Penetration Testing Services
Authorised simulated attack and vulnerability testing
Find partners
CyberGaar
CyberGaar is a cyber security company in Cheltenham providing security audits, penetration testing and vulnerability scanning to help organisations understand and reduce cyber risk. Services include manual penetration testing across web, mobile, network, cloud, wireless and social engineering; web application and API testing; cloud security reviews; and readiness support for Cyber Essentials, ISO 27001, SOC 2 and PCI DSS. It serves sectors including financial services, healthcare, technology and critical infrastructure.
Cyserch
Cybersecurity consultancy offering penetration testing, risk assessments and incident response.
FORTIFI CYBER SECURITY
This company delivers CREST-accredited penetration testing services, including web application, network, mobile application, and large language model testing, along with attack surface assessments and red and purple teaming. It provides human-led risk-based security testing, clear reporting, and remediation support to help protect businesses across various sectors from cyber security threats.
Heretek
Heretek is a Bromley-based cyber security testing firm offering vulnerability assessments, penetration testing and adversary simulation through threat-led red team engagements. Additional services include managed vulnerability scanning, purple team work building countermeasures alongside client teams, and advisory consulting from security leaders. It serves MSPs, resellers, partners and direct clients, from startups and scale-ups to enterprises, reporting findings through an online platform with remediation guidance.
ILLUME SECURITY
Illume Security provides penetration testing and security assurance services to organisations across the UK. Its offerings include network, web application, and API testing, alongside red team exercises, social engineering, cloud security assessments, and Active Directory password auditing. The CREST-accredited firm helps legal, accounting, manufacturing, fintech, food, beverage, and construction clients identify cyber vulnerabilities.
Incursion Cyber Security
Incursion Cyber Security is a boutique cyber security consultancy in Bath, founded by a former British Intelligence Analyst. The team delivers penetration testing with precisely scoped engagements and clear, actionable insights rather than templated reports. They also guide SMEs through IASME Cyber Essentials certification with practical, hands-on support, and help businesses achieve IASME Cyber Assurance accreditation by developing robust policies and providing continuous compliance support.
Information Risk Management Ltd
IRM is a cybersecurity consultancy founded in 1998 and part of the Capgemini Group. From Woking, it provides penetration testing, security assessments and red teaming across IT networks, operational technology and embedded systems, alongside GRC consultancy, managed security services and its SYNERGi governance platform. It serves sectors including automotive, telecommunications, energy, finance, public sector and transport, supporting compliance and cyber-maturity.
Logically Secure
Logically Secure provides cyber security testing and incident response services. Its testing portfolio covers penetration testing, web application, mobile application, wireless, phishing and red team testing, plus cloud review and testing. The company also develops CyberCPR, an incident and case management platform that lets teams record findings, store evidence securely and collaborate on sensitive incidents under need-to-know access controls. Consulting services are also offered.
MDSec Consulting Ltd
MDSec Consulting is a Macclesfield-based security consultancy offering penetration testing, adversary simulation, application security and incident response services. Its CBEST-certified ActiveBreach red team simulates real adversary tactics across the cyber kill chain, while its response team supports customers at all stages of the incident response lifecycle. The company also publishes security research and delivers training courses informed by its consultancy work, serving clients from technology firms to financial institutions.
Nanorisk
Nanorisk is a UK-based, independent cyber security consultancy delivering penetration testing and security assessments across infrastructure, applications and social engineering scenarios. Services include vulnerability assessments, bespoke adversary-focused testing and simulations, and Cyber Essentials and Cyber Essentials Plus certification via a partner. Engagements are managed through a dedicated security portal covering communication, findings and reporting, with documentation provided for each assessment.
Net Sec Group
Net Sec Group is a London-based cybersecurity firm led by a CREST Registered Penetration Tester and operating as an IASME Cyber Essentials Certification Body. Offensive services include web application, network infrastructure, API, mobile and wireless testing, social engineering and secure code review. Its Cyber 365 programme provides 24/7 SOC monitoring, continuous vulnerability scanning and patch management, guiding clients through Cyber Essentials and Cyber Essentials Plus certification.
OmniCyber Security Limited
OmniCyber Security is a boutique cyber security firm based in the UK and Canada, serving clients worldwide including financial institutions, retail chains, governments and technology companies. It provides CREST-accredited penetration testing, red teaming, vulnerability scanning, web, mobile and API testing, social engineering and continuous adversary emulation, alongside compliance services covering Cyber Essentials, ISO 27001, PCI DSS and GDPR, plus virtual CISO support, security training and phishing simulations.
Pen Test Partners
Pen Test Partners provides cybersecurity services including penetration testing, red teaming, incident response, digital forensics, security training, and compliance assessments for organisations across finance, healthcare, retail, transport and other sectors. They help clients identify vulnerabilities, simulate attacks, meet regulatory standards, and improve security maturity through tailored testing and advisory solutions.
Pentest Limited
Pentest Limited is a CREST-accredited offensive cybersecurity firm with over 25 years’ experience delivering penetration testing, adversary simulation, and compliance security assurance to organisations that take their cybersecurity risks seriously. The company provides human-led testing services across infrastructure, applications, cloud, mobile, AI, and IoT environments, tailored to clients’ security risk profiles and business needs, serving startups to enterprises across sectors including finance, healthcare, retail, and technology.
PrimoConnect
PrimoConnect is a Brighton-based IT security company providing penetration testing across networks, web and mobile applications, wireless environments and cloud platforms including AWS, Azure and Google Cloud. It also delivers cyber security awareness training, social engineering testing, vulnerability management, managed detection and response, forensic analysis and incident response. Compliance support covers ISO 27001, Cyber Essentials, SOC 2, NIST, DORA and ISO 42001, alongside cloud infrastructure delivery.
RMG Cyber Consulting
RMG Cyber Consulting is a Lincoln-based cyber security firm providing penetration testing across web applications, cloud environments and infrastructure, including enterprise black box testing. It also delivers auditing and assurance services, offering Cyber Essentials certification, IASME Level 1 and 2 assessments and ISO 27001 support, alongside cybersecurity training, risk management and software development. RMG is a Cloud Security Alliance partner holding Trusted Cloud Consultant status.
Red Citadel
Red Citadel is a CREST-accredited penetration testing company based in Leamington Spa, offering security testing from £750 per day plus VAT. Services cover web application, internal and external infrastructure, PCI-DSS, API, mobile, social engineering and AI/LLM penetration testing, alongside vulnerability assessments, Microsoft 365 audits, Azure and AWS cloud security reviews, and Cyber Essentials and IASME assessments. Reports prioritise practical remediation, with findings shared early throughout each engagement.
Rootshell Security Ltd
Rootshell Security Ltd, based in Basingstoke, provides penetration testing as a service (PTaaS) through its Rootshell Platform. The company offers continuous penetration testing alongside firewall, cloud, wireless, infrastructure, web application and AI penetration testing, plus ransomware assessments, phishing assessments and red team engagements. Attack surface management services include external, infrastructure and web application scanning. It serves sectors including financial services, healthcare, government, defence, retail and education.
SMARTSEC Information Security
SMARTSEC Information Security is a Wakefield-based offensive security testing company offering penetration testing across web applications, infrastructure and full red team engagements. It also tests AI systems — LLM deployments, agentic systems and RAG pipelines — and assesses non-human identities such as service accounts, tokens and agent credentials. Findings are delivered with reproduction steps, evidence and fixes.
Secario Labs
Secario Labs provides offensive cyber security services to modern organisations, operating in the UK and Bulgaria. Its services include application security testing for web and mobile applications, penetration testing that simulates real-world attack techniques, and adversary emulation (red team) engagements assessing defences across people, processes and technology. The company uses threat-intelligence-led mapping and testing to identify vulnerabilities and help clients reduce risk exposure and maintain compliance.
Secarma Limited
Secarma is a Manchester-based cybersecurity company providing penetration testing and security services to businesses and global brands. Services span three areas: Advise (vCISO, threat modelling, incident response, maturity assessments), Certify (Cyber Essentials, IASME Cyber Assurance, IoT Cyber Scheme) and Test (web, mobile, cloud, infrastructure and wireless penetration testing, red teaming, vulnerability scanning). It also offers AI and LLM application security testing and has traded for 25 years.
Sentrium Security
UK-based cybersecurity consultancy specialising in penetration testing, red teaming and secure code reviews.
Sovereign Secure Limited
Sovereign Secure is a cyber security consultancy established in 2012, with offices in the UK, US, Singapore and the Middle East. A Qualified Security Assessor, it provides PCI DSS compliance services alongside penetration testing of web applications, mobile apps, networks, APIs, cloud environments and hardware. It also supports clients through Cyber Essentials, Cyber Essentials Plus and ISO 27001, serving public and private sector organisations worldwide.
Wriggle Security
Wriggle Security is a cyber security firm based in Newcastle upon Tyne, established in 2017 with a team of seven specialists. The company helps businesses protect their websites, systems and networks through website security audits priced at £399 plus VAT, penetration testing to identify network vulnerabilities, security awareness training, GDPR compliance support and cyber liability insurance arranged with partner Todd and Cue Insurance.
Showing 145–168 of 169 providers
Search all 169 providersAre you a Penetration Testing Services provider?
Get listed and reach thousands of potential customers looking for penetration testing services services.