External testing
What an attacker on the internet can reach: exposed services, remote access, and your public footprint.
Cyber Security
A larger customer or an auditor often wants proof of where you stand before they trust you with their data. We test what an attacker would actually find, and write it up for the people who have to fix it rather than for other testers.
What this protects
A clean external scan flatters everyone. Testing tells you which weaknesses lead somewhere, before an attacker finds out for you.
A test report is increasingly what a larger customer asks for before awarding work or granting access to their systems.
Cyber insurance, Cyber Essentials Plus and public sector contracts expect evidence. A written, prioritised report is that evidence.
A priority order sends the money to the weaknesses that can actually be exploited, rather than the longest list of findings.
Penetration testing is a structured attempt to exploit your systems, carried out with your written permission and against a defined scope. It is not a vulnerability scan with a better name. A scan produces a list of theoretical weaknesses; a test establishes which of them actually lead somewhere.
The report is where most providers lose the plot. A hundred pages of CVSS scores is technically thorough and practically useless. You get a prioritised list in plain English: what to fix first, why it matters, how long it should take.
We will also tell you when something is not worth fixing. Not every finding deserves budget, and a tester who recommends remediating everything is not helping you make decisions.
What an attacker on the internet can reach: exposed services, remote access, and your public footprint.
What someone with network access can do, including escalation from a standard user account.
Testing of your own applications for injection, authentication and access control flaws.
Microsoft 365 and Azure tenancy review for the misconfigurations that testing rarely reaches.
Optional, and only where it genuinely adds insight. Usually the email route is more revealing than the phone call.
A follow-up pass to confirm the fixes actually closed the findings, so you have written evidence of closure.
Annually at minimum for most businesses. More often if you have changed significantly, launched a public-facing service, or if a customer contract requires it.
Properly scoped testing should not. We agree windows in advance and avoid anything likely to cause instability. Denial-of-service style testing is explicitly out of scope unless you ask for it.
They answer different questions. Cyber Essentials tells a customer you meet a baseline. Testing tells you where you actually stand. Many organisations need both.
We tell you immediately, before the report exists. Anything critical gets a phone call the same day with a workaround, not a paragraph in a document next week.
A full penetration test is often overkill for a business of fifteen people. An external assessment and a tenancy review usually offers better value at that size, and we will say so rather than sell you the bigger engagement.
Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.