Skip to main content
1 TO 4 WEEKS

Penetration Testing

Find the paths an attacker would take, before they do

A penetration test goes beyond listing weaknesses. Findings are exploited in a controlled way and chained together to show how far an attacker could genuinely reach, so you get proof of impact rather than a scanner printout. Engagements follow PTES and OWASP methodology and cover external and internal networks, web applications and APIs, and Active Directory environments.

When you need this

  • A client, auditor, or insurer is asking for a recent penetration test report
  • You are pursuing ISO 27001, SOC 2, PCI DSS, or Cyber Essentials Plus
  • You are about to launch something and it has never been independently tested
  • It has been more than a year since anyone looked at your external perimeter

What is included

External network testing

Perimeter enumeration, exposed service exploitation, and initial foothold from the position of an internet-based attacker.

Internal network testing

Lateral movement, privilege escalation, and credential attacks from an assumed-breach or on-network starting point.

Active Directory attacks

Kerberoasting, AS-REP roasting, delegation abuse, ACL attacks, and full domain compromise paths.

Web application and API testing

Manual testing against the OWASP Top 10, covering authentication, access control, injection, and business logic flaws.

Privilege escalation

Windows and Linux escalation via service misconfiguration, token impersonation, SUID binaries, and kernel-level issues.

How the engagement runs

01

Scoping

Agree objectives, rules of engagement, in-scope targets, and testing windows in writing before anything starts.

02

Reconnaissance

Passive OSINT and active enumeration to map the full attack surface.

03

Exploitation

Controlled exploitation and chaining of findings to establish genuine impact.

04

Reporting

Written report, walkthrough call, and remediation guidance your engineers can act on.

What you receive

  • Detailed technical report with reproduction steps
  • CVSS-scored findings ranked by real business risk
  • Proof-of-concept evidence and screenshots
  • Executive summary written for non-technical readers
  • Prioritised remediation roadmap
  • Free re-test of fixed findings

Tooling

Burp SuiteNmapMetasploitBloodHoundCrackMapExecImpacketWinPEASSQLMap

Common questions

How much does a penetration test cost?

Cost depends on scope: the number of in-scope hosts or applications, whether testing is external, internal, or both, and how deep you want the assessment to go. Every engagement starts with a free scoping call that produces a fixed quote before any work begins, so you never receive an open-ended bill.

Will testing disrupt our production systems?

Testing is designed around availability. Denial-of-service testing is excluded by default, destructive actions are agreed in advance, and testing windows can be scheduled outside business hours. Rules of engagement are signed off before work starts and include an emergency contact and stop procedure.

What is the difference between this and a vulnerability assessment?

A vulnerability assessment identifies and catalogues weaknesses. A penetration test exploits them to prove real-world impact and shows how findings chain together into a full compromise. If you need coverage and a risk register, an assessment fits. If you need proof of what an attacker could actually achieve, you need a penetration test.

Do you provide a report we can share with clients or auditors?

Yes. Reports are written for two audiences at once: an executive summary an auditor, client, or board member can read directly, and technical detail with CVSS scoring and reproduction steps your engineers use to fix the issues.

Discuss a penetration testing engagement

Scoping conversations are free and produce a fixed quote before any work begins.

Get in touch

Other services