Scoping and rules of engagement
A written scope, testing windows and emergency contacts agreed before anything starts.
We test your systems the way a real attacker would, with your permission and within agreed limits. You get a clear picture of what could be reached, and exactly how to close it.
Last reviewed

A penetration test is a controlled, authorised attack on your systems. Automated scanners find known weaknesses; a tester goes further, chaining small issues together to show what someone could actually achieve.
Every test starts with a scoping conversation. We agree what is in bounds, when testing happens and who to call if we find something urgent, so there are no surprises for your team or your customers.
A written scope, testing windows and emergency contacts agreed before anything starts.
Hands-on testing that goes beyond scanner output to find logic flaws and chained weaknesses.
Every issue rated by real-world impact, not just a severity score from a tool.
A short, plain-English overview your board and clients can read.
Evidence and step-by-step remediation guidance for your developers or IT provider.
Once fixes are in, we check them and update the report.
We agree targets, depth, timing and contacts.
Our testers work through your systems, keeping you updated on anything critical.
Findings ranked by risk, with clear remediation steps.
We confirm the fixes worked and close out the report.
Websites, portals and APIs, tested against authentication, access control, injection and business-logic flaws.
External testing of what faces the internet, and internal testing that assumes someone is already inside.
Configuration and access review of your cloud accounts, storage and identity setup.
iOS and Android apps, including the APIs and data storage behind them.
The number of applications, IP addresses or user roles in scope.
A focused external test takes less time than a full internal and application assessment.
Custom applications with many roles and integrations need more testing time.
Out-of-hours testing to protect live services can affect the schedule.
We give a fixed quote once the scope is agreed, so you know the cost of a penetration test before any work starts.
Get a quoteIt depends on scope and depth. A focused test of one web application costs far less than a full internal network assessment. After a short scoping call we give you a fixed quote.
Most tests run for a few days to two weeks of testing time, followed by the report. We agree the timeline with you before starting.
Testing is planned to avoid disruption. We agree testing windows, avoid destructive techniques on live systems, and contact you immediately if anything unexpected happens.
A scan is automated and lists known weaknesses. A penetration test is carried out by a person, who confirms which weaknesses are real and shows how they could be combined to cause harm.
At least once a year, and after any significant change such as a new application, a cloud migration or a major network change.
A short call, no obligation. We'll listen, ask a few questions and suggest a sensible first step.
Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.
The Leather Market
London Bridge