Compare Penetration Testing Providers UK (2026)
Compare Scope, Tester Assurance, Methodology, Reporting, Retesting And Cost
Compare penetration testing for UK businesses by scope, tester competence, accreditation, methodology, exploitation depth, rules of engagement, safety controls, reporting, remediation guidance, retesting, evidence, timelines and total cost. Evaluate providers against the same infrastructure, web, API, mobile, cloud, wireless or specialist-system requirements before authorising intrusive security testing.

A Penetration Test Must Be Authorised And Precisely Scoped
The tester is deliberately attempting to identify and validate exploitable weaknesses. Ambiguous targets, ownership or stop conditions can create avoidable business and legal risk.
- Confirm asset ownership and written permission for every target
- Define test objectives, exclusions, time windows and escalation contacts
- Agree safe exploitation, data handling and immediate-stop conditions
- Plan remediation ownership and retesting before the test begins
Penetration testing is an authorised point-in-time assessment in which qualified security testers simulate realistic attack techniques against an agreed system, application or environment. The purpose is to identify weaknesses, determine whether they can be exploited, explain the likely business impact and provide practical remediation advice.
A penetration test is not the same as automated vulnerability scanning. Scanners can identify known weaknesses and configuration issues at scale, but manual testers analyse context, chain findings, test business logic, validate attack paths and distinguish exploitable risk from noise. A good engagement may use automated tools, but consultant-led reasoning and controlled exploitation remain central.
This page does not compare ongoing managed security, continuous monitoring or security-awareness services. An MSSP monitors and operates security controls over time, while a penetration test assesses an agreed target during a defined engagement. Employee awareness and phishing education have their own service page. Continuous vulnerability management also remains separate from this point-in-time testing comparison.
Choose The Right Type Of Penetration Test
Different targets require different skills, access, safety controls and reporting. Avoid buying a generic number of tester days before defining the actual attack surface.
| Test Type | What It Usually Assesses | Best-Fit Question |
|---|---|---|
| External infrastructure test | Assesses internet-facing hosts, services, remote-access systems and network devices from an external attacker perspective | Are all authorised domains, addresses, cloud services and third-party-owned targets included and current? |
| Internal infrastructure test | Assesses network segmentation, configuration, authentication, privilege escalation and lateral movement from an internal starting point | Which user, device, location and assumed compromise level should the tester begin with? |
| Web application test | Tests authentication, authorisation, session management, input handling, business logic, configuration and client-side risks | Are every role, workflow, API, tenant, integration and non-production dependency represented? |
| API penetration test | Assesses API authentication, object-level access, rate limits, data exposure, injection, business logic and abuse paths | Will the tester receive complete endpoint documentation, test accounts, schemas and representative data? |
| Mobile application test | Assesses the mobile application, local storage, communications, authentication, APIs and platform-specific controls | Does the scope include both the application package and the backend services it depends on? |
| Cloud penetration test | Tests authorised cloud identities, configurations, workloads, applications and attack paths within provider rules | Which cloud-provider testing policies, tenant permissions and customer responsibilities apply? |
| Wireless and onsite test | Assesses wireless networks, segmentation, client isolation and authorised onsite infrastructure | Are premises access, safety, radio scope, guest networks and physical restrictions clearly documented? |
| Specialist product, IoT or OT test | Assesses connected products, embedded devices, industrial systems or specialist platforms using tailored techniques | Can the supplier demonstrate relevant technical experience and a testing approach that protects safety and availability? |
Eight Areas That Determine Penetration-Testing Quality
Use the same engagement criteria for every provider so accreditation badges, tester-day estimates and vulnerability counts do not hide weak scope or reporting.
Comparison Criterion
Scope, Objectives And Asset Ownership
Compare the provider’s discovery and scoping process, including target lists, domains, addresses, applications, APIs, user roles, cloud accounts, environments, third parties, exclusions, assumptions and desired assurance outcome. The supplier should challenge an incomplete scope before pricing.
Comparison Criterion
Tester Competence And Assurance
Review company accreditation, individual qualifications, relevant technical experience, sector work and quality assurance. CREST membership can provide organisational assurance, while CHECK is intended for NCSC-assured testing of public-sector and CNI systems. Match tester expertise to the exact technology.
Comparison Criterion
Methodology And Manual Testing Depth
Assess how the supplier combines reconnaissance, automated discovery, manual analysis, exploitation, privilege escalation, business-logic testing and validation. For web and API work, require coverage mapped to current application-security testing practices rather than an automated scan with a consultant logo.
Comparison Criterion
Rules Of Engagement And Safety
Define written authorisation, source addresses, time windows, communication, data access, denial-of-service exclusions, persistence, social engineering, production restrictions, backup, stop conditions and emergency contacts. Safety controls should reflect the target’s operational impact.
Comparison Criterion
Access, Test Accounts And Knowledge Level
Compare black-box, grey-box and white-box approaches. Determine which architecture, source code, credentials, roles, logs and documentation improve coverage. Withholding useful information does not automatically make the test more realistic and can reduce assurance within a fixed budget.
Comparison Criterion
Findings, Risk And Reporting
Review the report structure, technical evidence, attack narrative, affected assets, reproducibility, severity method, business impact, remediation, root cause, management summary and handling of sensitive details. A finding list without context or fix guidance is difficult to action.
Comparison Criterion
Remediation Support And Retesting
Confirm debriefs, developer or infrastructure workshops, clarification, fix review, retest scope, time window, evidence and updated report. A retest should validate the affected weakness and relevant attack path without being represented as a complete new assessment.
Comparison Criterion
Data Handling, Quality And Exit
Assess tester devices, encrypted communication, evidence storage, access control, subcontractors, retention, destruction, report delivery, conflict handling, insurance, complaints, secure deletion and return of credentials or test accounts. Treat the supplier as a temporary privileged party.
Measures To Define Before A Pen Test Is Commissioned
Translate comprehensive and expert-led into measurable scope, execution, evidence, reporting, remediation and safety outcomes.
| Measure | What It Should Define | Evidence To Request | Common Weakness |
|---|---|---|---|
| Scope completeness | Whether every authorised target, role, interface and environment required for the objective was tested | Final scope, exclusions, changes, unavailable targets, untested roles, owner and impact | A fixed quote is accepted before the application and asset inventory is complete |
| Test execution against plan | Whether the engagement delivered the agreed methodology, tester time and coverage | Dates, consultants, targets, techniques, interruptions, constraints and approved changes | The report does not explain where time was lost to unavailable systems or access problems |
| Validated finding rate | Whether reported weaknesses are manually confirmed and supported by sufficient evidence | Finding, validation, exploitability, affected asset, evidence, false-positive process and reviewer | Automated scanner output is copied into the report without consultant validation |
| Critical attack-path coverage | Whether important combinations of weaknesses and privileges were assessed safely | Starting position, steps, dependencies, achieved access, business impact and stop condition | Findings are reported individually while a practical chain to sensitive data is missed |
| Reporting timeliness | Whether urgent findings, draft reports and final reports arrive within agreed times | Immediate notification, test completion, draft, review comments, final and delay reason | Critical findings wait for the final report even though early action was possible |
| Remediation action quality | Whether recommendations are specific, proportionate and assigned to owners | Root cause, recommended control, priority, owner, due date, dependency and accepted alternative | Advice says only to patch or follow best practice without identifying the required change |
| Retest closure | Whether agreed fixes were validated and the result recorded accurately | Original finding, changed component, retest method, evidence, closed, partially resolved or open | A supplier marks a finding resolved from a screenshot without retesting the target |
| Testing safety and incidents | Whether the engagement avoided or controlled operational impact and handled unexpected effects | Event, target, time, stop decision, communication, recovery, cause and improvement | Minor outages and account lockouts are excluded from project reporting |
| Stakeholder acceptance | Whether technical and business owners understand the findings and next actions | Debrief attendance, questions, disputed risk, accepted report, owners and escalation | The report is delivered to procurement without a technical handover |
| Total cost per completed scope | The complete scoping, testing, reporting, travel, retest and internal coordination cost | Targets, tester days, specialist roles, expenses, retest, workshops, project management and changes | A low day rate hides narrow coverage, travel or separate retesting charges |
Penetration Testing Providers UK Businesses Can Consider
Shortlist providers whose tester competence, specialist experience, methodology and reporting fit the target. Confirm current accreditation, availability and pricing directly before award.
Provider Profile
NCC Group Penetration Testing
NCC Group provides penetration testing across infrastructure, applications, products, cloud, mobile, networks and specialist environments, alongside red-team and other assurance services. Include NCC Group where a business needs broad technical depth, complex scope or access to specialist testing disciplines. Confirm the exact service and methodology, proposed tester experience, location, accreditation required for the engagement, rules of engagement, report format, remediation support, retest terms, project management and whether specialist work is priced separately.
Review official NCC Group testing servicesProvider Profile
LRQA Penetration Testing Services
LRQA offers penetration testing across web, mobile, cloud, infrastructure, connected products and other specialist areas, with CREST-certified expertise and a documented multi-stage testing approach. Include LRQA where a business values broad assurance capability and links to wider regulatory or resilience services. Confirm the exact testing team, scope, accreditation, data location, methodology, exploitation restrictions, report review, remediation support, optional retesting, travel and the boundary from LRQA’s ongoing assurance or managed services.
Review official LRQA penetration testingProvider Profile
Bridewell Penetration Testing
Bridewell provides tailored testing for IT, OT, applications, infrastructure and critical environments, with current positioning around highly regulated and critical organisations. Include Bridewell where operational technology, CNI, complex environments or NCSC CHECK assurance may be relevant. Confirm whether CHECK is actually required for the target, tester availability, sector and technology experience, onsite needs, safety restrictions, test evidence, report format, retesting, travel and the separation from red-team or social-engineering engagements.
Review official Bridewell penetration testingProvider Profile
Integrity360 Penetration Testing
Integrity360 offers infrastructure, application, API, wireless, cloud, IoT, OT and related testing, including a penetration-testing-as-a-service option for organisations requiring repeatable access to testing. Include it where a business wants a broad European provider or testing linked to other cyber services. Confirm whether the proposal is a one-off test or PTaaS, named scope, test credits or days, delivery location, manual depth, report and portal access, remediation support, retesting and any dependency on Integrity360’s wider services.
Review official Integrity360 penetration testingProvider Profile
WorkNest Secure Penetration Testing
WorkNest Secure combines penetration-testing capability associated with Pentest People and Bulletproof under the current WorkNest brand. Its service covers applications, networks, cloud, web, APIs and CHECK or CREST-accredited routes, supported by the GuardNest platform. Include it where an SME values accessible UK delivery, portal-led findings and a broad testing catalogue. Confirm the legal contracting entity, tester team, portal and report ownership, exact accreditation, automated versus manual work, retesting, subscription options and the boundary from continuous scanning.
Review official WorkNest Secure testingProvider Profile
Cyberis Reply Penetration Testing
Cyberis Reply is a UK CREST-accredited penetration-testing provider covering infrastructure, applications, cloud, mobile and web services, with wider red-team and specialist assurance capability. Include Cyberis where technical depth, regulated-sector testing or complex attack-path analysis matters. Confirm the proposed consultants, current company and individual assurance, CHECK or CBEST relevance, testing location, scope assumptions, source-code or architecture access, evidence handling, remediation workshop, retest and the commercial boundary from advanced attack simulation.
Review official Cyberis Reply testingProvider Profile
Pen Test Partners
Pen Test Partners provides CHECK and CREST-accredited testing across applications, infrastructure, cloud, APIs, mobile, connected systems and specialist environments including OT, transport and embedded technology. Include it where unusual hardware, connected products or complex operational systems require demonstrated specialist experience. Confirm the exact tester background, safety engineering, authorised targets, travel, laboratory or onsite work, data handling, report and disclosure process, retesting and whether a standard penetration test or a separate specialist engagement is appropriate.
Review official Pen Test Partners serviceProvider Profile
Risk Crew Penetration Testing
Risk Crew, now part of the Red Helix family, provides network, web application, cloud, IoT and other penetration-testing services with a risk-led approach and optional retesting. Include it where a business wants a UK specialist combining technical testing with governance and risk context. Confirm the current contracting and delivery entity, accreditation, tester qualifications, exact methodology, report and evidence, data handling, included retest, onsite or remote delivery, service-level commitments and the separation from ongoing compliance or managed services.
Review official Risk Crew testingWhat Changes Penetration Testing Cost
The tester day rate is only one component. Scope quality, specialist skills, safety, reporting and retesting materially affect the engagement value.
| Cost Driver | Why It Changes Spend | What A Comparable Proposal Should Show |
|---|---|---|
| Target type and technical complexity | A standard external network, authenticated web application, cloud estate, mobile app, OT system and connected product require different skills and preparation | Exact targets, technologies, versions, architecture, integrations, users, environments and specialist requirements |
| Scope size and attack surface | Hosts, addresses, APIs, screens, user roles, functions, cloud accounts and locations influence tester time | Count and complexity by target, assumptions, exclusions, discovery allowance and change process |
| Knowledge and access level | Black-box, grey-box and white-box testing use different reconnaissance, credentials, documentation and source access | Accounts, roles, source code, architecture, API documentation, test data and expected coverage |
| Testing depth and objectives | Compliance validation, exploit confirmation, attack-path analysis, business-logic testing and specialist research require different effort | Required techniques, safe exploitation, evidence, prohibited actions, assurance outcome and stop conditions |
| Accreditation and tester seniority | CHECK, CREST and specialist individual qualifications may influence availability and price | Required organisational scheme, individual competence, named roles, substitutions and evidence |
| Production safety and scheduling | Out-of-hours work, onsite testing, fragile systems, operational technology, change freezes and standby support add planning | Windows, locations, travel, support contacts, backups, safety restrictions and incident handling |
| Reporting and stakeholder support | Executive reporting, detailed evidence, developer workshops, risk mapping and presentation require additional consultant time | Report audiences, format, scoring, debriefs, workshops, disputed findings and delivery dates |
| Retesting and remediation assistance | Some quotes include one limited retest while others charge separately for validation or consultancy | Retest window, findings included, evidence, report update, additional testing and advisory rates |
| Project changes and unavailable targets | Late scope, inaccessible systems, unstable environments and missing accounts can create delay or extra days | Readiness responsibilities, cancellation, rescheduling, unused time, change rates and acceptance |
| Travel, tax and commercial terms | Onsite work, international targets, expenses, minimum days and contract terms affect total cost | Professional fees, expenses, VAT, payment, minimums, insurance, liability, term and price validity |
How The Target Changes The Provider Shortlist
The right provider depends on target technology, regulatory assurance, operational risk, available documentation and who must remediate the findings.
Small Business Web Or External Test
Prioritise clear fixed scope, CREST-accredited delivery where appropriate, practical reporting, direct access to the tester, an included debrief and one proportionate retest after fixes.
Software Or SaaS Business
Prioritise application, API, authentication, authorisation, tenant separation and business-logic depth, with multiple roles, architecture context, source or documentation access and developer-ready remediation.
Public Sector Or CNI Environment
Prioritise whether CHECK is required, assured provider status, suitably qualified personnel, sensitive-data handling, operational safety, formal reporting and procurement routes appropriate to the system.
Specialist, OT Or Connected Product
Prioritise demonstrable experience with the exact technology, safety constraints, laboratory or onsite requirements, hardware and firmware analysis, responsible disclosure and reports that operational teams can act on.
How To Compare Pen Test Proposals
Give every provider the same target inventory, architecture, roles, interfaces, objectives, knowledge level, constraints, test windows, reporting audiences and retest requirement. Require each response to identify proposed tester skills, assumptions, exclusions and how scope changes are controlled.
- Every target has a verified owner and written testing authority
- Methodology and tester competence match the technology
- Unsafe actions, data handling and stop conditions are explicit
- Reports include evidence, impact, root cause and practical remediation
- Retest scope and timing are priced consistently
- Credentials, evidence and reports are deleted or transferred securely
Make Every Provider Scope The Same Attack Surface
Give each finalist the same application roles, APIs, network ranges, cloud services, dependencies and excluded production actions.
Compare uncovered assumptions, proposed coverage, tester suitability and report examples before comparing price.
Six Questions To Put To Every Penetration-Testing Provider
The answers expose weak scope, unsuitable tester experience, unsafe assumptions and incomplete remediation support before authorisation.
Who Will Perform The Test?
Request proposed tester roles, relevant technical experience, current individual qualifications, organisational accreditation, substitutions and quality-review arrangements.
What Is Included And Explicitly Excluded?
Confirm targets, roles, interfaces, environments, discovery, source code, social engineering, denial-of-service, third parties, cloud rules and unavailable systems.
How Will Testing Be Kept Safe And Authorised?
Ask for written rules of engagement, source addresses, windows, backups, stop conditions, emergency contacts, evidence handling and unexpected-impact response.
How Will Findings Be Validated And Reported?
Require manual validation, attack narrative, reproducible evidence, severity rationale, business impact, root cause, remediation and executive summary.
What Remediation Support And Retest Are Included?
Confirm debrief, technical workshop, clarification period, retest findings, time window, evidence, updated report and charges for broader testing.
How Will Sensitive Data And Access Be Closed?
Confirm test accounts, credentials, downloaded data, screenshots, reports, storage, subcontractors, retention, destruction, return and written deletion evidence.
A Seven-Stage Penetration Testing Evaluation
Move from verified ownership and scope to completed remediation rather than buying tester days before the target and objective are understood.
- Identify the business objective, target owner, target inventory, architecture, data sensitivity, users, dependencies, regulation and previous findings.
- Select the appropriate infrastructure, web, API, mobile, cloud, wireless or specialist test while keeping ongoing monitoring and awareness services separate.
- Define written scope, knowledge level, test accounts, exclusions, windows, communications, safe exploitation, stop conditions and evidence handling.
- Issue one written brief and obtain comparable tester, methodology, schedule, report, retest, assurance and commercial responses.
- Complete supplier due diligence and a readiness review covering ownership, backups, contacts, access, test data, third-party permission and operational support.
- Run the authorised test with controlled communication, immediate escalation for serious findings, change records and documented scope variations.
- Review the report, assign remediation, hold the technical debrief, retest agreed fixes and retain evidence for governance before closing access.
Penetration Testing Comparison Checklist
Use this table before authorising a penetration test or signing a testing statement of work.
| No. | Requirement | Evidence To Obtain Before Award | Confirmed |
|---|---|---|---|
| 01 | Business objective and accountable owner agreed | Assurance need, business impact, decision, risk owner, technical owner and report audience | |
| 02 | Target ownership and written authority confirmed | Domains, addresses, applications, APIs, cloud, devices, third parties and signed permission | |
| 03 | Exact testing scope documented | Targets, roles, functions, environments, interfaces, dependencies, exclusions and assumptions | |
| 04 | Test type and knowledge level selected | External, internal, web, API, mobile, cloud, wireless or specialist; black, grey or white box | |
| 05 | Provider and tester assurance verified | Company accreditation, individual qualifications, relevant experience, proposed team and quality reviewer | |
| 06 | Rules of engagement approved | Dates, source addresses, communications, safe exploitation, prohibited actions, stop conditions and escalation | |
| 07 | Cloud and third-party permissions obtained | Provider policy, tenant owner, hosting provider, supplier approval, shared services and restrictions | |
| 08 | Environment readiness tested | Accounts, roles, data, backups, monitoring, support contacts, stable release and access validation | |
| 09 | Sensitive-data handling accepted | Collection, minimisation, encryption, tester devices, storage, sharing, retention, deletion and subcontractors | |
| 10 | Methodology and coverage agreed | Reconnaissance, automated tools, manual testing, business logic, exploitation, chaining and evidence | |
| 11 | Reporting and severity model accepted | Management summary, technical detail, evidence, impact, root cause, scoring, remediation and appendices | |
| 12 | Immediate critical-finding process agreed | Severity threshold, notification, verification, recipients, containment advice and decision record | |
| 13 | Remediation and retest terms agreed | Owners, clarification, workshop, retest window, included findings, evidence, report update and extra charges | |
| 14 | Complete engagement cost compared | Scoping, test days, specialists, project management, travel, reporting, debrief, retest and changes | |
| 15 | Closure and evidence retention agreed | Credentials, test accounts, access, reports, raw evidence, deletion proof, lessons and follow-up testing |
Common Penetration Testing Buying Mistakes
Most avoidable failures begin with unclear permission, scanner-led delivery, unsuitable tester skills or a report that is never converted into remediation.
| Mistake | Why It Creates Risk | Better Control |
|---|---|---|
| Buying a vulnerability scan as a penetration test | Automated findings may not validate exploitability, business logic or attack chains | Require consultant-led manual testing |
| Starting before target ownership is confirmed | Testing a third party or shared service without permission creates legal and operational risk | Obtain written authority for every target |
| Selecting an MSSP for a one-off test without checking specialist competence | Ongoing security-operation capability does not prove offensive-testing depth | Assess the proposed testers and methodology |
| Adding staff awareness work to the penetration-test scope | Human education and phishing programmes have different objectives and buying criteria | Keep security-awareness procurement separate |
| Choosing only by tester day rate | An incomplete scope, junior team or weak report can cost less but deliver little assurance | Compare complete accepted coverage and outputs |
| Withholding all architecture and credentials | A fixed engagement spends time discovering basics and may miss deeper weaknesses | Choose the knowledge level deliberately |
| Testing production without stop conditions | Unexpected load, account lockout or data change can affect live services | Use approved safety rules and contacts |
| Accepting vulnerability counts as value | More findings do not necessarily mean better testing or higher business risk | Review validated attack paths and impact |
| Leaving remediation until the next annual test | Known exploitable weaknesses remain open and are reported repeatedly | Assign owners and retest material fixes |
| Failing to close tester access and evidence | Credentials, test accounts and sensitive reports remain exposed after delivery | Complete documented access and data closure |
Frequently Asked Questions
Answers to common questions from UK businesses comparing authorised penetration-testing providers.
What Is Penetration Testing?
Penetration testing is an authorised point-in-time security assessment in which qualified testers simulate realistic attack techniques against an agreed system, application or environment. The engagement identifies exploitable weaknesses, explains likely impact and provides remediation guidance.
How Is A Penetration Test Different From A Vulnerability Scan?
A vulnerability scan uses automated tools to identify known weaknesses at scale. A penetration test combines tools with manual analysis, validates exploitability, tests business logic and may chain weaknesses into realistic attack paths. A good test may include scanning, but it is not only scanner output.
How Is Penetration Testing Different From An MSSP?
A penetration test assesses an agreed target during a defined engagement. An MSSP monitors and operates security controls continuously across a wider environment. A provider may offer both, but the scope, personnel, authorisation, reporting and commercial model are different.
What Is The Difference Between CREST And CHECK?
CREST accredits cyber security service providers and certifies individual practitioners. CHECK is the NCSC scheme under which assured companies conduct authorised penetration tests of public-sector and critical-national-infrastructure systems. CHECK is required only where the relevant buyer or system demands it.
What Systems Can Be Penetration Tested?
Common targets include external and internal infrastructure, web applications, APIs, mobile apps, cloud environments, wireless networks, connected products and operational technology. The supplier should have relevant experience and adapt safety controls to the technology.
How Often Should A Business Run A Penetration Test?
Frequency depends on risk, regulation, customer commitments and system change. Common triggers include a new internet-facing service, major release, architecture change, cloud migration, material incident or annual assurance cycle. Testing does not replace continuous vulnerability and security management.
How Much Does Penetration Testing Cost?
Cost depends on target type, scope, complexity, knowledge level, tester seniority, safety, onsite work, reporting and retesting. Compare total cost for a completed scope, including project management and remediation support, rather than only a day rate.
Can A Penetration Test Disrupt A Live System?
Yes, intrusive testing can cause unexpected load, account lockouts, data changes or service interruption. Reduce risk through a stable test environment where practical, backups, approved windows, prohibited actions, stop conditions, live contacts and experienced testers.
What Should A Penetration Test Report Include?
The report should include scope, methodology, constraints, executive summary, validated findings, affected targets, evidence, exploitation context, business impact, severity rationale, root cause, practical remediation and a retest outcome where fixes are checked.
How Should A UK Business Compare Penetration Testing Providers?
Give every provider the same targets, roles, objective, access, constraints, report and retest requirement. Compare tester competence, methodology, rules of engagement, sample reporting, safety, remediation support, total cost and evidence closure—not only accreditation or tester days.
Provider Information And UK Penetration-Testing Resources
Reviewed by Bhav Giva, Founder & Lead Analyst at CompareServices.co.uk, on 16 July 2026.
Use NCSC, CREST, OWASP and official provider documentation to confirm current accreditation, methodology, tester competence, service scope, report outputs, retesting and commercial terms. Provider ownership and assurance status can change during procurement.
- NCSC — Penetration Testing Guidance
- NCSC — Information For CHECK Buyers
- NCSC — Find An Assured CHECK Provider
- CREST — Cyber Security Services And Supplier Assurance
- OWASP — Web Security Testing Guide
- NCC Group — Penetration Testing Services
- LRQA — Penetration Testing Services
- Bridewell — Penetration Testing
- Integrity360 — Penetration Testing
- WorkNest Secure — Penetration Testing
- Cyberis Reply — Penetration Testing
- Pen Test Partners — Penetration Testing
- Risk Crew — Penetration Testing
