Cybersecurity

Penetration testing across your whole stack

A penetration test answers one question a scanner cannot: given this system as it is deployed today, what can a motivated attacker actually achieve? Not what is theoretically vulnerable — what chains together into real access.

That requires a human. Automated tooling finds known signatures; it does not reason about broken authorisation between two endpoints, or notice that a low-severity information leak hands over the key to a high-severity one.

What the engagement includes

  • Web application testing aligned to the OWASP Testing Guide
  • API testing including broken object-level authorisation and mass assignment
  • Mobile application testing for Android and iOS, including local storage and transport
  • External and internal network penetration testing
  • Cloud configuration and privilege-escalation path testing across AWS, Azure and GCP
  • Attack chains documented end to end, not just isolated findings
  • Remediation guidance and a free retest of fixed issues

Who this is for

Product teams shipping a new platform, organisations under customer or regulatory testing obligations, and any business that has never had an independent adversarial review.

How it runs

Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →

How the engagement runs

Five stages, with indicative timing. Exact dates are confirmed at scoping.

  1. 01
    Scope & rules

    Assets, depth, exclusions and an emergency stop contact agreed. Authorisation signed by the system owner.

    Week 0
  2. 02
    Reconnaissance

    Mapping the real attack surface: hosts, endpoints, authentication flows, and the assets you forgot existed.

    Days 1–2
  3. 03
    Exploitation

    Manual testing to the OWASP Testing Guide and equivalent network methodology. Business logic included.

    Days 2–6
  4. 04
    Chain & escalate

    Individual findings combined into realistic attack paths — the part that turns "medium" into "critical".

    Days 6–8
  5. 05
    Report & retest

    Attack chains documented end to end, remediation written for developers, retest included.

    Days 8–10

Questions we get asked

Grey box is usually the best value: we start with the access a real user would have. Pure black box spends budget on reconnaissance you already have answers to. White box suits code-level assurance on a critical component.
Annually as a baseline, and after any significant architectural change, new external-facing feature, or acquisition. Continuous exposure change is better handled by attack surface management between tests.
Yes, with written authorisation from the system owner, which is part of our engagement paperwork. We do not test any asset without it, and we verify you have the authority to authorise third-party hosted systems.

Every engagement starts free.

We assess your environment first, then scope. No commitment until you have seen how we work.