Penetration Testing Services

Authorised simulated attack and vulnerability testing

Find partners

CyberGaar

CyberGaar is a cyber security company in Cheltenham providing security audits, penetration testing and vulnerability scanning to help organisations understand and reduce cyber risk. Services include manual penetration testing across web, mobile, network, cloud, wireless and social engineering; web application and API testing; cloud security reviews; and readiness support for Cyber Essentials, ISO 27001, SOC 2 and PCI DSS. It serves sectors including financial services, healthcare, technology and critical infrastructure.

Cheltenham

Cyserch

Cybersecurity consultancy offering penetration testing, risk assessments and incident response.

UK

FORTIFI CYBER SECURITY

This company delivers CREST-accredited penetration testing services, including web application, network, mobile application, and large language model testing, along with attack surface assessments and red and purple teaming. It provides human-led risk-based security testing, clear reporting, and remediation support to help protect businesses across various sectors from cyber security threats.

Heretek

Heretek is a Bromley-based cyber security testing firm offering vulnerability assessments, penetration testing and adversary simulation through threat-led red team engagements. Additional services include managed vulnerability scanning, purple team work building countermeasures alongside client teams, and advisory consulting from security leaders. It serves MSPs, resellers, partners and direct clients, from startups and scale-ups to enterprises, reporting findings through an online platform with remediation guidance.

Bromley

ILLUME SECURITY

Illume Security provides penetration testing and security assurance services to organisations across the UK. Its offerings include network, web application, and API testing, alongside red team exercises, social engineering, cloud security assessments, and Active Directory password auditing. The CREST-accredited firm helps legal, accounting, manufacturing, fintech, food, beverage, and construction clients identify cyber vulnerabilities.

Incursion Cyber Security

Incursion Cyber Security is a boutique cyber security consultancy in Bath, founded by a former British Intelligence Analyst. The team delivers penetration testing with precisely scoped engagements and clear, actionable insights rather than templated reports. They also guide SMEs through IASME Cyber Essentials certification with practical, hands-on support, and help businesses achieve IASME Cyber Assurance accreditation by developing robust policies and providing continuous compliance support.

Bath

Information Risk Management Ltd

IRM is a cybersecurity consultancy founded in 1998 and part of the Capgemini Group. From Woking, it provides penetration testing, security assessments and red teaming across IT networks, operational technology and embedded systems, alongside GRC consultancy, managed security services and its SYNERGi governance platform. It serves sectors including automotive, telecommunications, energy, finance, public sector and transport, supporting compliance and cyber-maturity.

Woking

Logically Secure

Logically Secure provides cyber security testing and incident response services. Its testing portfolio covers penetration testing, web application, mobile application, wireless, phishing and red team testing, plus cloud review and testing. The company also develops CyberCPR, an incident and case management platform that lets teams record findings, store evidence securely and collaborate on sensitive incidents under need-to-know access controls. Consulting services are also offered.

Cheltenham

MDSec Consulting Ltd

MDSec Consulting is a Macclesfield-based security consultancy offering penetration testing, adversary simulation, application security and incident response services. Its CBEST-certified ActiveBreach red team simulates real adversary tactics across the cyber kill chain, while its response team supports customers at all stages of the incident response lifecycle. The company also publishes security research and delivers training courses informed by its consultancy work, serving clients from technology firms to financial institutions.

Macclesfield

Nanorisk

Nanorisk is a UK-based, independent cyber security consultancy delivering penetration testing and security assessments across infrastructure, applications and social engineering scenarios. Services include vulnerability assessments, bespoke adversary-focused testing and simulations, and Cyber Essentials and Cyber Essentials Plus certification via a partner. Engagements are managed through a dedicated security portal covering communication, findings and reporting, with documentation provided for each assessment.

Darlington

Net Sec Group

Net Sec Group is a London-based cybersecurity firm led by a CREST Registered Penetration Tester and operating as an IASME Cyber Essentials Certification Body. Offensive services include web application, network infrastructure, API, mobile and wireless testing, social engineering and secure code review. Its Cyber 365 programme provides 24/7 SOC monitoring, continuous vulnerability scanning and patch management, guiding clients through Cyber Essentials and Cyber Essentials Plus certification.

London

OmniCyber Security Limited

OmniCyber Security is a boutique cyber security firm based in the UK and Canada, serving clients worldwide including financial institutions, retail chains, governments and technology companies. It provides CREST-accredited penetration testing, red teaming, vulnerability scanning, web, mobile and API testing, social engineering and continuous adversary emulation, alongside compliance services covering Cyber Essentials, ISO 27001, PCI DSS and GDPR, plus virtual CISO support, security training and phishing simulations.

Birmingham

Pen Test Partners

Pen Test Partners provides cybersecurity services including penetration testing, red teaming, incident response, digital forensics, security training, and compliance assessments for organisations across finance, healthcare, retail, transport and other sectors. They help clients identify vulnerabilities, simulate attacks, meet regulatory standards, and improve security maturity through tailored testing and advisory solutions.

UK (national)

Pentest Limited

Pentest Limited is a CREST-accredited offensive cybersecurity firm with over 25 years’ experience delivering penetration testing, adversary simulation, and compliance security assurance to organisations that take their cybersecurity risks seriously. The company provides human-led testing services across infrastructure, applications, cloud, mobile, AI, and IoT environments, tailored to clients’ security risk profiles and business needs, serving startups to enterprises across sectors including finance, healthcare, retail, and technology.

UK (national)

PrimoConnect

PrimoConnect is a Brighton-based IT security company providing penetration testing across networks, web and mobile applications, wireless environments and cloud platforms including AWS, Azure and Google Cloud. It also delivers cyber security awareness training, social engineering testing, vulnerability management, managed detection and response, forensic analysis and incident response. Compliance support covers ISO 27001, Cyber Essentials, SOC 2, NIST, DORA and ISO 42001, alongside cloud infrastructure delivery.

Brighton

RMG Cyber Consulting

RMG Cyber Consulting is a Lincoln-based cyber security firm providing penetration testing across web applications, cloud environments and infrastructure, including enterprise black box testing. It also delivers auditing and assurance services, offering Cyber Essentials certification, IASME Level 1 and 2 assessments and ISO 27001 support, alongside cybersecurity training, risk management and software development. RMG is a Cloud Security Alliance partner holding Trusted Cloud Consultant status.

Lincoln

Red Citadel

Red Citadel is a CREST-accredited penetration testing company based in Leamington Spa, offering security testing from £750 per day plus VAT. Services cover web application, internal and external infrastructure, PCI-DSS, API, mobile, social engineering and AI/LLM penetration testing, alongside vulnerability assessments, Microsoft 365 audits, Azure and AWS cloud security reviews, and Cyber Essentials and IASME assessments. Reports prioritise practical remediation, with findings shared early throughout each engagement.

Leamington Spa

Rootshell Security Ltd

Rootshell Security Ltd, based in Basingstoke, provides penetration testing as a service (PTaaS) through its Rootshell Platform. The company offers continuous penetration testing alongside firewall, cloud, wireless, infrastructure, web application and AI penetration testing, plus ransomware assessments, phishing assessments and red team engagements. Attack surface management services include external, infrastructure and web application scanning. It serves sectors including financial services, healthcare, government, defence, retail and education.

Basingstoke

SMARTSEC Information Security

SMARTSEC Information Security is a Wakefield-based offensive security testing company offering penetration testing across web applications, infrastructure and full red team engagements. It also tests AI systems — LLM deployments, agentic systems and RAG pipelines — and assesses non-human identities such as service accounts, tokens and agent credentials. Findings are delivered with reproduction steps, evidence and fixes.

Wakefield

Secario Labs

Secario Labs provides offensive cyber security services to modern organisations, operating in the UK and Bulgaria. Its services include application security testing for web and mobile applications, penetration testing that simulates real-world attack techniques, and adversary emulation (red team) engagements assessing defences across people, processes and technology. The company uses threat-intelligence-led mapping and testing to identify vulnerabilities and help clients reduce risk exposure and maintain compliance.

Crawley

Secarma Limited

Secarma is a Manchester-based cybersecurity company providing penetration testing and security services to businesses and global brands. Services span three areas: Advise (vCISO, threat modelling, incident response, maturity assessments), Certify (Cyber Essentials, IASME Cyber Assurance, IoT Cyber Scheme) and Test (web, mobile, cloud, infrastructure and wireless penetration testing, red teaming, vulnerability scanning). It also offers AI and LLM application security testing and has traded for 25 years.

Manchester

Sentrium Security

UK-based cybersecurity consultancy specialising in penetration testing, red teaming and secure code reviews.

UK

Sovereign Secure Limited

Sovereign Secure is a cyber security consultancy established in 2012, with offices in the UK, US, Singapore and the Middle East. A Qualified Security Assessor, it provides PCI DSS compliance services alongside penetration testing of web applications, mobile apps, networks, APIs, cloud environments and hardware. It also supports clients through Cyber Essentials, Cyber Essentials Plus and ISO 27001, serving public and private sector organisations worldwide.

Bolton

Wriggle Security

Wriggle Security is a cyber security firm based in Newcastle upon Tyne, established in 2017 with a team of seven specialists. The company helps businesses protect their websites, systems and networks through website security audits priced at £399 plus VAT, penetration testing to identify network vulnerabilities, security awareness training, GDPR compliance support and cyber liability insurance arranged with partner Todd and Cue Insurance.

Newcastle upon Tyne

Showing 145–168 of 169 providers

Search all 169 providers

Are you a Penetration Testing Services provider?

Get listed and reach thousands of potential customers looking for penetration testing services services.