Penetration Testing
Tool output is not a penetration test. We test manually, and we write findings that a board and an engineer can both act on.
Three tiers
| Tier | Method | Best suited to |
|---|---|---|
| Baseline | Tool-driven scanning with executive and technical reporting. | First review, annual compliance evidence. |
| Manual | Hands-on testing including business logic flaws, chained exploits and authenticated testing. | Payment, remittance and digital-asset platforms. |
| Advanced | Senior team, full attack chain, lateral movement, objective-based. | Listed companies, financial institutions, critical infrastructure. |
Frequently asked
How often should we test?
Annually at minimum, and after any material change to a customer-facing system.
Do you test production?
Usually yes, under a written rules-of-engagement agreement, with the option of a staging environment for destructive tests.
Consultancy fee refund commitment
If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.
Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.
Request a quotation
Tell us which standard or service you need. If you are not sure, tell us what the client or regulator is asking for and we will work it out.