APOLLOSEC

Penetration testing and cyber security in Wales

APOLLOSEC is a Welsh offensive security company, headquartered in Cardiff. We test the applications, networks, cloud and people of organisations across Wales, and work with clients across the UK and Europe.

Based in Wales

Our headquarters are on West Bute Street in Cardiff Bay, and Apollo Cybersecurity Ltd’s registered office is in Fishguard, Pembrokeshire. We work with organisations right across Wales: Cardiff and Newport, Swansea, Neath and Llanelli, Bridgend, west Wales and Pembrokeshire, and north Wales including Wrexham.

Most testing is delivered remotely, from the internet or through a VPN or small test device on your network. When the work needs us in the building, for wireless testing, physical intrusion or some internal network tests, our consultants come to you.

Who we work with in Wales

Our Welsh clients include energy companies such as Gas4Wales and Pembrokeshire Energy and a Welsh local council.

The work ranges from continuous attack surface management, which finds the systems an organisation has forgotten it exposes, to phishing simulations and social engineering tests of staff and processes.

The Welsh context

The Welsh Government’s Cyber Action Plan for Wales, published in 2022, sets out an ambition for a cyber-resilient Wales across public services, businesses and communities. Public bodies and their suppliers are increasingly asked for evidence that their security is tested, not just written down.

Operators of essential services in Wales, such as energy and drinking water, fall under the UK NIS Regulations, where regulators use the NCSC Cyber Assessment Framework. Independent testing, vulnerability management and incident exercises are some of the most direct evidence against it. If you also supply organisations in the EU, see what NIS2 and DORA mean for you.

Help available in Wales

Wales has a strong cyber community. The Cyber Resilience Centre for Wales supports small businesses and charities, Cyber Wales brings together people and companies working in the sector, and the National Cyber Security Centre publishes free guidance for every size of organisation.

When you need an independent test of your defences, that is where we come in.

From Welsh clients

“APOLLOSEC was great at uncovering our exposed services and their risks. The platform helps us understand and map assets to vulnerabilities and they took the time to really get to know our business.”
Gas4Wales
“APOLLOSEC not only secured our organisation but also pinpointed critical areas for improvement. Their collaborative approach and consistent communication made us active participants in the process.”
A local council in Wales
“APOLLOSEC expertly enhanced our defences against social engineering. They exposed hidden vulnerabilities and gave us actionable insights that improved our security posture.”
Pembrokeshire Energy

Questions we get asked

Do you only work in Cardiff?

No. We are headquartered in Cardiff but work with organisations across Wales, from Swansea and west Wales to Newport and north Wales, as well as across the UK and Europe. Most testing is remote, so location rarely limits what we can do.

Can you come on site in Swansea, Pembrokeshire or north Wales?

Yes. Wireless, physical and some internal network tests need us on site, and our consultants travel across Wales for them. We agree site visits when we scope the work.

Do you work with Welsh public sector organisations?

Yes. Our clients include a Welsh local council, and we understand the scrutiny public bodies and their suppliers face over security.

How quickly can you start?

It depends on scope and our schedule. Attack surface discovery can start as soon as the scope is agreed; penetration tests are booked once we have scoped the work with you.

Working in Wales? Let’s talk.

Talk to us