Forcent DevSecOps

Perimeter

Penetration testing

A scanner tells you what matched a signature. A test tells you what someone could actually do with it. We do the second thing, and the report is written for the engineer who has to fix it as much as the board that funded it.

What this covers

The work itself.

Web application and API testing

Authenticated and unauthenticated, following the OWASP Web Security Testing Guide as a floor rather than a ceiling. Business-logic flaws — the ones no scanner finds — are where most of the interesting results come from.

External and internal network

Perimeter testing from the outside, and assumed-breach testing from the inside, which is usually the more informative of the two. Lateral movement, privilege escalation, and what a foothold in one segment actually reaches.

Cloud configuration review

IAM policy analysis, exposed storage and services, network path review, and the chains where three individually-minor misconfigurations combine into account takeover.

Incident response and forensics

When something has already happened: scoping the compromise, establishing a timeline, and working out what was reachable rather than only what was touched.

How it runs

Engagement shape.

01

Scoping

We agree targets, rules of engagement, testing windows and escalation contacts in writing. Critical findings get reported immediately, not held back for the report.

02

Testing

Manual testing, tool-assisted where tools help. You get a named tester, and a channel to ask what they're seeing while they're seeing it.

03

Reporting

An executive summary that a non-technical reader can act on, and technical detail with reproduction steps and specific remediation — not a severity label and a vendor link.

04

Retest

Once you've fixed things, we verify the fixes and reissue the report. Included in the engagement, not billed as a second one.

What you get

Deliverables.

  • Executive summary written for a non-technical audience
  • Technical findings with reproduction steps and evidence
  • Findings ranked by exploitability, not just CVSS
  • Specific remediation guidance per finding
  • Retest and reissued report after remediation
  • Debrief call with your engineering team

Context

Where this comes up.

Testing is often triggered by a compliance requirement, and it's worth being clear about what that means. PCI DSS, SOC 2, ISO 27001, DORA and NIS2 all expect testing, but they differ in scope, frequency and how much independence they require.

We'll tell you honestly whether a given engagement satisfies your obligation, and where it doesn't. A test scoped to tick a box and a test scoped to find problems are not the same engagement, and it's better to know which one you're buying.

Certifications. Testing is delivered by a consultant holding OSCP (Offensive Security) and CREST CRT PEN, with prior UK SC clearance and CHECK Team Member status. Where a procurement process requires a specific accreditation, tell us early — we will say plainly whether we meet it rather than after you have shortlisted us.

Common questions

Before you ask.

How much does a penetration test cost?

It depends on scope, and anyone quoting before scoping is guessing. The variables are application count and complexity, number of user roles, network size, and whether testing is authenticated. A scoping call takes about half an hour and produces a fixed price.

Is the retest included?

Yes. Verifying that fixes actually worked is part of the engagement, not an upsell. A report describing problems nobody confirmed were solved has limited value.

Will testing disrupt production?

We agree that explicitly during scoping. Most testing is safe against production; anything with genuine disruption risk is either scheduled into a window, run against staging, or demonstrated rather than executed. We don't surprise you.

Do you test against a methodology?

OWASP WSTG for web and API work, PTES for engagement structure, and MITRE ATT&CK for describing post-exploitation activity. Methodology sets the floor for coverage; the findings that matter usually come from going past it.

Can you sign an NDA?

Yes, and we expect to. We'll also work under your rules of engagement and any client-side security requirements for handling findings.

Next step

Scoping calls are free.

Tell us what you're dealing with. If we're not the right fit we'll say so on the call, and usually point you at who is.