Certification to prove the basics. Testing to prove the rest.
Every engagement is scoped to a fixed price, run by an experienced senior tester, and reported in plain English your whole team can act on.
Cyber Essentials & Cyber Essentials Plus
The UK government-backed scheme covering the five technical controls that stop the large majority of common internet-based attacks. It's the credential customers, insurers and public-sector tenders increasingly expect.
You complete the verified self-assessment questionnaire and we review your responses for gaps against the standard, giving you the chance to remediate anything that falls short. As a Cyber Essentials Certification Body we certify you and issue the certificate ourselves. Cyber Essentials Plus adds the hands-on technical audit of those same controls.
We hold it ourselves, too: Plainsight Security is Cyber Essentials Plus and IASME Cyber Assurance certified.
Cyber Essentials in detail → Cyber Essentials Plus in detail →
What's assessed
- Firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Security update management
Cyber Essentials is self-assessment verified by us; Cyber Essentials Plus adds an independent hands-on test of those same controls.
What we look at
- Public IP ranges and exposed services
- Web, mail and VPN gateways
- Cloud edges and forgotten assets
- Patch levels and misconfigurations
- Credential exposure and weak authentication
External infrastructure
Everything an attacker can reach from the internet, tested the way a real adversary works, not just scanned.
We enumerate your internet-facing footprint, hunt for the exposures automated tools miss, and safely demonstrate real impact where we find a way in. You get a clear picture of your perimeter and a prioritised list of what to fix first.
Hands-on, manual testing to a recognised methodology, not just an automated scan.
Internal infrastructure
If an attacker got a foothold (a phished laptop, a rogue insider), how far could they go? Internal testing answers that.
Working from inside your network, we map what's reachable and methodically escalate: lateral movement, privilege escalation, and the Active Directory weaknesses that turn one compromised machine into domain-wide control. The report shows the chain step by step, so the fixes are obvious.
Methodical, manual testing that maps the full attack path, not just a vulnerability list.
What we look at
- Network segmentation and reachable services
- Active Directory and identity weaknesses
- Privilege escalation paths
- Lateral movement and credential reuse
- Server, workstation and patch hygiene
What we look at
- OWASP Top 10 and beyond
- Authentication, sessions and access control
- Business-logic and authorisation flaws
- APIs and integrations
- Injection, SSRF, and data exposure
Web application
Authenticated, role-aware testing of your apps and APIs, including the logic flaws a scanner will never understand.
We test as different user roles to find broken access controls, probe your business logic, and chain issues into real-world attack scenarios. Findings come with reproduction steps your developers can follow and fixes mapped to your stack.
Hands-on, methodology-led testing aligned to the OWASP standards, not just an automated scan.
Vulnerability scanning
Routine internal and external scanning with professionally reviewed reports that show your security posture improving over time.
Delivered as Plainsight Security Pulse on a simple twelve-month plan: we scan on the schedule you choose, monthly, quarterly or six-monthly, and compare every report against the last. Fixed price for the agreed scope, from £50 per month + VAT.
It complements certification and testing rather than replacing them. Certify the basics, test in depth once a year, and keep watch in between.
What we scan
- External internet-facing services
- Internal hosts via a lightweight agent
- Missing patches and security updates
- Insecure configuration
- Known vulnerabilities across the estate
Scanning finds and tracks known issues on a schedule; a penetration test goes hands-on to prove exploitability.
Many teams combine all three.
External, internal and web app testing answer different questions, and together they give the fullest picture. Tell us your environment and we'll recommend the right scope, not the biggest one.