Penetration testing with named testers, not a black box
Penetration testing delivered by the same senior consultants from scoping call to retest. Daily updates, one-hour critical escalation, and a retest included.
Test types we cover
External network
Black-box and grey-box testing of your internet-facing perimeter — firewalls, VPNs, remote services, and exposed APIs.
Web application
OWASP Top 10 coverage with authenticated role-based testing, business logic abuse, and client-side attack chains.
Internal network
Simulated insider and assumed-breach scenarios across Active Directory, cloud workloads, and flat network segments.
Cloud configuration
IAM, network, and workload review across AWS, Azure, and GCP, mapped to CIS Benchmarks and provider guidance.
API & mobile
REST/GraphQL API fuzzing, token and session abuse, plus iOS and Android app testing including runtime inspection.
Red team & phishing
Objective-led engagements against detection and response, with optional social engineering and phishing payloads.
Sanitized sample report
See exactly what your report will look like. We send a redacted external-network and web-application report — CVSS scoring, reproduction steps, and remediation guidance included — in exchange for a work email.
Available sample reports
Pick the report closest to your scope and we will send a sanitized copy to your work email.
Sample Report
TESTing IV
Our methodology
- 1
Scoping
We run a 30-minute scoping call, issue a fixed-fee proposal, and sign an MSA + rules of engagement.
- 2
Kick-off
Named lead tester introduces themselves, confirms scope, targets, and comms channels, and agrees testing windows.
- 3
Testing
Daily stand-ups, a live findings channel, and critical-issue escalation inside one hour of discovery.
- 4
Reporting
Draft report within five working days of test end, including executive summary, CVSS-scored findings, and reproduction steps.
- 5
Retest
Free retest of all High and Critical findings within 90 days, with an updated attestation letter.
Frequently asked questions
Can I see a sample pen test report before I buy?
Yes. Request a sanitized sample report using the form below — we will share a redacted external-network and web-application report so you can see our writing, CVSS scoring, and remediation detail before committing.
How long does a penetration test take?
A typical SME external + web-app test runs 5–10 working days end-to-end, with a further 5 working days for reporting. Larger or red team engagements run 3–6 weeks.
How much does a penetration test cost?
Most SME engagements land between $7,500 and $22,500 depending on scope and test type. We issue a fixed-fee proposal after a 30-minute scoping call.
What happens if a critical issue is found mid-test?
We escalate Critical and High findings through an agreed comms channel within one hour of discovery, with enough detail for your team to triage immediately — you do not have to wait for the report.
Do you offer a retest?
Yes. A retest of all High and Critical findings is included within 90 days of the final report, with an updated attestation letter for customers, auditors, and insurers.
Book a 30-minute scoping call
Fixed-fee proposal within 48 hours. Named lead tester, and a free retest of High and Critical findings within 90 days.
Book a scoping callRelated insights and breach analysis
Recent reporting and incidents that connect to this service.
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- Breach reportSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]
2026-09-20
- Breach reportAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
2026-09-18
- Breach report23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
2026-09-18