Penetration testing · CREST · Fixed quotes
Find out beforesomeone else does.
Goal-driven testing that simulates real attackers rather than checklists. Our testers spend their other days in a SOC watching intrusions unfold, so they know which weaknesses get used. You get a plain-English report, a fix list for engineers and a retest when you are done.
CREST-certified testers£950 + VAT a dayOSSTMM · PTESMITRE ATT&CK · OWASPRetest included
A list of vulnerabilities is not the point. What an attacker could actually do with them is.
Many penetration tests stop at scanning and compliance. Ours combine detailed reconnaissance, manual exploitation and post-exploitation analysis to answer precise questions: how far could an attacker go, what data or systems are at risk, and which weaknesses must be fixed first. We deliver one-off tests, recurring programmes and scenario-based engagements, and we work with your engineers until the findings are closed.
- Methodologies
- OSSTMM · PTES · OWASP Testing Guide · OWASP API Top 10
- Mapping
- MITRE ATT&CK for every finding and attack path
- Testers
- CREST-certified testers only, who also work alongside the SOC
- Cadence
- One-off · Annual programmes · Continuous offensive assurance
Scopes
What we test
External infrastructure
Everything reachable from the internet — web servers, VPN gateways, mail, DNS and PKI, exposed admin interfaces and the forgotten test server — found with OSINT and certificate transparency, then exploited under controlled conditions.
Internal network and Active Directory
Assume the phishing email worked. From a standard user or an assumed-breach foothold we map credential reuse, Kerberoasting, ACL abuse and trust relationships to show how far an intruder could really spread.
Web applications
OWASP-aligned manual testing of authentication, access control, injection, business logic and the multi-role, multi-tenant edge cases that scanners cannot reason about.
APIs
REST, SOAP and GraphQL services tested for authentication and object-level authorisation, rate limiting, input handling and workflow abuse, from OpenAPI definitions or captured traffic.
Mobile applications
iOS and Android: local storage, transport security, session handling, reverse-engineering resistance and the backend APIs the app depends on.
Cloud and Microsoft 365
Azure, AWS, Microsoft 365 and hybrid identity reviewed for over-permissive roles, weak conditional access, sharing exposure and privilege-escalation paths.
Wireless and remote access
Corporate and guest Wi-Fi, 802.1X and PSK hygiene, rogue access point scenarios, VPN hardening, portal security and device-trust checks.
Red team and scenario-based
Objective-led engagements — reach the data, gain domain or cloud admin, move from outside to inside — that test people, process and detection together, with a purple-team debrief to tune your defences.
How it works
Scope, test, prove, fix, prove again
Stage 01
Scope
A thirty-minute call establishes what matters, what is in bounds, the rules of engagement and a fixed price.
Stage 02
Reconnaissance
Discovery of hosts, services, applications, roles and exposures using OSINT, DNS and certificate analysis, and mapping of the attack surface.
Stage 03
Exploit and validate
Targeted exploitation of identified weaknesses to establish real impact and eliminate false positives.
Stage 04
Chain
Attack-path analysis showing how issues combine — a weak VPN, an exposed console, a default credential — into a route to what you care about.
Stage 05
Report
An executive summary the board can read and a technical report with reproduction steps, evidence and a prioritised fix list, delivered within five working days.
Stage 06
Retest
Once you have fixed the findings, we confirm it. Included in the price.
Deliverables
What you receive from every engagement
- _01Executive summaryOverall posture, key risks and business impact in clear, accessible language.Board
- _02Detailed technical reportIssue descriptions, affected assets, reproduction steps, screenshots and references mapped to the relevant standards.Engineers
- _03Risk-based remediation planWhat to fix first and the control improvements that remove whole classes of finding.Plan
- _04Attack-path mappingDiagrams and narrative showing how findings chain into realistic attack scenarios.Evidence
- _05Debrief sessionsWalk-throughs with engineers and leadership; purple-team sessions after red-team work.Included
- _06Detection follow-throughFor SOC365 clients, findings feed straight into detections and watchlists so the same path cannot be used quietly later.SOC365
Common findings
What external tests usually turn up
Every environment is different, but some weaknesses recur. If you recognise yours, you already know where to start.
Outdated and unpatched services
Web servers, VPN appliances and middleware running software with known, exploitable vulnerabilities.
Misconfigured remote access
VPNs and portals with weak authentication, insufficient hardening or legacy protocols still enabled.
Exposed administrative interfaces
Management consoles and orchestrators reachable from the internet without adequate controls.
Information leakage via DNS and TLS
Subdomains and certificates revealing internal naming, technologies and forgotten systems.
Permissive firewalls
Unnecessary open ports, over-broad rules and inconsistent segmentation at the edge.
Shadow IT and legacy systems
Unmanaged or forgotten assets sitting outside the vulnerability-management process.
Estimate
Price it yourself, then we fix it
Tick what you want tested and the estimate builds from our published day rate. It is indicative: a thirty-minute scoping call confirms the days and turns it into a fixed price, which is the number you will pay.
Everything reachable from the internet: web and mail servers, VPN gateways, exposed admin interfaces and the forgotten test server.
Assume the phishing email worked: from a standard user we map how far an intruder could spread.
Remote via a small appliance or VPN; on-site days add travel at cost.
OWASP-aligned manual testing of authentication, access control, injection and business logic.
REST, SOAP or GraphQL, from an OpenAPI definition or captured traffic.
Local storage, transport security, session handling and reverse-engineering resistance.
Add the app's backend as an API item.
Azure, AWS, Google Cloud or Microsoft 365: roles, conditional access, sharing exposure and privilege-escalation paths.
Corporate and guest Wi-Fi, 802.1X and PSK hygiene, rogue access point scenarios.
On site; travel at cost.
A campaign against an agreed staff group, with a report on who clicked, who reported it and what to change.
A laptop image, a server template or a firewall configuration checked against hardening benchmarks.
Red team and scenario-based engagements, OT and ICS environments, and annual programmes are quoted separately after a call. Testing that needs someone on site adds travel at cost.
Pricing
How we quote
- _01One published day rate£950 + VAT a day. The number of days follows the scope — hosts, applications, roles, endpoints — and the estimate above shows how it adds up.£950 + VAT
- _02Fixed price, agreed up frontAfter the scoping call the days are fixed and so is the price, whatever we find.No surprises
- _03Retest includedConfirming your fixes is part of the job, not an extra line on the invoice.Included
- _04Programmes and retainersAnnual testing programmes and continuous offensive assurance run on a twelve-month retainer at 30% below the day rate, with the day rate for ad-hoc work.30% less
- _05Compliance-driven scopesPCI DSS, ISO 27001, Cyber Essentials Plus and insurer requirements shape the scope so the report answers the question being asked.Assurance
Questions
Will testing disrupt production?
Testing is scoped to avoid it, run at agreed times, and stopped the moment anything looks fragile. Our testers work alongside a SOC; they know what an outage costs.
How often should we test?
Annually as a minimum for most organisations, and after any significant change. Regulated firms and those handling card data usually need more; we will tell you what your regime expects.
Do you provide evidence for auditors and insurers?
Yes. The report is written with ISO 27001, PCI DSS and cyber-insurance questionnaires in mind, and we will speak to your auditor if it helps.
Can you test our SOC or MSSP as well as our systems?
Yes. Red-team and scenario engagements are designed to evaluate whether your detection and response actually works, whoever runs it — including us.
Start a conversation
Get a fixed quote this week.
Send us the rough scope — IP ranges, applications, objectives — and we will come back within one business day.