Penetration testing services
If there is a way in, we will find it. Manual testing the way a real adversary works, with findings you can act on. Run it once, on a schedule, or continuously through the platform.
What a penetration test is
A penetration test is an authorised, simulated attack on your systems. A consultant uses the same tools and techniques as a real attacker to find vulnerabilities, proves which can be exploited, and tells you how to fix them.
That is the difference from a vulnerability scan. A scan lists possible problems. A penetration test involves a person who understands context: which issues chain together into a breach, which matter to your business, and which are noise.
Choose a test type
Web applications and APIs
Authentication, access control and business logic flaws that scanners miss, in applications and APIs.
See what we test →Infrastructure and networks
External and internal networks and Active Directory: how far an attacker gets, and what to fix first.
See what we test →Cloud: AWS, Azure, Google Cloud
AWS, Azure, Google Cloud and Microsoft 365: configuration and real attack paths.
See what we test →Mobile applications
iOS and Android apps and the APIs behind them, aligned to OWASP MASVS.
See what we test →Wireless
Rogue access points, WPA2 and WPA3, enterprise authentication and guest networks.
See what we test →Physical intrusion
Tailgating, badge cloning and reception pretexts. Could someone walk in?
See what we test →How we test
Platform discovery first, so we test what you really expose, not just what is on the list. Then manual testing by a consultant who reads what the tools find.
- Findings as we discover them, in the portal, with evidence, so you can start fixing before the test ends.
- A tester you can talk to through the portal chat.
- A report within five working days of testing finishing, written for both technical and non-technical readers.
- A retest after you fix, to close each finding with evidence.
Who does the testing
Our consultants are practising penetration testers and red teamers. Between them they hold qualifications including OSCP, CRTO and the Cyber Scheme’s penetration testing certifications. These are held by the individuals, not the company.
We follow recognised methods: the OWASP testing guides for applications, and PTES and NIST SP 800-115 for infrastructure. Severity is rated with CVSS, adjusted for your context.



Penetration testing in Wales, the UK and Europe
APOLLOSEC is headquartered in Cardiff. We work with organisations across Wales, including a Welsh local council, Gas4Wales and Pembrokeshire Energy, and with clients across the UK and Europe.
Most testing is delivered remotely. External tests run from the internet, and internal tests run over a VPN or through a small test device you connect to your network. When an engagement needs people on site, such as wireless, physical or some internal testing, our consultants come to you.
More on our work across Wales. If you operate in the EU, we can also help you use testing to meet NIS2 and DORA requirements.