Security testing

Our tests are performed 'hands-on' by experienced senior consultants utilising the same methods and tools as hackers.

Our mission is to provide unrivalled testing and training services, whilst at the same time advancing the understanding of security vulnerabilities throughout the IT industry and amongst our organisations.

We provide our organisations with the reassurance that their systems, networks and web sites will perform as required, showing them how to mitigate the threat of attack from unauthorised sources, both externally and from within the organisation.

We are accredited to ISO 27001 and our testing consultants are certified to relevant industry standards such as CESG CHECK and we are a member of CREST (Council of Registered Ethical Security Testers).

Ethically using up-to-date techniques, technologies and industry recognised information sources deployed by genuine hackers to mitigate the identified risks and improve security measures, our services involve far more than simply 'scanning' the network for weaknesses.

Key areas of expertise include:

  • Network security testing: We analyse the security of the networks supporting your web sites and applications. Considering the potential for both an internal and external attack is essential for organisations where breaches of customer confidentiality or fraud could result in bad publicity, loss of reputation and business.
  • Web application security testing: We rigorously test your web applications to ensure they are secure enough to cope with the transactions they are required to undertake (e.g. online banking and order processing).
  • Payment Card Industry Data Security Standard: As a Qualified Security Assessor (QSA) and Approved Scanning Vendor (ASV) we help organisations who sell or take donations or payments by credit card to become and stay compliant with PCI DSS.
  • Remote access and remote worker security: We cover the security risks that arise from remote and home working. Issues such as laptop security, home and remote worker security, VPN security and access to remote servers are considered.