01 / PENETRATION TESTING

How far could an attacker
get?

A penetration test explores how weaknesses could be used in an attack. We agree the objectives and boundaries, test selected attack paths and explain what the findings mean for your business.

Request a quote
SUITABLE FOR

For businesses that want to investigate risk in selected systems, before a major launch or as part of planned security work.

01 / SCOPE AND DELIVERABLES

From insight to action.

01

A clear testing mandate

Systems, objectives, timing and permitted methods are agreed in writing before testing begins. Testing only covers systems you are authorised to have tested.

02

Testing attack paths

Selected weaknesses are examined together to assess whether they could allow unauthorised access or other consequences. Depth and methods follow the agreed scope.

03

Findings that mean something

Reporting explains what was tested, which findings were confirmed and what they could mean for information and operations. The level of documentation is agreed in advance.

04

A basis for remediation

Priorities and recommended actions make the results useful for IT and management. Retesting after remediation can be agreed separately.

Scope, deliverables and pricing are tailored to the engagement. A penetration test is a snapshot within defined boundaries and cannot reveal every possible attack path.

HOW WE GET STARTED

01

Define the scope

We agree which systems, attack scenarios and testing methods the engagement will cover.

02

Test

Testing follows the mandate, with agreed contact points and stop conditions.

03

Prioritise

Findings inform practical actions. Follow-up and any retesting are agreed together.

02 / REGULATIONS AND DOCUMENTATION

Supporting your security work.

See requirements and scope

Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.

Risk-appropriate requirements

GDPR / privacy

Test findings can help assess whether technical security measures adequately protect personal data.

GDPR, including Article 32
Requirements for entities in scope

DORA

An agreed penetration test may form part of a risk-based testing programme. This service is not offered as DORA TLPT.

DORA: testing and training
A standard, not a separate law

ISO/IEC 27001

Findings and follow-up can inform the organisation’s risk treatment and improvement work.

ISO on the standard

Useful to know before we start.

How is this different from a vulnerability assessment?

A vulnerability assessment provides a broader view of technical weaknesses and may include controlled testing of selected findings. A penetration test puts greater emphasis on specific attack paths, connections and consequences. The agreed scope determines the depth.

Can production systems be tested?

This is assessed for each engagement. The testing window, system load, contingency arrangements and limits on active testing must be agreed, particularly for systems essential to operations.

Is this a DORA TLPT test?

An ordinary penetration test is not a threat-led penetration test under DORA’s specific TLPT framework. TLPT applies to designated entities and has separate requirements for testing and testers.

NEXT STEP / A NO-OBLIGATION CONVERSATION

Discuss your penetration test

What would you like to test, and what do you want to learn? Do not include passwords or sensitive system details here.

We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.

How can we help?

Choose a service and tell us a little about your needs.

I would like

Opens your email app with a draft to Eddie. Review it and send it yourself. This form does not store your details.