Service reference

Find your vulnerabilities before an attacker does

We go past the automated scan. You get the real risks in your infrastructure, your applications and your people, ranked and evidenced.

Clear scope · friendly support · practical advice

Last reviewed

The short version

Included as standard

Everything here is covered by the agreed fee. Anything outside it is quoted in advance.

  • External infrastructure penetration testing
  • Internal network penetration testing
  • Web application security testing
  • Microsoft 365 and cloud configuration review
  • Social engineering and phishing assessments
  • Wireless network security testing
  • Vulnerability assessment and prioritised remediation
  • Executive summary and technical reports

Gaps found in a test, not in a breach

Every business has vulnerabilities. The only question is how you find yours. A controlled assessment tells you on your terms. A breach tells you on the attacker’s.

Ransomware attacks on UK mid-market firms keep rising, and regulatory penalties keep climbing with them. A planned test is a far cheaper way to learn where you stand.

A penetration test gives you a picture of where your defences stand. Not the theoretical picture from a compliance checklist. The practical reality of what an attacker could achieve if they targeted you today.

What a penetration test covers

Our penetration testing in London covers your whole attack surface. We start outside, testing everything visible from the internet: your website, email gateway, VPN endpoints, cloud services and DNS. We look for the vulnerabilities that would give an attacker a way in.

Then we move inside. With a foothold on your network — a compromised laptop, or a phishing email that worked — we test how far that attacker gets. Can they escalate privileges? Reach your file shares? Open financial systems? Extract client data?

That internal stage matters most. Getting in is rarely the goal. What happens next decides the damage.

For web applications we test past the OWASP Top 10. Injection flaws, authentication bypasses, insecure direct object references and business logic faults are all in scope. If your application holds financial or client data, particularly for hedge funds and regulated firms, that testing is not optional.

What a pen test finds that a scanner cannot

Automated vulnerability scanners earn their place, and we run them on every engagement. They also miss the things a person finds.

Three low-severity issues chain into one critical attack path. A workflow behaves differently from the way it was designed. Two systems trust each other more than anyone intended. No scanner tests a social engineering route at all.

Our testers take the time to understand your environment, think like an attacker and follow the path of least resistance. The findings feed straight into our managed detection and response service, so your ongoing monitoring gets sharper too. That is the difference between a vulnerability assessment and a genuine penetration test.

Which penetration test you actually need

“Penetration testing” covers several different exercises with very different costs and outcomes. Buying the wrong one is the most common and most expensive mistake we see.

Test type What it answers Typical duration When you need it
External infrastructure What can an attacker reach from the internet? 2–4 days Annually; required for most cyber insurance
Internal infrastructure How far do they get once inside? 3–5 days Annually, or after any office/network change
Web application Can our app be abused or its data extracted? 3–10 days Before launch, then annually or after major releases
Cyber Essentials Plus Do we pass the certification’s technical audit? 1–2 days At certification and each renewal
Red team Would we actually detect a determined attacker? 3–6 weeks Once your controls are already mature
Vulnerability scan What known CVEs are exposed? Automated, continuous Monthly — this is not a pen test

The last row is where most confusion lives. A scan is a useful hygiene control and it is not a penetration test. If a supplier quotes a few hundred pounds for a “pen test”, that price buys automated scanning rather than tester time.

What penetration testing costs in the UK

Pricing follows scope and tester-days, not company size. Realistic 2026 UK market ranges:

  • External infrastructure test (up to ~30 live IPs): £2,000–£4,500
  • Internal infrastructure test (single site, ~100 hosts): £3,000–£6,500
  • Web application test (one authenticated app): £4,000–£12,000 depending on complexity and user roles
  • Cyber Essentials Plus technical audit: sampling-based, quoted by scope and device count
  • Red team engagement: £25,000+

Retesting after remediation should be included. If it is quoted as an extra, factor it in — a test you cannot afford to retest is a test whose findings never get closed.

CREST and CHECK accreditation, explained

The accreditation landscape is genuinely confusing, so here is what each badge tells you.

  • CREST — an industry body accrediting both companies and individual testers. The most widely recognised commercial standard in the UK, and what most cyber insurers and enterprise procurement teams look for.
  • CHECK — an NCSC scheme, required specifically for testing UK government and public-sector systems. If you are not touching government systems, you do not need CHECK.
  • OSCP / CREST CRT — individual tester certifications. Useful signals about the person doing the work, not about the firm.
  • “ISO 27001 certified” as a pen test credential — not a testing credential at all. It means the supplier has an information security management system, not that they can test yours.

Our testing is CREST-aligned and scoped to the same methodology. Ask any supplier — including us — who specifically will run your test and what they hold.

Prepare for your pen test and get more from the same spend

Firms that prepare get materially more out of the same budget:

  1. Decide what you are protecting. “Test everything” produces a shallow test of everything. “Prove an attacker cannot reach the client portfolio database” produces a useful one.
  2. Do the obvious patching first. Paying a senior tester day-rate to discover you have unpatched servers is poor value. Fix the known issues, then test for the unknown ones.
  3. Get written authorisation. Testing systems without documented sign-off from the asset owner is a legal problem. Cloud providers may need notification too.
  4. Warn the right people, not everyone. Your IT lead needs to know. If you tell the whole company, you are testing an alerted organisation, which is not the scenario you are worried about.
  5. Book the remediation window before the test. Findings without allocated engineering time become a report that ages in a drawer.
  6. Agree the escalation path. If we find something critical on day one, who do we call, and at what hour?

Closing the loop after the test

A penetration test earns its value in the remediation, not the report. We rank findings by exploitability and business impact rather than raw CVSS score. A medium-severity flaw on your client portal usually matters more than a high-severity one on an isolated print server.

Where a finding points at a systemic gap rather than a single misconfiguration, we say so. Repeated privilege-escalation paths usually point at your Active Directory design. Repeated web findings usually point at a development process with no security review in it.

Fix the finding without fixing the source and it returns at the next test. That is why our findings feed into managed detection and response and, where the root cause is a person rather than a system, into security awareness training.

A pen test report your board and your engineers can both use

Every pen test gives you two documents.

The executive summary runs to two or three pages. Your board and compliance team can read it in ten minutes and come away with the scope, the key findings, your overall risk position and what we recommend doing next.

The technical report carries every finding in full: what we found, how we exploited it, what an attacker could have done with it, and how to close it. The remediation steps are specific. Not “apply patches”, but instructions your IT team can follow.

Once you have remediated, we re-test every finding and send you an updated report showing the before and after state of each one.

DORA and Cyber Essentials Plus testing duties

For FCA-regulated firms, regular penetration testing meets the testing requirements under DORA’s digital operational resilience framework. We scope tests against those expectations and format the reports for your compliance and audit teams to submit directly.

Cyber Essentials Plus certification also requires an external vulnerability test. Our assessment covers it.

Last reviewed , and maintained by the Nerdster engineering team.

Tell us what would make IT easier

Share what is causing problems or taking up time. Our London team replies during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report

What you get from us

See a real attack, safely

Our testers use the techniques real attackers use. A scanner finds the obvious issues. A person finds the chained vulnerabilities and the logic flaws a scanner walks straight past.

Get findings you can act on

Every finding arrives with a severity rating, proof we exploited it, and the steps to close it, ordered so your team knows what to tackle first.

Fix it, then prove it is fixed

We work with your IT team to close what we find. Then we re-test each finding and show you the before and after state.

FAQ

Frequently asked questions

How often should we do a penetration test?

At minimum, annually. We recommend testing after any significant infrastructure change (cloud migration, new application deployment, office move) and more frequently for FCA-regulated firms where DORA mandates regular resilience testing.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment scans your systems and reports known vulnerabilities. A penetration test goes further by attempting to exploit those vulnerabilities to demonstrate real impact. It also tests for logic flaws, misconfigurations, and chained attack paths that scanners cannot identify.

Will the test disrupt our business?

We scope and schedule the test in advance, run the high-risk elements outside business hours, and stay in contact with your team throughout. Before we start we agree a stop condition and an escalation contact, so anything unexpected pauses the test rather than your business.

Do you test cloud environments?

Yes. We test Azure, AWS, and Microsoft 365 configurations including identity management, storage permissions, network security groups, and conditional access policies.

What do we receive after the test?

You get an executive summary suitable for board and compliance audiences, plus a detailed technical report with every finding, its severity, evidence of exploitation, and step-by-step remediation guidance. We also present findings in person and answer questions.