← Solutions
CyberPopular

Penetration testing and security testing

Threat-led testing of web apps, APIs, cloud, networks and people, by testers who prove exploitability and help you fix what they find.

Typical timing
1–4 weeks
Engagement
Fixed scope
Delivery framework
User researchDiscoveryAlphaBetaLive

Find the weaknesses an attacker would use before they do. Tests are scoped against who would realistically target you, findings are proven rather than theoretical, and every issue comes with a clear fix — then we retest to confirm it is closed.

  • A new application or major change is about to go live
  • Customers, insurers or a certification require an annual test
  • You have never tested what an attacker could reach from the internet
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 02 · Discovery3–5 days

    Scope and threat profile

    • Targets, rules of engagement and test windows agreed
    • Likely attackers and techniques mapped to MITRE ATT&CK
    • Test approach: black, grey or white box
  2. 03 · Alpha1–3 weeks

    Test

    • Web, API, mobile, cloud, network or social engineering testing
    • Manual exploitation beyond automated scanning, including OWASP Top 10
    • Critical findings reported immediately
  3. 04 · Beta1 week, retest within 90 days

    Report and retest

    • Findings rated by risk with reproduction steps and fixes
    • Walkthrough with developers and leadership
    • Retest of remediated findings

Deliverables

What you keep at the end.

  • Executive summary and technical report
  • Findings rated by CVSS and business risk
  • Remediation guidance for each finding
  • Retest letter confirming closure

Outcomes

What it is built to change.

  • Exploitable weaknesses found and fixed before attackers find them
  • Evidence for customers, insurers and auditors
  • Developers who understand why the issues occurred