Penetration Testing

Penetration Testing Services

CREST, CSTM and OSCP qualified penetration testers. London-based.

A penetration test is only as useful as the people carrying it out. Automated scans find the obvious. Real attackers chain together the things that look harmless on their own. Every Forensic Control penetration test is delivered by CREST, CSTM and OSCP qualified testers using a methodology built on NIST Special Publication 800-115 and the Penetration Testing Execution Standard (PTES).

Forensic Control has been delivering cyber security services for UK organisations since 2008. We are an authorised IASME Certification Body, which means the same team that scopes your pen test can sign your Cyber Essentials Plus certificate at the end of it. No handoffs, no second supplier.

Penetration Testing Services
Trusted by UK organisations for security testing
Nurole logo Know Why logo Victoria and Albert Museum logo Save the Children logo Faculty logo
What we offer

Our penetration testing services

We scope each engagement to the systems and threat scenarios that matter for your business. Pricing is by scope, not by tester-day, so we can give you the cost before testing begins. The six services below cover our standard catalogue; if your requirement doesn’t fit neatly into one of them, get in touch and we’ll scope something bespoke.

01

External Network Penetration Testing

Your public-facing systems are the most exposed part of your estate and the first target most attackers reach for. We test from outside the network against your public IP ranges and exposed services, identifying what an internet-based attacker can see, reach and exploit. Findings are CVSSv3-rated with clear remediation steps.

02

Internal Network Penetration Testing

Most successful breaches don’t end at the perimeter — they begin there. An internal pen test starts from inside the network, simulating an attacker who already has a foothold (a stolen credential, a compromised endpoint, an opportunistic insider). We map lateral movement paths, escalate privileges where we can, and report exactly how far an attacker could reach.

03

Web Application Penetration Testing

If your business builds or maintains custom web applications, those applications are your largest attack surface. We test authentication, session management, authorisation logic, input handling, business-logic flaws and the trust boundary between client and server. Most clients opt for grey-box testing using staging credentials — the most realistic and cost-effective approach.

04

Mobile Application Penetration Testing

A mobile app is three things at once: the binary on the device, the data it stores locally, and the APIs it talks to. We test all three across iOS and Android — looking at how credentials are stored, how data is transmitted, whether the supporting APIs can be abused independently of the app, and what an attacker with a reverse-engineered build could learn.

05

Social Engineering

Technical controls only matter if the people behind them aren’t tricked into bypassing them. A social engineering engagement tests the human layer: targeted phishing campaigns, voice-based pretexting, and tailored scenarios drawn from publicly available information about your business. The output tells you which controls held, which didn’t, and where to focus training.

06

Red Teaming

A red team engagement is a goal-oriented attack simulation: agree an objective (“exfiltrate finance data”, “gain domain admin”, “compromise the CEO’s mailbox”) and let a team of testers chain together every technique an advanced attacker might use to achieve it. Longer, broader and stealthier than a standard pen test. Best suited to organisations with mature security programmes that want to test their detection and response capability.

Our approach

How we run a penetration test

Our penetration testing methodology is built on NIST Special Publication 800-115 and the Penetration Testing Execution Standard (PTES). A typical engagement follows the six stages below, with a CREST, CSTM or OSCP qualified tester leading the work from start to finish.

1

Pre-Engagement

Client goals, scope and rules of engagement agreed. Senior FC staff lead this conversation.

2

Intelligence Gathering

Open-source intelligence on the target systems to inform the testing approach.

3

Reconnaissance

Automated and manual enumeration to map potential entry points.

4

Vulnerability Identification

Entry points probed using manual and automated techniques.

5

Vulnerability Verification

Potential vulnerabilities confirmed through manual exploitation.

6

Reporting

CVSSv3-prioritised findings with daily updates during testing.

Deliverables

What you receive

Each engagement produces a written report and a set of deliverables designed to be useful both to the board and to the IT team or MSP that has to act on them.

Executive summary

Written for non-technical readers. The board and senior leadership can act on this section without reference to the technical detail.

CVSSv3-rated findings

Every vulnerability prioritised by Common Vulnerability Scoring System v3 risk rating, with evidence, location and reproduction steps.

Proof of concepts

Clear proof of concept content showing how each vulnerability can be replicated. Useful for the team remediating the issues.

Remediation recommendations

Clear remediation guidance for every finding, with full hands-on support for critical and high-risk vulnerabilities at no extra cost.

Daily updates during testing

If a high or critical vulnerability is discovered during testing, you hear about it that day. Urgent issues can be addressed in parallel.

Walkthrough call with your team

Once the report is delivered, we schedule a call or video conference to walk through the major findings with your team.

Retesting included as standard

Once you have remediated findings, we retest to confirm the fix. Included in scope, not charged separately. Report updated post-retest.

Penetration Testing Certificate

Once retesting is complete, you receive a Certificate. Useful for client due diligence, supplier questionnaires, cyber insurance and ISO 27001 evidence.

Why choose us

Why organisations choose Forensic Control for penetration testing

Qualified security experts

Every engagement is delivered by CREST, CSTM and OSCP qualified penetration testers using a methodology built on NIST 800-115 and PTES. No junior testers, no offshore work, no being passed between accounts.

Clear and focused reporting

Findings reported in plain English and prioritised by CVSSv3, with proof of concepts and remediation steps for every issue. A walkthrough call with your team once the report is delivered, and a Penetration Testing Certificate once everything is resolved.

Senior-led scoping

Scoping is the stage where most pen tests succeed or fail. Senior Forensic Control staff lead every scoping conversation, drawing on investigative-grade experience from New Scotland Yard to focus the engagement on the threats that actually apply to your business.

Joined up with Cyber Essentials Plus

We are an authorised IASME Certification Body. If your pen test is feeding into a Cyber Essentials Plus certification, ISO 27001 audit or SOC 2 readiness, the same team that scopes the test signs the certificate or supports the audit. No handoffs.

Understand the difference

Penetration testing vs vulnerability scanning

A penetration test and a vulnerability scan look at the same problem from different angles. Most organisations need both: scanning monthly, pen testing once a year or after a significant change.

Penetration Testing

Vulnerability Scanning

Frequency
Annual or post-change
Monthly (recurring)
Method
Hands-on manual testing
Automated tooling, read by an assessor
Coverage
Deep examination of a defined scope
Known vulnerabilities at scale
Output
Exploit-chain narrative with CVSSv3 ratings
Prioritised remediation list
Read the full guide
Everything you need to know

Penetration testing: Frequently asked questions

What is penetration testing?
Are your penetration testers CREST certified?
How is penetration testing different from vulnerability scanning?
What does a penetration testing report include?
How much does a penetration test cost?
How often should we run a penetration test?
Is penetration testing required for Cyber Essentials Plus?
How do I get started with Forensic Control penetration testing?

Speak to us about scoping a pen test

Whether you are running a pen test for the first time, renewing an annual engagement, or testing in advance of a Cyber Essentials Plus or SOC 2 audit, we can scope it on a 15-minute call.

Contact an Expert
LATEST UPDATES

Penetration Testing News

Stay informed with the latest updates, guidance, and insights related to Penetration Testing. From practical advice to emerging risks and best practices, these articles help you stay informed and ahead of the curve.
Next steps

Explore Penetration Testing support

Use these links to review related news, resources, and further information that may help scope your matter.
Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.