Web Application Testing
Your web applications are your most exposed attack surface. We test them against the OWASP Top 10 and the OWASP Web Security Testing Guide the way an attacker would — logged out, logged in, and between user roles — with testers who have spent close to two decades doing this. You get findings you can hand straight to your developers.
Who this is for
- You are launching or materially changing a customer-facing application
- A client, insurer or framework (ISO 27001, PCI DSS) requires independent testing
- You handle personal or payment data through a web portal
- You have never had the application tested by a human, only scanned
What we test
Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.
- Surface
Injection and input handling
Everything the application accepts before it knows who you are — SQLi, XSS, SSRF, template and command injection. This is where an automated scan starts and, usually, where it stops.
- Identity
Authentication and session management
Credential handling, MFA bypass, and token and cookie weaknesses — how you prove who you are, and how that proof can be taken, forged or kept alive past logout.
- Privilege
Access control
Horizontal and vertical privilege escalation between user roles: whether one customer can reach another's data, and whether a standard account can reach an administrative one.
- Logic
Business-logic flaws
Workflow abuse, price and quantity manipulation, race conditions. Nothing here is a malformed request — every step is legal, in the wrong order or at the wrong scale. No scanner finds these.
- Assurance
Mapped to a published standard
Coverage mapped to the OWASP Top 10 and the OWASP Web Security Testing Guide, with OSINT-derived credential testing where in scope — so the breadth can be checked rather than taken on trust. Run by testers with close to twenty years in offensive security, not a scan with a logo on it.
What you get
The package in three parts — what you read, what you act on, and what happens after.
What you read
Written for two audiences in one document.
- Executive summary and overall risk rating written for non-technical stakeholders
- Findings table ordered by CVSS severity with remediation effort indicators
What you act on
Enough detail for a developer to reproduce and close.
- Per-finding technical detail sufficient to reproduce, with step-by-step remediation and references
- OWASP Top 10 mapping to focus secure-development training
What happens after
We verify the fix ourselves.
- Free remediation retest — fix what we found and we verify it*
* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.
How it runs

The same six phases, every engagement
Threat Model Development
We agree what the exercise is replicating: the credible threats to your organisation, the starting position, the objectives, and which controls are in scope. It is also where disruption is bounded, so the test does not cost you a working day.
Information Gathering
Enumerating the systems and services actually in play from that starting point, so the attack surface is mapped as it is rather than as the asset register describes it — and choosing tools and techniques that suit it.
Vulnerability Identification
Examining that surface for weakness, using automated tooling for breadth and manual technique for everything a scanner cannot reason about. Neither finds what the other does, which is why the blend is deliberate.
Attack Vector Development
Weighing each weakness against your actual environment — how exploitable it really is, what skill it demands, what it would cost you. The output is the routes that are practical here, not the ones theoretically possible somewhere.
Exploitation
Where it is appropriate, we exploit, which usually opens a fresh attack surface and sends us back round the cycle. Where exploiting would cause harm we verify the finding is genuine rather than a stale banner, and assume the worst case.
Reporting
One document for two audiences: an executive summary your board can act on, and the technical chain your engineers can reproduce step by step, each finding carrying its severity and its remediation.
Prerequisites
- Test accounts for each user role in scope
- Access from Laneden's public IP addresses allowlisted where required
- A signed Laneden authorisation form
Frequently asked questions
Will testing disrupt the live application?
Our protocol is non-destructive and starts with non-invasive checks. Where risk exists we test against staging, agree testing windows, or exclude specific actions — scoped with you before we begin.
How long does a web application test take?
Most single applications take 3-5 testing days depending on size and role count. We confirm effort in a fixed-price proposal after a short scoping call.
Is this just an automated scan?
No. Scanners find known patterns; our engineers find logic flaws, chained exploits and access-control failures scanners cannot see. Automated tooling supports, never replaces, manual testing.
What happens if you find something critical?
Critical findings are reported to your named contact immediately — not saved for the report — so your team can start remediation the same day.
Related services
API Testing
APIs move your most sensitive data, yet they rarely get the scrutiny given to the interfaces built on top of them.
Learn more →
External Infrastructure Testing
Everything you expose to the internet — mail, VPN, remote access, forgotten subdomains — is being probed constantly by people who never asked permission.
Learn more →
Vulnerability Assessment
Not everything needs a full penetration test, and not every budget stretches to one each quarter.
Learn more →
Ready to test your defences?
Tell us about your web application testing requirement — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).
