Penetration testing
Simulated attacks against your live environment
- External and internal network testing
- Web and mobile application testing
- API and authentication logic testing
- Social engineering on request
Home / Services
Six services covering the full surface — offensive testing to uncover flaws, defensive coverage to keep them out. Every engagement ends with a report your engineers can act on and a free retest.
Simulated attacks against your live environment
Breadth-first discovery across your estate
Stop information leaving before it does damage
Defeat advanced and evasive payloads
Harden the perimeter and everything behind it
Secure what you run on AWS, Azure and GCP
Emergency response when your files are encrypted
These are not add-ons or upsells. They come with every service we run.
Agreed in writing before any testing starts, including windows and escalation contacts.
Reproducible evidence for every finding, captured safely without exfiltrating your data.
A board-ready overview alongside the technical detail your engineers need.
We verify your patches closed the gap and reissue the report at no extra cost.
Indicative timelines and coverage. Exact scope and duration are confirmed in writing before any testing begins.
| Engagement | Typical duration | Coverage | Deliverable |
|---|---|---|---|
| External network test | 3–5 days | Perimeter hosts, exposed services, VPN and mail gateways, DNS configuration | Findings report + executive summary + free retest |
| Internal network test | 5–8 days | Active Directory, segmentation, lateral movement, privilege escalation paths | Attack path diagram + prioritised remediation plan |
| Web application test | 4–7 days | OWASP Top 10, business logic, authentication and session handling, access control | Per-finding proof of concept + developer fix guidance |
| API / GraphQL test | 3–5 days | Authorisation flaws, rate limiting, injection, schema introspection, mass assignment | Annotated request/response evidence |
| Cloud configuration review | 3–6 days | IAM policies, storage exposure, network controls, logging, container workloads | Benchmark-mapped findings + hardening checklist |
| Emergency incident response | Immediate, 24/7 | Containment, entry-point identification, eradication, service restoration | Incident timeline + root cause + hardening actions |
Ransomware, defaced pages, crypto-mining scripts, spam sent from your domain, customer data dumped online, or admin access you have lost — tell us what happened and our response team moves at once. We contain the attacker, close the entry point, remove the malicious code and restore your services within hours, then tell you exactly how they got in.
Tell us what you'd like tested and we'll scope an engagement — with a fixed price agreed in writing and a free retest once you've shipped the fixes.
Request an assessmentTell us what you need secured. An engineer — not a salesperson — replies within one business day.