Don't assume. Test.

Don't assume your security works. Prove it.

Independent Cyber Essentials, Cyber Essentials Plus and penetration testing for UK businesses. Find the weaknesses before an attacker does, with fixed-price scoping and plain-English reports.

Not sure what you need? Tell us what you're trying to achieve and we'll tell you which level makes sense.

Senior, hands-on testing Plain-English reporting Report in 5 working days No surprise costs
Senior, hands-on testing NCSC-recognised testing standards UK-based testers Fixed-price scoping Plain-English reports
What we do

Prove the basics. Then test the rest.

Get certified to show customers you take the basics seriously, then test properly to find what a determined attacker would.

Certification

Cyber Essentials & Cyber Essentials Plus

The UK government-backed scheme that covers the five controls stopping the majority of common attacks. We get you assessment-ready, then certify, without the jargon.

  • Gap review against the current scheme
  • Hands-on help closing the gaps
  • Certification, including the hands-on Plus audit
How certification works →
Penetration test

External infrastructure

Everything an attacker can reach from the internet (your perimeter, exposed services, VPNs and cloud edges), probed the way a real adversary would.

What's covered →
Penetration test

Internal infrastructure

We model the breached laptop or rogue insider, then see how far that foothold spreads across your network, servers and Active Directory.

What's covered →
Penetration test

Web application

Authenticated, role-aware testing of your apps and APIs against the OWASP Top 10 and the logic flaws scanners simply never find.

What's covered →
What a test actually does

One ordinary account. Watch how far it goes.

A scanner hands you a list of issues. A penetration test shows you the story an attacker would tell: start with a single compromised user, and see how quickly that becomes control of everything.

This is exactly what an internal infrastructure test models. The path below is illustrative, not a real client, but every step is one we see in the wild.

See how internal testing works
  1. 01 · Initial access

    One employee's password, phished and reused elsewhere. We're in as a normal user, with nothing that looks out of place.

  2. 02 · Credential discovery

    That user can open a file share they shouldn't. Inside is a setup script with an administrator password saved in plain text.

  3. 03 · Privilege escalation

    The password unlocks a server. We're no longer an ordinary user; we're a local administrator with room to work.

  4. 04 · Lateral movement

    From that server we reach others, collecting credentials as we go, quietly spreading across the network.

  5. 05 · Domain administrator

    One of those credentials owns the domain: every account, every machine, every file. Game over.

    DOMAIN ADMIN
A clear progression

Start where you are. Prove more as you go.

Most clients begin with certification and climb as their needs grow. Each step proves something the one before it couldn't.

  1. Step 01

    Cyber Essentials

    Are the basic controls in place?

    Self-assessment, verified by us. The credential customers, insurers and tenders increasingly expect.

  2. Step 02

    Cyber Essentials Plus

    Do those controls survive independent testing?

    A hands-on audit of the same controls, checked from outside your team rather than taken on trust.

  3. Step 03

    Penetration testing

    What could an attacker actually do?

    External, internal and web application testing that goes looking for the way in, not just a list of theoretical issues.

  4. Step 04

    Annual testing

    Are you still secure as things change?

    Regular retesting, so new gaps surface on your schedule instead of an attacker's.

Not sure which step fits? Let's work it out

A frictionless engagement

The test should be the easy part.

Security work has a reputation for being slow, opaque and full of surprises. We've built ours to be the opposite: clear scope, a fixed price up front, and a report you can actually act on.

A single point of contact runs your engagement end to end, so you're never re-explaining your environment to a stranger.

Start with a free scoping call
  1. Scope

    A short call to understand your environment. You leave with a fixed price and a clear plan, no obligation.

  2. Schedule

    We agree dates that suit you, including out of hours, and confirm exactly what's in and out of scope in writing.

  3. Test

    An experienced tester runs the assessment, keeping you posted and flagging anything critical the moment it's found.

  4. Report

    A plain-English report: an exec summary anyone can follow, plus prioritised, reproducible findings and fixes for your engineers.

  5. Aftercare

    We walk you through the findings, answer your team's questions, and re-test the fixes, at no extra cost.

Independence

Your IT team shouldn't have to mark their own homework.

They work hard to keep you secure, and that's exactly why the check should come from outside. Independent testing isn't a challenge to your team, it's how you prove the controls hold up. We test from the attacker's side, so a pass actually means something.

Credentials you can verify

Independently accredited, and certified ourselves.

Our lead tester is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing. And we hold ourselves to the same bar we set for clients: we're Cyber Essentials Plus and IASME Cyber Assurance certified. Tap a badge to check the live certificate.

Why teams choose us

Senior testing, none of the friction.

100%
Engagements led by an experienced senior tester
48h
From scoping call to a fixed-price quote
5 days
Typical turnaround for your final report
£0
For remediation re-tests and aftercare
Common questions

Good to know.

What's the difference between Cyber Essentials and a penetration test?

Cyber Essentials certifies that you have five fundamental controls in place: it's a baseline and a trust signal for customers and tenders. A penetration test goes much further: a qualified tester actively tries to break in, the way a real attacker would, and tells you exactly what they found. Most organisations benefit from both.

Who actually carries out the testing?

An experienced, senior tester runs your engagement from scoping to report, with no hand-off to a junior halfway through. Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards; web application testing follows the OWASP methodology. The point isn't the badges: it's that the work is done thoroughly and by hand, not left to a scanner.

Do you cover both internal and external infrastructure?

Yes. External testing looks at everything reachable from the internet; internal testing assumes an attacker already has a foothold and measures how far it spreads. They answer different questions, and many engagements include both alongside a web application test.

How long does it take, and will it disrupt us?

Most tests run over a few days and can be scheduled out of hours. We agree the rules of engagement in writing first, work to a careful methodology, and stay in contact throughout, so there are no surprises for your team.

Is the price really fixed?

Once we've scoped the work, the quote is fixed. Remediation re-tests and the post-report walkthrough are included. If the scope genuinely changes, we'll talk it through before any cost does.

Get a quote

Tell us what you're protecting.

A couple of details is all we need to get started. We'll come back within one working day with next steps, usually a short, no-obligation scoping call.