APOLLOSEC

Penetration testing services

If there is a way in, we will find it. Manual testing the way a real adversary works, with findings you can act on. Run it once, on a schedule, or continuously through the platform.

What a penetration test is

A penetration test is an authorised, simulated attack on your systems. A consultant uses the same tools and techniques as a real attacker to find vulnerabilities, proves which can be exploited, and tells you how to fix them.

That is the difference from a vulnerability scan. A scan lists possible problems. A penetration test involves a person who understands context: which issues chain together into a breach, which matter to your business, and which are noise.

How we test

Platform discovery first, so we test what you really expose, not just what is on the list. Then manual testing by a consultant who reads what the tools find.

  • Findings as we discover them, in the portal, with evidence, so you can start fixing before the test ends.
  • A tester you can talk to through the portal chat.
  • A report within five working days of testing finishing, written for both technical and non-technical readers.
  • A retest after you fix, to close each finding with evidence.

Who does the testing

Our consultants are practising penetration testers and red teamers. Between them they hold qualifications including OSCP, CRTO and the Cyber Scheme’s penetration testing certifications. These are held by the individuals, not the company.

We follow recognised methods: the OWASP testing guides for applications, and PTES and NIST SP 800-115 for infrastructure. Severity is rated with CVSS, adjusted for your context.

Offensive Security Certified Professional (OSCP) badgeCertified Red Team Operator (CRTO) badge from Zero-Point SecurityThe Cyber Scheme logo

Penetration testing in Wales, the UK and Europe

APOLLOSEC is headquartered in Cardiff. We work with organisations across Wales, including a Welsh local council, Gas4Wales and Pembrokeshire Energy, and with clients across the UK and Europe.

Most testing is delivered remotely. External tests run from the internet, and internal tests run over a VPN or through a small test device you connect to your network. When an engagement needs people on site, such as wireless, physical or some internal testing, our consultants come to you.

More on our work across Wales. If you operate in the EU, we can also help you use testing to meet NIS2 and DORA requirements.

Questions we get asked

How long does a penetration test take?

It depends on scope. A single web application or a small network typically takes a few days of testing; large estates or several applications take longer. We estimate the days needed when we scope the work with you.

How much does a penetration test cost?

Cost follows the number of testing days the scope needs, which depends on the size and complexity of what is being tested. We scope every test with you and quote before any work starts.

How often should we test?

At least once a year and after significant changes. A yearly test still leaves eleven months in which new assets and vulnerabilities go unseen, which is why many clients pair testing with continuous attack surface management on the platform.

Why do we need to sign an authorisation form?

Testing systems without permission is an offence under the Computer Misuse Act 1990. Before we start, you sign an authorisation setting out what we may test, when and from which addresses. It protects you and us, and helps your team tell our testing apart from a real attack.

Will testing disrupt our business?

We plan testing to avoid disruption, schedule around your busy periods and avoid techniques that risk availability unless you ask for them. If anything unexpected happens, we stop and tell you.

What happens if you find something critical?

We tell you straight away, not at the end of the test, with advice on what to do. Critical findings also appear in the portal as soon as we confirm them.

Tell us what you want tested.

Talk to us