Penetration Testing Services

Offensive security testing for your applications, APIs, and networks.

Consultant-led penetration testing across applications, APIs, networks, and infrastructure. UK-based consultants, fixed pricing, and reports delivered within 2 business days.

Accreditations and memberships

Offensive security and penetration testing services for web applications, infrastructure, and networks

Application Security Testing

Offensive security testing for your applications and APIs

Web Application Penetration Testing From £2,700

Manual offensive testing that goes well beyond automated scanning. We approach your application the way a real attacker would, chaining weaknesses across authentication, authorisation, and business logic to identify what's genuinely exploitable.
OWASP Top 10Authenticated TestingAPI Testing

API Penetration Testing From £1,800

OWASP API Security-aligned testing covering broken authorisation, excessive data exposure, rate limiting, and parameter tampering across your REST, GraphQL, and SOAP APIs.
REST APIsGraphQLSOAP

Website Security Testing From £750

A focused assessment of your public-facing website covering CMS and plugin exposure, TLS configuration, security headers, admin panel exposure, and common misconfigurations.
CMS & WordPressSecurity HeadersMisconfigurations

Mobile Application Security Testing From £2,800

iOS and Android penetration testing covering insecure data storage, weak cryptography, improper platform usage, and API security - assessed through reverse engineering, runtime manipulation, and backend API testing.
iOS & AndroidOWASP MASVSAPI Testing

Desktop Application Security Testing From £2,700

Identify privilege escalation, insecure data storage, and code injection flaws in Windows and macOS applications through both source code review and black-box techniques.
Windows & macOSCode InjectionPrivilege Escalation

Network & Infrastructure Penetration Testing

Test your network perimeter and internal trust boundaries

Infrastructure testing overview

External Network Penetration Testing From £1,800

We map your external attack surface from an attacker's perspective, identifying exposed services and testing firewalls, VPNs, and remote access infrastructure for exploitable weaknesses.
Black-box TestingOSINT ReconFree Retesting

Internal Network Penetration Testing From £2,850

Simulate insider threats and assumed-compromise scenarios, assessing Active Directory security, lateral movement opportunities, privilege escalation paths, and access to critical systems.
Active DirectoryLateral MovementAssumed Breach

Wi-Fi Security Assessment From £1,700

Wireless penetration testing covering corporate and guest networks, testing encryption strength, rogue access points, network isolation, and captive portal security.
Rogue AP DetectionNetwork IsolationGuest Networks

Vulnerability Assessment From £700

Automated vulnerability scanning with manual validation and prioritisation, identifying known vulnerabilities, misconfigurations, and missing patches with actionable remediation guidance.
Authenticated ScanningRemediation GuidanceInternal & External Networks

Continuous Offensive Security Testing

Go further with testing that keeps pace with your environment

Pentest as a Service (PTaaS) From £3,800/mo

Continuous offensive security testing with unlimited retesting, on-demand consultant access, and real-time vulnerability tracking.
Continuous TestingUnlimited RetestingOn-demand Access

Specialist Testing Services

Offensive security testing for specialist requirements

OSINT Reconnaissance

We identify publicly available information across your infrastructure, personnel, and online footprint - the same reconnaissance an attacker would perform before a targeted engagement.
Passive ReconBreach DataAttack Surface Mapping

Embedded Device & IoT Security Testing From £4,500

Full-stack offensive testing of hardware products and IoT devices, covering hardware interfaces, firmware analysis, wireless protocols, and the complete ecosystem.
Firmware AnalysisHardware InterfacesFull Ecosystem

Password Auditing

Offline Active Directory password auditing: we crack your password hashes and analyse them for weakness, reuse, predictable patterns, and breach-data exposure - showing you exactly what your users are actually setting.
Offline Hash CrackingAD Password AnalysisPolicy Assessment

Key Deliverables

What's included in every engagement?

Our offensive security engagements are designed to support both technical remediation and executive-level decision-making. Every Exploitr assessment includes the following as standard.
01

Executive Report

A clear, non-technical summary of findings with risk ratings and remediation guidance written to be understood by board members, senior management, and any non-technical decision-makers who need to act on the results.
02

Technical Report

A detailed report for your technical team covering each vulnerability, reproduction steps, severity scoring, remediation guidance, and mappings to CVE, CVSS, and MITRE ATT&CK where applicable.
03

Debrief Session

A debrief call to walk through findings, discuss remediation priorities, and answer questions from both technical and executive stakeholders.
04

Retesting

Free focused retesting of any remediated vulnerabilities for externally-based assessments - including web application, API, and external network penetration testing.
05

Attack Surface Center Access

Complimentary access to our Attack Surface Center ASM platform to review, track, and collaboratively remediate findings in real time throughout and beyond the engagement.
06

Consultant-led From Start to Finish

All testing is performed by in-house consultants. Your assigned consultant works with you from scoping through to debrief. Nothing is outsourced or subcontracted.

Ready to scope your next penetration test?

We'll help you identify the right type of offensive security assessment for your environment, compliance requirements, and budget.

Pentest Requirements

Which type of penetration test do you need?

Not every organisation has the same requirements. Here are the most common situations we see, and the testing we'd typically recommend.

Not sure what's right for you?

Book a free scoping call and we'll help you identify the right type of assessment for your environment, compliance requirements, and budget.

Speak to an expert

You're preparing for ISO 27001 certification or renewal

Your ISMS audit will expect evidence of independent security testing. We'd typically recommend an external network penetration test as a starting point, combined with web application testing if you have customer-facing systems in scope.

You're working towards PCI DSS compliance

PCI DSS Requirement 11.4 mandates penetration testing of your cardholder data environment at least annually and after significant change. We scope CDE-focused engagements to meet PCI DSS requirements and provide evidence-ready reporting for your QSA.

You're launching or significantly updating a web application or API

Pre-launch is the right time to test. Application penetration testing identifies authentication flaws, data exposure risks, and business logic vulnerabilities before they reach production - using the same techniques a real attacker would apply.

You've never had a penetration test before or aren't sure what you need

That's what scoping calls are for. Tell us about your environment, compliance obligations, and specific concerns. We'll recommend an assessment that fits your risk profile and budget, and provide a fixed quote within 24 hours.

Our Approach

Offensive security led by consultants, not scanners

Every engagement is scoped individually, priced transparently, and delivered directly by our lead consultant from the very beginning.

Our penetration testing methodology draws from OWASP WSTG and NIST SP 800-115, with adversary-informed techniques aligned to the MITRE ATT&CK framework and NCSC guidance.

Whether your goal is meeting a compliance requirement, validating a pre-launch application, or understanding your real-world risk exposure, the focus is on findings that are genuine and exploitable.

Common Questions

Penetration testing & offensive security - frequently asked questions

Everything you need to know about how our offensive security assessments are scoped, priced, and delivered before you request a quote.

All testing is carried out by our in-house consultants, and nothing is outsourced or subcontracted. Your assigned consultant will be confirmed before testing begins and remains your direct point of contact from scoping through to debrief.

Our lead consultant holds OSCP (Offensive Security Certified Professional) and OSCE (Offensive Security Certified Expert) certifications from Offensive Security.

Pricing is based on scope, complexity, and your organisation's context. We publish realistic price ranges so you can quickly assess fit before requesting a quote.

For bespoke engagements, we tailor methodology and consultant time to your objectives. Each quote factors in:

  • Scope of testing (e.g., number of IPs, applications, or cloud resources)
  • Technical and architectural complexity
  • Testing methodology (black box, grey box, white box, or blended)
  • Depth of exploitation, reporting, and retest support required

To ensure accurate pricing by not over or under-scoping an assessment, we aim to learn as much about your business and the target(s) as possible.

A scoping call reduces back-and-forth over email, allows for quick walkthroughs of applications or infrastructure, and gives us the context we need to tailor an offensive assessment to your specific risk concerns.

We're able to support scoping discussions via email if preferred.

Most engagements run between 3-5 days of active testing, but could take longer depending on the type of assessment and the complexity of your environment. An internal network pentest may take between 4-8 days, whilst a basic company website assessment may take 1-2 days.

With Exploitr, we provide live access to our findings throughout testing via Attack Surface Center, so you don't have to wait for the final report to start understanding your risk.

To get accurate timelines, schedule a free scoping call to discuss your testing requirements with no obligation.

Retesting is available and can be bundled or quoted separately. For certain assessments, including external network, web application, and API penetration testing, we include free spot-check retesting of remediated findings at no additional charge.

Yes, we can provide an attestation letter confirming that the penetration test was conducted according to the agreed scope and methodology. This can be useful for compliance purposes or to provide assurance to stakeholders.

An attestation of penetration testing is included as standard for all of our engagements.

We can test any part of your environment that you want. We don't require you to test everything, and we don't believe in a one-size-fits-all approach.

We'd recommend including all relevant assets for network testing, and all user roles and critical functionality for application testing, but ultimately it's your choice.

During the scoping call, we'll discuss your environment and objectives in detail to help you determine the most effective scope for your engagement.

These terms describe how much information is shared with the tester before the engagement begins.

  • Black-box testing simulates an external attacker with no prior knowledge of your environment. It's useful for testing your external perimeter and detection capabilities, but may miss deeper issues due to limited context.

  • Grey-box testing provides the tester with partial information, which is typically credentials, architecture diagrams, or access to the application as an authenticated user. This is the most common approach for web application and API testing as it balances realism with thoroughness and efficiency.

  • White-box testing gives the tester full access to source code, architecture documentation, and credentials. This maximises coverage and is often used for compliance-driven engagements or where a deep audit of application security is required.

We'll recommend the most appropriate approach during your scoping call based on your objectives.

Get a tailored quote for your next assessment

Our team are on hand to discuss your security requirements and provide a tailored, fixed-price proposal within 24 hours.