EXPERTISE / PEN
Penetration testing
Show how far an authorised attack scenario can progress and what needs remediation or better detection.

WHAT TO ADDRESS
Choose the right engagement.
No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.
9 results
PEN-01 / Penetration testing
External penetration testing
An authorised simulation of an internet-based attacker to assess whether exposed services allow unauthorised access or actions.
PEN-02 / Penetration testing
Internal and assumed-breach penetration testing
An assessment of what an attacker could reach after gaining an initial internal foothold, examining excessive privileges and weak separation.
PEN-03 / Penetration testing
Web application penetration testing
Testing browser-based applications for weaknesses, particularly in authentication, authorisation and business workflows.
PEN-04 / Penetration testing
API penetration testing
Testing the interfaces applications use to exchange data, with particular attention to object-level permissions and abusive usage.
PEN-05 / Penetration testing
Mobile application security testing
Assessment of an Android or iOS application and its communications to identify exposed data and inadequate security controls.
PEN-06 / Penetration testing
Wireless security testing
Assessment of wireless networks, authentication and separation to reduce unauthorised access near company premises.
PEN-07 / Penetration testing
Cloud and IAM penetration testing
Controlled testing of abuse scenarios in a cloud environment, beyond configuration review alone.
PEN-08 / Penetration testing
Objective-based red team exercise
A coordinated adversary simulation to exercise prevention, detection and response against a defined business objective.
PEN-09 / Penetration testing
Purple teaming and control validation
Joint work between testers and defenders to verify that simulated malicious behaviour produces the expected signals and responses.
No matching results. Try a broader term or another family.
SET THE BOUNDARIES
What we agree
before we start.
- Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.
- Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.
Technology names in service descriptions are implementation examples, not claims of partnership or licence entitlement.
START A CONVERSATION
Let’s put the next step in focus.
Tell us what you need to protect, change or understand. We will start with the scope, not a product list.
