5

    Retest

    Once you have made the fixes, we retest the findings and reissue the report so it reflects reality. The retest is part of the engagement, not a second job.

Common questions

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated. It runs a tool against your systems and lists everything the tool recognises, including a great deal that does not apply to you. A penetration test uses those results as a starting point and then has a person try to actually exploit what is there, chain issues together, and work out what an attacker could really achieve. Scans tell you what is theoretically wrong; a test tells you what someone could do about it. A scan is cheaper and worth running regularly, but it is not what a client questionnaire or an insurer means when they ask for a penetration test.

Will testing take my systems down?

That is what the scoping conversation is for. We agree in writing what is in scope, and any genuinely disruptive technique is either excluded or scheduled for a window you choose. Most testing is entirely invisible to your users. If we find something where proving it would risk an outage, we stop and describe it rather than demonstrating it live.

How much does a penetration test cost?

It depends almost entirely on scope: how many applications, how many external addresses, whether internal network testing is included. That is why we scope before quoting rather than publishing a number that would be wrong for most people. What we can promise is a fixed price before the work starts, so the invoice matches the quote.

Do I need one, or is something cheaper enough?

Often something cheaper is enough. If you have never done any security work, a penetration test will mostly confirm that, expensively. A security audit and some basic hardening will get you further for less. We will tell you if that is where you are, because a test that finds fifty things you already suspected is a poor use of your money.

Who actually does the work?

A senior consultant, and the same person who scoped it. There is no handover to a junior after you sign, and no offshore subcontracting.

Need help with Security Testing?

Tell us where you are and what is worrying you. We will tell you honestly what we would do first.

Get in touch