Our Services
Which service do you need?
Most organisations do not need all four. They need the right one, scoped properly. Here is how to tell which applies.
Start with an external infrastructure test if…
You are testing for the first time, a customer questionnaire or insurer prompted this, or you simply want to know what someone on the internet can reach. It is the least expensive place to begin at £500, and it routinely finds assets nobody remembered were exposed. For most first-time buyers, this is the correct purchase.
Start with an application test if…
You built or operate software that customers log into. Your data lives in the application, not the network, and no generic control protects it. If an enterprise customer is asking about security, the application is almost always what they mean. From £1,000.
Start with a cloud configuration review if…
Most of what you run is Microsoft 365, Azure or AWS rather than servers you own. Cloud environments fail through misconfiguration — over-permissive roles, gaps in conditional access, public storage — and none of that is visible to a network test. £1,500 for a one-time baseline.
Add managed vulnerability scanning if…
You have tested once and want the eleven months in between covered. Serious vulnerabilities are disclosed weekly; an annual test cannot see them. From £1,000 a year, this is the cheapest continuous security spend on this page.
Comparing the services
| Service | Answers | Cadence | From |
|---|---|---|---|
| Infrastructure testing | What can an attacker reach and exploit, outside and inside your network? | Annual | £500 |
| Application testing | Can a user reach data or functions they should not? | Annual, or after major change | £1,000 |
| Cloud configuration review | Is our cloud configured securely against benchmarks? | One-time or ongoing | £1,500 |
| Managed vulnerability scanning | What new weaknesses appeared this month? | Monthly or quarterly | £1,000/yr |
What every engagement includes
Whichever service you choose, these are standard rather than upsells:
- An executive summary written for people who do not work in security, and a technical summary for the people doing the remediation
- Detailed findings with severity, evidence, reproduction steps and specific remediation advice — the setting to change, not the principle to consider
- Severity rated in your context, not by generic score. A medium on your internet-facing VPN may matter more than a high on an isolated test box
- Immediate disclosure of anything critical. If we find something serious on day one, you hear on day one
- Remediation support from the people who did the work, while you fix it
- Re-testing and a reissued report on penetration testing engagements, so you can show a customer or auditor issues resolved rather than identified
On accreditation, honestly
If your procurement process or insurer requires a CREST or NCSC CHECK accredited provider, check that before shortlisting anyone — it decides the outcome before price or quality enter the conversation, and it will save you time.
If you have no such requirement, and many organisations buying their first test do not, then judge providers as you would any technical supplier. Ask what proportion of the work is manual. Ask to see a redacted sample report. Ask who is actually doing the testing. Those answers tell you more about what you will receive than any badge does.
Not sure which you need?
Describe what you are running and we will tell you what we would test, in what order, and what it would cost. If our honest answer is that you should spend the money somewhere else first, that is the answer you will get. Our full price list is published in the UK penetration testing cost guide.
Simple Steps to Schedule Your Penetration Test
Ready to secure your organization? Here’s how to get started:
1. Contact Us – Reach out to our team to express your interest.
2. Scoping Call or Email – We’ll discuss your goals and requirements to define the best approach.
3. Our Proposal – Receive a tailored proposal based on your needs.
4. Delivery – Once you approve, we’ll deliver.
Our Services
Challenge Your Defences, Fortify Your Business.
Contact Us Now
We are happy to discuss your challenges and our solutions.