Skip to main content

Precedent

Security Assessments and Penetration Testing

The basics stop most attacks, but how do you know they’re actually in place? A security assessment tests your systems the way an attacker would, then tells you in plain English what we found, how serious it is, and what to fix first.

Our team has tested and advised on security for banks, government agencies, defence and national infrastructure providers, as well as small businesses. We’ve found and reported vulnerabilities in widely used software, including one in Microsoft DNS that Microsoft has since patched, and demonstrated complete network takeovers to management teams so they could see the risk for themselves.

Three levels of assessment

  • Free self-check: Twelve questions and an instant score. Take the self-check
  • Security review: We review your Microsoft 365 or Google Workspace settings, devices, backups, firewall and remote access against the fundamentals recommended by the National Cyber Security Centre (NCSC), and give you a prioritised list of fixes
  • Penetration test: Hands-on testing of your website, internet-facing systems or internal network, with a written report and a debrief

Safe and agreed in advance

Every test is scoped and authorised in writing before it starts. We agree what’s in scope, when testing happens and who to call, and we avoid anything that could disrupt your business.

What we test

  • External exposure: Everything your business has facing the internet, including forgotten servers, open ports, remote access and old test systems
  • Websites and web applications: Logins, forms, plugins and hosting checked for common weaknesses such as injection, broken access control and outdated software
  • Internal network: What an attacker could reach from a single compromised laptop, and how far they could get
  • Cloud accounts: Microsoft 365, Google Workspace, Azure and AWS settings, file sharing and admin access
  • Email and domains: SPF, DKIM, DMARC and domain settings that stop criminals sending email as you
  • Servers: Linux and Windows server hardening, patching, access control and logging
  • People and process: Payment approvals, password resets and staff departures, the processes attackers most often exploit

Most issues we find we can fix for you, as a one-off project or as part of our managed IT service. Read how a live demonstration changed one organisation’s view of its security.

What you get

A short summary for management, a detailed list of findings for whoever looks after your IT, each rated by risk and effort to fix, and a meeting to walk through it. Once the fixes are in, we retest to confirm they’ve worked.

Common questions

Do we need a penetration test?
If you hold sensitive client information, take payments, or a client, insurer or contract asks for one, probably. If the basics aren’t in place yet, start with a security review: it costs less and fixes the most likely problems first.

Will testing break anything?
We plan tests to avoid disruption and agree timing with you. Anything that carries risk is discussed beforehand, and we can test out of hours.

We already have an IT provider. Can you still help?
Yes. An independent second opinion is one of the most useful things an assessment provides, and we’re happy to work alongside your existing provider on the fixes.

Call 04 282 0045 or send us a message to arrange an assessment.

Call 04 282 0045