Services

Penetration Testing Services for UK Small and Medium Businesses

Authorised, scoped, evidence-backed attacks against your web applications, external perimeter and internal network — carried out by consultants who then sit down and explain exactly how to close what they found.

METHODOLOGY
OWASP WSTG, PTES, NCSC Guidance
TEST TYPES
Black, Grey and White Box
EVIDENCE
Reproducible Proof for Every Finding
RETEST
Free Retest Within 60 Days
In short

What is penetration testing and does a small business need it?

Penetration testing is an authorised simulated attack in which a tester actively exploits weaknesses to prove what a real attacker could achieve. Small businesses need it when they handle customer or payment data, sell to enterprise clients who ask for a test report, or have built a web application of their own.

What a penetration test actually involves

A penetration test is not a scan. A tester works the way an attacker works: mapping what you expose, looking for the weak link, and chaining small issues together into something that matters. A password policy weakness on its own is a medium finding. The same weakness combined with an exposed remote desktop gateway and a service account with domain administrator rights is a full compromise, and that is the sort of chain only a human finds.

Everything is authorised in writing before we begin. Scope, timing, target systems, what is explicitly off-limits, and an emergency contact are all agreed in a rules of engagement document you sign. Testing without that document is a criminal offence under the Computer Misuse Act 1990, and no reputable firm will proceed without one.

  • Reconnaissance and attack surface mapping
  • Vulnerability identification and manual verification
  • Controlled exploitation to establish genuine impact
  • Privilege escalation and lateral movement where in scope
  • Evidence capture, then a clean tear-down of any test artefacts

Choosing the right type of test

Black box testing gives the tester nothing but a company name or a URL, mimicking an outside attacker with no inside knowledge. It is realistic but spends a lot of billable time rediscovering things you could simply have told us. Grey box gives the tester standard user credentials, which is usually the best value for money because it mirrors the most common real scenario: an attacker who has phished one employee. White box provides full documentation and source code, giving the deepest coverage per pound spent.

For most SMEs we recommend grey box against the web application and external perimeter, with an internal assumed-breach test if you hold sensitive data on a company network.

  • Black box — realistic outsider view, best for validating perimeter defences
  • Grey box — standard user credentials, best value and most realistic breach model
  • White box — full access and documentation, deepest coverage for critical apps
  • Assumed breach — starts from a compromised workstation to test internal containment

Web application and API testing

If you have built or commissioned a web application — a customer portal, a booking system, an online shop, an internal tool exposed to the internet — that application is usually the single highest-risk asset you own. It is reachable by anyone, it talks directly to your database, and it was probably built to a deadline.

We test against the OWASP Web Security Testing Guide: injection, broken access control, authentication and session flaws, insecure direct object references, server-side request forgery, and the business logic problems automated tools never catch — such as being able to change a price, view another customer's order, or skip a payment step by manipulating a request.

  • Broken access control and horizontal or vertical privilege escalation
  • Injection flaws including SQL, command and template injection
  • Authentication, password reset and session management weaknesses
  • Business logic flaws unique to how your application works
  • API authorisation, rate limiting and data exposure issues
  • File upload handling, SSRF and insecure deserialisation

The report is the product

You are not buying a test, you are buying a document you can act on and — often — send to a customer. Ours contains an executive summary in business language, a clear statement of what we achieved and how far we got, and a technical section where every finding carries evidence, reproduction steps, business impact and a specific fix.

We do not pad reports with informational findings to make them look thorough. If we found three things that matter, the report says so and explains them properly.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Penetration Testing Rules of Engagement (RoE)

Written authorisation for active security testing: targets, windows, permitted techniques, exclusions, emergency contacts and stop conditions.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Penetration Testing — your questions answered

How much does a penetration test cost in the UK?
Price is driven by scope and duration. A focused web application test or a small external perimeter test is typically a few days of consultant time; larger internal network tests run longer. We quote a fixed price in writing after a free scoping call, so the cost is known before you commit.
How long does a penetration test take?
Testing for a typical SME web application or external perimeter takes three to five days, with the report delivered within a week of fieldwork finishing. Critical findings are reported to you the same day they are discovered rather than held back for the report.
Is penetration testing legal?
Yes, when properly authorised. Testing must be covered by a written rules of engagement document signed by someone with authority over the systems in scope; without it, testing would breach the Computer Misuse Act 1990. We will not begin work until that document is signed.
Will penetration testing break our website or systems?
Disruption is rare and we work to avoid it. Destructive tests such as denial of service are excluded unless you specifically request them, testing can be scheduled out of hours, and we maintain a live contact throughout so anything unexpected is stopped immediately.
How often should we get a penetration test?
Annually is the general standard, and additionally after any significant change — a new application, a major release, a cloud migration or an office move. Many clients run continuous vulnerability assessment between annual tests.
Do you provide a certificate or letter we can show clients?
Yes. After remediation and the free retest we issue an attestation letter confirming the scope, dates and that identified issues were resolved. Enterprise clients and insurers commonly ask for exactly this.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about penetration testing?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.