IT Services
Penetration Testing
Ethical hacking to find vulnerabilities in your systems before real attackers do, with clear, actionable reports that your team can act on.
A penetration test gives you an adversarial view of your security posture. Our testers think like attackers, probing your systems, applications and people for weaknesses. The result is a prioritised list of vulnerabilities and practical remediation guidance.
Types of testing
We offer a range of penetration testing services depending on your requirements and risk profile.
- External network penetration testing: attacking your perimeter from the internet
- Internal network penetration testing: simulating an insider or post-breach scenario
- Web application penetration testing: OWASP Top 10 and beyond
- Social engineering: phishing simulations and physical security testing
- Cloud configuration review: AWS, Azure and Google Cloud posture assessment
What you receive
Every engagement delivers a comprehensive written report and a debrief session.
- Executive summary for leadership: risk rating and key findings
- Technical report with full vulnerability details and evidence
- Prioritised remediation roadmap with effort/risk ratings
- Debrief session with your technical team
- Optional re-test to verify remediation
Know what you are buying
A vulnerability scan is not a penetration test
Both are sold under the same words and the price gap between them is large. A scan is a useful thing to run continuously, and it is not what this page is offering. Here is the difference, so a quote can be read properly.
Vulnerability scan
Penetration test
Who does the work
Vulnerability scan
Software, running against a database of published vulnerabilities.
Penetration test
A person, using tools, who decides what to try next based on what they find.
What it finds
Vulnerability scan
Known issues with a published signature: missing patches, outdated versions, weak ciphers.
Penetration test
The above, plus logic flaws, broken access control and chains where three harmless findings combine into one serious one.
False positives
Vulnerability scan
Common. Anything matching a signature is reported whether it is exploitable in your environment or not.
Penetration test
Findings are confirmed by exploiting them before they reach the report.
What you get
Vulnerability scan
A list, often hundreds of rows, ordered by a generic severity score.
Penetration test
Prioritised findings with evidence, business impact and remediation guidance.
How long
Vulnerability scan
Minutes to hours, and it can run continuously.
Penetration test
Days to weeks, depending on scope.
Scoping
How much do you tell the tester?
This choice affects both cost and depth more than any other, and buyers are often asked to make it without being told what it means.
Black box
No prior knowledge
The tester starts where an external attacker starts, with your public footprint and nothing else. The most realistic simulation of an opportunistic attack, and the least efficient use of the days, because time goes into discovering what a white box test is simply told.
Grey box
Limited access
Standard user credentials and a basic description of the architecture. Usually the best value for most businesses: it answers both what an outsider can reach and what one compromised staff login leads to, which is how most real breaches actually unfold.
White box
Full visibility
Architecture documentation, configuration and often source code. The deepest coverage per day spent and the best choice when you want assurance over a specific application rather than a simulation of an attack.
How a test runs
Six phases, from scope to retest
Engagements draw on the OWASP Web Security Testing Guide, the detailed methodology behind application testing, and on the Penetration Testing Execution Standard. The first phase and the last are the two that decide whether anything actually gets fixed: without agreed scope a test answers the wrong question, and without a retest nobody has confirmed the fix worked.
Scope and rules of engagement
What is in scope, what is explicitly out, when testing may run, and who to call to stop it immediately. Agreed and signed before anything is touched. Testing without this in writing is a risk to both sides.
Reconnaissance
Mapping what you actually expose: hosts, services, applications, subdomains, exposed credentials and anything published that was never meant to be. Most engagements surface assets the client did not know were reachable.
Exploitation
Attempting to use what was found, because a vulnerability nobody can exploit in your environment is not the same as one they can. This is the step an automated scan cannot perform, and the reason findings arrive already verified.
Post-exploitation
Having got in, how far does it go? Escalating privilege, moving laterally and reaching data establishes real business impact rather than a theoretical severity rating. This is where a medium finding is sometimes shown to be critical.
Reporting
An executive summary written for people who will not read the technical section, and a technical report with evidence, reproduction steps and remediation guidance for the people who will.
Retest
Verifying that the fixes actually fixed it. Remediation frequently changes behaviour without closing the underlying issue, and a finding is only closed once somebody has tried it again.
FAQ
Questions we are asked most
How often should we run a penetration test?
What drives the cost?
Will testing break anything or take our systems down?
Do you test web applications against the OWASP Top 10?
What do you need from us to scope it?
Book a penetration test
Tell us about your environment and we'll scope the right engagement for you.