Penetration testing
Find out what an attacker could actually reach, before one does.
A penetration test is an authorised, human-led attempt to exploit the weaknesses in your systems and show what they really expose. Done to a standard, it is also the evidence a SOC 2, ISO 27001, or PCI DSS auditor asks for.
How an engagement runs
A test is only worth trusting if it is bounded, repeatable, and honest about its limits. That shapes how each one is run.
Authorised and human-led
Every engagement starts with a signed scope, rules of engagement, and written authorisation. The testing itself is done by a person attempting to exploit real weaknesses, not an automated scan, and the report shows the manual path taken rather than a tool dump.
Scoped to a recognised standard
External network and web-application testing, run against PTES and NIST SP 800-115, with web coverage tracked to the OWASP testing guide and its verification standard. Coverage is recorded so the report can show what was tested and what was not.
Findings you can act on
Each issue is rated with CVSS, described with the exact steps to reproduce it, and paired with a specific fix. Counts by severity appear up front, and a remediation order tells you what to do this week versus what can wait.
Closed with a retest
The engagement is not finished at the report. Once the fixes are in, the original attack path is tested again to confirm it is actually closed, and the retest is documented next to the original finding.
What is in scope, stated plainly
The work is external and web-facing. Saying what a test does not cover matters as much as saying what it does, because a report is only as honest as its limits.
What this covers
- External network testing of your internet-facing systems
- Web application and API testing, authenticated where roles are provided
- Exploitation to prove real impact, within agreed limits
- A written report and an independent retest of the fixes
What it does not cover
- Internal network and Active Directory testing, which needs a device inside your network
- Wireless and on-site physical testing
- Anything outside the signed scope, an out-of-scope system found in range is reported, not tested
Independence, stated honestly
A penetration test carries weight only when the tester does not run the systems being tested. That rule shapes who we can independently assess.
If we do not manage it
You get an independent test, the kind an auditor accepts as external assurance.
If we do manage it
The report says so on the first page and is read as internal diligence, or we bring in an independent tester. An assessment of something we are connected to is not third-party assurance, and pretending otherwise helps no one.
Scope a test.
Tell us what is in scope and what you need it for. You get a fixed scope and a written quote before anything starts, and the report is yours regardless of what happens next.