Cyber Security

Penetration Testing

A larger customer or an auditor often wants proof of where you stand before they trust you with their data. We test what an attacker would actually find, and write it up for the people who have to fix it rather than for other testers.

What this protects

Knowing where you actually stand

A clean external scan flatters everyone. Testing tells you which weaknesses lead somewhere, before an attacker finds out for you.

Customer and contract confidence

A test report is increasingly what a larger customer asks for before awarding work or granting access to their systems.

Insurance and frameworks

Cyber insurance, Cyber Essentials Plus and public sector contracts expect evidence. A written, prioritised report is that evidence.

Budget spent where it matters

A priority order sends the money to the weaknesses that can actually be exploited, rather than the longest list of findings.

What testing is, and is not

Penetration testing is a structured attempt to exploit your systems, carried out with your written permission and against a defined scope. It is not a vulnerability scan with a better name. A scan produces a list of theoretical weaknesses; a test establishes which of them actually lead somewhere.

The report is where most providers lose the plot. A hundred pages of CVSS scores is technically thorough and practically useless. You get a prioritised list in plain English: what to fix first, why it matters, how long it should take.

We will also tell you when something is not worth fixing. Not every finding deserves budget, and a tester who recommends remediating everything is not helping you make decisions.

Testing we carry out

External testing

What an attacker on the internet can reach: exposed services, remote access, and your public footprint.

Internal testing

What someone with network access can do, including escalation from a standard user account.

Web application testing

Testing of your own applications for injection, authentication and access control flaws.

Cloud configuration review

Microsoft 365 and Azure tenancy review for the misconfigurations that testing rarely reaches.

Social engineering

Optional, and only where it genuinely adds insight. Usually the email route is more revealing than the phone call.

Retesting

A follow-up pass to confirm the fixes actually closed the findings, so you have written evidence of closure.

How we run an engagement

  • Scoping call to agree boundaries, exclusions and what success looks like
  • Written authorisation and rules of engagement before anything is tested
  • Testing carried out in a defined window, with a named contact available throughout
  • Immediate notification of anything critical, rather than waiting for the report
  • Findings explained in a debrief, with time for your team to ask awkward questions
  • A retest once remediation is complete, with a closing statement you can hand to a customer or auditor

Questions we get asked about Penetration Testing

Annually at minimum for most businesses. More often if you have changed significantly, launched a public-facing service, or if a customer contract requires it.

Properly scoped testing should not. We agree windows in advance and avoid anything likely to cause instability. Denial-of-service style testing is explicitly out of scope unless you ask for it.

They answer different questions. Cyber Essentials tells a customer you meet a baseline. Testing tells you where you actually stand. Many organisations need both.

We tell you immediately, before the report exists. Anything critical gets a phone call the same day with a workaround, not a paragraph in a document next week.

A full penetration test is often overkill for a business of fifteen people. An external assessment and a tenancy review usually offers better value at that size, and we will say so rather than sell you the bigger engagement.

Not sure whether you need penetration testing?

Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.