Home / Services / Penetration Testing
Penetration Testing

Penetration testing that finds what a scanner won't.

Manual, practitioner-led penetration testing across your network, web applications and cloud infrastructure, with reports built to satisfy ISO 27001, SOC 2 and your customers' security teams, all from consultants based in the UK, US and EU.

Manual-Led TestingOWASP-based methodology
One remediation round included
UK · US · EU testers
Who it's for

Who this is for

Most companies book their first penetration test for one of three reasons. A customer has sent a security questionnaire asking for a recent test report and the deal is blocked without one. An auditor has flagged that ISO 27001 Annex A.8.8 or SOC 2 CC7.1 expects evidence of technical vulnerability testing. Or an engineering lead has quietly worried for months that nobody has ever looked at the platform from the outside. All three are good reasons. The difference is that the first two come with a deadline attached, so tell us about it early and we will work backwards from the date your customer or auditor needs the report in hand.

What's included

Scope, in plain terms.

PT-01 Scope

Network Pentest

External and internal network testing across your cloud VPCs, on-prem ranges or hybrid estate, mapped to real attack paths rather than a generic scanner output.

PT-02 Scope

Web Application Pentest

Manual testing against the OWASP Top 10 and business-logic flaws automated scanners miss: authentication, authorisation, API abuse and injection classes.

PT-03 Scope

Cloud Configuration Review

AWS, Azure or GCP configuration testing: IAM privilege paths, storage exposure, network segmentation and logging gaps.

PT-04 Deliverable

Remediation Round Included

One round of fixes followed by a re-test of those findings, so the final report reflects your remediated state rather than the day we found the issue.

PT-05 Deliverable

Executive + Technical Report

A board-readable summary alongside a fully reproducible technical report your engineers can action line by line.

PT-06 Fit

Compliance-Ready Evidence

Reports formatted to satisfy ISO 27001 Annex A.8.8, SOC 2 CC7.1 evidence requests, and customer security questionnaires without extra rework.

What a penetration test is, and what it is not

A penetration test is a time boxed, manual security assessment where a tester tries to compromise your systems the way an attacker would, then documents exactly how they did it. The value is in the chain, not the individual finding. A low severity information disclosure combined with a weak password policy and an over privileged service account is how real breaches happen, and no automated tool will tell you that story.

It is worth being clear about what a penetration test is not, because a lot of the market sells one thing and delivers another. It is not a vulnerability scan. A scanner runs signature checks against known software versions and produces a list of possible issues, many of which are false positives and none of which are validated by a human. Scans are useful, they are cheap, and you should run them continuously. They are not a penetration test, and an auditor who knows the difference will notice.

It is also not a substitute for secure development. A test tells you the state of your systems on the days it ran. If you ship weekly, the report starts ageing immediately. That is why we push clients toward annual testing plus retesting after significant change, rather than treating one report a year as the whole security programme.

Choosing the right scope

Scope is where most penetration test budgets are won or lost. Testing everything you own sounds thorough and is usually the wrong call, because effort gets spread so thin that nothing is examined properly. It is better to test the systems that actually carry risk and test them well.

For most software companies, the highest value scope is the production web application including its authenticated areas, the API behind it, and the cloud infrastructure it runs on. Authenticated testing matters enormously here. A test that only probes your login page from outside will find very little, because the interesting flaws in modern applications are almost always authorisation problems that only appear once you have a valid session. We ask for test accounts at several privilege levels precisely so we can check whether a standard user can reach data belonging to another tenant.

External network testing is worth including if you run your own infrastructure or have a meaningful public IP footprint. If you are entirely serverless or platform hosted, that budget is usually better spent on application and cloud configuration testing instead. We will tell you honestly which applies to you rather than selling the larger scope.

How findings are rated, and why that matters

Every finding we report carries a severity rating based on realistic impact in your environment, not a raw CVSS score copied from a database. CVSS is a useful common language but it is context free. A vulnerability rated high in the abstract may be genuinely low risk on a system with no sensitive data and no network path to anything that does, and a medium rated issue may be critical if it exposes your customer database.

We rate findings the way we would want them rated if we had to fix them: by what an attacker actually gains, how hard it is to exploit in practice, and what it is connected to. Each finding includes reproduction steps precise enough for an engineer to confirm the issue themselves, because a report your team cannot verify is a report your team will not act on.

Engagement process

How the work actually happens.

01

Scoping & rules of engagement

We define in-scope assets, testing windows, and any systems that need extra care (production databases, payment flows) before a single packet is sent.

02

Active testing

Manual, practitioner-led testing runs over your agreed window, typically 3 to 10 days depending on scope, with a direct line to the tester if anything urgent surfaces.

03

Critical findings, same day

Anything exploitable and high-impact is flagged to you the same day we find it, not buried until the final report.

04

Report & readout

A full report plus a live readout call to walk through findings, business impact and remediation priority with your engineering team.

05

Remediation round and re-test

You get one round to apply fixes to the findings we raised. We then re-test those findings at no extra cost and issue the final report, which is the one you hand to a customer or auditor.

Included as standard

One remediation cycle is built into every engagement

After we deliver the initial report, you get one round to apply fixes to the findings we raised. We then re-test those findings and issue the final report reflecting your remediated state. That is the report you hand to a customer or auditor, so it shows what you fixed rather than what we found on day one.

What goes wrong

Common mistakes we are asked to fix.

Testing too late in the deal cycle

Booking a test the week a customer asks for a report leaves no time to remediate anything found. Aim to test at least six to eight weeks before you need a clean report in a customer's hands.

Excluding the authenticated application

Unauthenticated only testing is cheaper and finds far less. Most serious application flaws sit behind the login, in how the application decides what a logged in user is allowed to see.

Treating the report as the finish line

The report is the start of the work. Findings that sit unremediated for a year look considerably worse to an auditor than findings that were fixed and retested within a month.

Accepting a scan dressed up as a test

If a proposal is unusually cheap and the turnaround is a day or two, you are almost certainly buying an automated scan with a cover page. Ask how many days of manual testing are included and who performs them.

Timelines

Timing and what to expect

A typical engagement runs three to ten days of active testing depending on scope, with the report delivered within five business days of testing ending. Add a week at the start for scoping and rules of engagement, and budget time after delivery for your engineering team to remediate before the retest. From first call to final retested report, a straightforward engagement usually takes six to eight weeks end to end. If you are working to a customer deadline, tell us the date at the first conversation and we will tell you honestly whether it is achievable rather than discovering the problem halfway through.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Offer

Your first year of service is free

Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →

Common questions

Frequently asked questions

How often do we need a penetration test for SOC 2 or ISO 27001?

Most organisations run an annual penetration test to satisfy SOC 2 CC7.1 and ISO 27001 Annex A.8.8, plus after any significant infrastructure change. We'll flag if your specific auditor or customer expects more frequent testing.

Is this an automated scan or manual testing?

Manual, practitioner-led testing. We use tooling to accelerate reconnaissance, but every finding is manually validated, no unvalidated scanner output padding the report.

Will testing disrupt our production systems?

We agree a rules-of-engagement document upfront covering safe testing windows, rate limits and any systems to exclude or test only in staging.

Can you test before we're fully ISO 27001 or SOC 2 ready?

Yes. A pentest is a standalone technical service and doesn't require any other framework work in progress. Many clients start here specifically to answer a customer security questionnaire.

Who performs the test?

A UK, US or EU-based penetration tester on our team, never a subcontracted or offshore resource.

What is the difference between a penetration test and a vulnerability scan?

A scan is automated and checks for known issues against signatures, producing unvalidated results including false positives. A penetration test is performed manually by a tester who validates each issue, chains findings together, and explains real business impact. Scans are useful continuously; tests are what auditors and enterprise customers ask for.

Do you need access to our source code?

Not necessarily. Black box testing works without code access and reflects an external attacker's view. Grey box testing, where we get documentation and test credentials, generally finds more for the same budget because time is not spent rediscovering how your application is structured. We will recommend the approach that suits your goal.

What do you need from us before testing starts?

Test accounts at each privilege level, a list of in scope hosts and applications, any systems that must be excluded, a technical contact who can be reached during testing, and written authorisation from someone empowered to give it. If you are hosted with a third party, we will let you know whether they need advance notice.

Will the report satisfy our customer's security questionnaire?

In most cases yes. Reports include an executive summary suitable to share externally alongside the detailed technical findings, which are usually kept internal. If a customer requires a specific format or an attestation letter, tell us during scoping and we will accommodate it.

What happens if you find something critical mid test?

We stop and tell you the same day rather than saving it for the report. If a finding suggests an active compromise rather than a theoretical weakness, we will escalate immediately and pause testing while you respond.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call