Services
Security testing that earns its place on your risk register
CREST-accredited penetration testing of your infrastructure, applications and APIs, alongside threat simulation against your people and processes — scoped to your risk, not a template — with a remediation retest to confirm your fixes, free where the assessment size allows.
Penetration Testing
Hands-on, CREST-accredited testing of your infrastructure and applications.
Internal Infrastructure Testing
When an attacker gets past the perimeter — through phishing, a compromised laptop or a rogue device — how far can they go?
Learn more →
Active Directory Security Audit
Active Directory is the key to almost everything else you own, and in most organisations it has been quietly accumulating accounts, permissions and exceptions for a decade or more.
Learn more →
Active Directory Password Audit
Your password policy says fourteen characters with complexity.
Learn more →
External Infrastructure Testing
Everything you expose to the internet — mail, VPN, remote access, forgotten subdomains — is being probed constantly by people who never asked permission.
Learn more →
Web Application Testing
Your web applications are your most exposed attack surface.
Learn more →
API Testing
APIs move your most sensitive data, yet they rarely get the scrutiny given to the interfaces built on top of them.
Learn more →
API Gateway Audit
Every request to every API you publish passes through one control point: the gateway.
Learn more →
Vulnerability Assessment
Not everything needs a full penetration test, and not every budget stretches to one each quarter.
Learn more →
WiFi Penetration Testing
Your wireless network is the one part of your perimeter that leaves the building.
Learn more →
Threat Simulation
Real-world attack scenarios against your people and processes.
API Stress Testing
APIs usually fail under load before they fail under attack — on launch day, during a campaign, or when a client integration ramps up.
Learn more →
Social Engineering
Attackers rarely start with technology; they start with a phone call, an email or a confident walk through reception.
Learn more →
Phishing Campaigns
One convincing email is still the most reliable way into most organisations.
Learn more →
Executive Threat Assessment
Senior leaders are targeted precisely because of who they are: their names authorise payments, their inboxes carry weight, and their personal lives leak online in ways corporate controls never touch.
Learn more →
Ransomware Simulation
Every ransomware plan looks sound until the day it runs.
Learn more →
Which test do I need?
Several of these sound alike. Here is what each one actually answers, and what it asks of you.
- Internal Infrastructure Testing
If someone gets a foothold inside, how far can they get?
Needs from you: An assumed-breach position on the internal network.
- Active Directory Security Audit
What is the full configured state of my domain, and who really holds power in it?
Needs from you: A standard domain user and network reach to a domain controller. No admin rights.
- Active Directory Password Audit
Would my workforce's passwords actually survive an offline attack?
Needs from you: Password hashes extracted under your control. Privileged — the most sensitive engagement we run.
- External Infrastructure Testing
What can an attacker on the internet see, reach and exploit today?
Needs from you: Your public IP ranges and domains. No internal access.
- Web Application Testing
Can my web application be broken by a determined attacker?
Needs from you: Test accounts for each user role. Staging or agreed production.
- API Testing
Can the API behind my apps be attacked directly?
Needs from you: API docs or a Postman collection, and test credentials per access level.
- API Stress Testing
Will my API hold under load — and are its security headers sound?
Needs from you: A Postman collection and an agreed test window. Non-production preferred.
- API Gateway Audit
Is my Azure API Management gateway configured to actually enforce its controls?
Needs from you: Read access to the Azure APIM instance. Azure APIM only.
- Vulnerability Assessment
Where are my known weaknesses, triaged into a real priority list?
Needs from you: Scope of IP ranges or hostnames; internal access for internal scans.
- WiFi Penetration Testing
Can someone attack my network from the car park, and where do they land if they get on?
Needs from you: A testing engineer on site at each location. Cannot be done remotely.
- Social Engineering
Do my people and processes hold up when someone plausible asks?
Needs from you: Agreed scenarios and a small informed group. Scoped and bounded up front.
- Phishing Campaigns
How would my organisation fare against realistic phishing, measured over time?
Needs from you: Target mailing lists from an authorised contact. Blame-free by design.
- Executive Threat Assessment
What could an attacker build on my named executives, and what could they do with it?
Needs from you: Written consent and seed data per subject. Passive by default.
- Ransomware Simulation
If ransomware fired today, would we see it — and what would my people actually do?
Needs from you: Named Windows hosts, a signed authorisation and a client lead holding the kill code.
| Service | The question it answers | What it needs from you |
|---|---|---|
| Internal Infrastructure Testing | If someone gets a foothold inside, how far can they get? | An assumed-breach position on the internal network. |
| Active Directory Security Audit | What is the full configured state of my domain, and who really holds power in it? | A standard domain user and network reach to a domain controller. No admin rights. |
| Active Directory Password Audit | Would my workforce's passwords actually survive an offline attack? | Password hashes extracted under your control. Privileged — the most sensitive engagement we run. |
| External Infrastructure Testing | What can an attacker on the internet see, reach and exploit today? | Your public IP ranges and domains. No internal access. |
| Web Application Testing | Can my web application be broken by a determined attacker? | Test accounts for each user role. Staging or agreed production. |
| API Testing | Can the API behind my apps be attacked directly? | API docs or a Postman collection, and test credentials per access level. |
| API Stress Testing | Will my API hold under load — and are its security headers sound? | A Postman collection and an agreed test window. Non-production preferred. |
| API Gateway Audit | Is my Azure API Management gateway configured to actually enforce its controls? | Read access to the Azure APIM instance. Azure APIM only. |
| Vulnerability Assessment | Where are my known weaknesses, triaged into a real priority list? | Scope of IP ranges or hostnames; internal access for internal scans. |
| WiFi Penetration Testing | Can someone attack my network from the car park, and where do they land if they get on? | A testing engineer on site at each location. Cannot be done remotely. |
| Social Engineering | Do my people and processes hold up when someone plausible asks? | Agreed scenarios and a small informed group. Scoped and bounded up front. |
| Phishing Campaigns | How would my organisation fare against realistic phishing, measured over time? | Target mailing lists from an authorised contact. Blame-free by design. |
| Executive Threat Assessment | What could an attacker build on my named executives, and what could they do with it? | Written consent and seed data per subject. Passive by default. |
| Ransomware Simulation | If ransomware fired today, would we see it — and what would my people actually do? | Named Windows hosts, a signed authorisation and a client lead holding the kill code. |
Not sure which fits? Tell us the problem and we’ll point you to the right one — often it is two run together.
Ready to test your defences?
Tell us what you need secured — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).