“IG-Smart Ltd has proven to be an indispensable ally in safeguarding our digital assets.”

Cyber Resilience & Supplier Assurance · Security testing
Penetration Testing
Authorised, controlled testing of the systems your organisation depends on — with evidence-based findings your technical teams can remediate and your leadership can act on.
- Authorise
- Scope
- Test
- Escalate
- Report
- Retest
Not sure this is the right service? Find the Right Service
- Qualified specialistsUK and international testing expertise
- Controlled & authorisedTesting governed by agreed rules of engagement
- Evidence-led reportingTechnical findings translated for remediation and leadership
When this service fits
When independent testing evidence is needed
A new system or major change is going live
Independent testing before launch or after significant change.
Customers, procurement or tenders require independent security evidence
Buyers and frameworks ask for proof that systems have been tested.
Security or assurance programmes need technical validation
ISO/IEC 27001, Cyber Essentials or NHS DSPT work needs technical evidence.
Previous findings or remediation need independent verification
Confirm that fixes work, rather than assume they do.
Leadership needs an independent view of technical exposure
A clear, evidenced position the Board can act on.
A changing digital estate needs recurring assurance
Consistent testing that keeps pace with change.
Evidence, not a scan report
Know what can be exploited, what matters most and what needs to happen next.
Automated vulnerability scanning identifies potential weaknesses at scale. Penetration testing goes further: it seeks to validate which weaknesses are exploitable within the authorised scope, and produces evidence that supports remediation and assurance decisions.
Testing gives an evidence-based view of security at the time of testing within the agreed scope. It is not a guarantee that systems are free of vulnerabilities.
What we test
Testing matched to your environment
External network testing
How internet-facing infrastructure stands up to an attacker’s approach.
Internal network testing
What an attacker could reach and exploit from inside the network.
Web application testing
Customer-facing and internal web applications, within the agreed scope and accounts.
Mobile application testing
Mobile applications and the services they rely on, where in scope.
Wireless testing
Wireless environments and their separation from sensitive networks.
Assurance-context reporting
Where agreed, findings can be contextualised against relevant security or assurance requirements, including UK GDPR security obligations, Cyber Essentials-related controls, NHS DSPT expectations, ISO/IEC 27001 or other agreed frameworks.
Penetration testing provides technical assurance evidence. It does not itself constitute a complete compliance assessment and does not guarantee certification.
IG-Smart controlled testing path
Authorised, controlled and reported
Authorise
Written permission and rules of engagement are agreed before testing.
Scope
Targets, exclusions, access, testing windows and escalation routes are defined.
Test
Controlled testing is performed within the agreed scope.
Escalate
Material or critical findings identified during testing are escalated through the agreed engagement route rather than being held solely for the final report. Escalation arrangements and any response expectations are agreed in the rules of engagement.
Report
Evidence-based findings are documented with CVSS scoring where applicable, technical context and prioritised remediation guidance.
Retest
Remediation can be independently retested where included or separately agreed.
Severity, interpreted
CVSS scoring, read in context
Findings are assigned CVSS scores where applicable to support consistent severity assessment and prioritisation. Severity is then interpreted alongside the factors that determine real priority:
Penetration testing can also sit within IG-Smart’s wider Assess → Build → Manage → Assure → Improve assurance model.
Qualified testing specialists
The right expertise, selected for your environment
Testing is delivered by appropriately qualified IG-Smart practitioners and specialist testing partners selected for the engagement, with recognised UK and international cybersecurity, information-security and penetration-testing qualifications.
IG-Smart coordinates the agreed scope, engagement governance, client communication and delivery assurance, working with appropriately qualified practitioners and specialist partners selected for the requirement.
Where required by procurement, assurance or engagement criteria, CREST-accredited penetration-testing delivery can be provided through a trusted specialist partner.
Practitioner selection takes account of
Environment & technologies
The systems, applications and infrastructure in scope.
Testing discipline
The specialist technical capability required.
Complexity & risk
The sensitivity and complexity of the environment.
Sector & assurance context
Relevant regulatory, customer and assurance requirements.
Independence & reporting
Conflict considerations and the evidence stakeholders require.
What you receive
Reporting engineers and decision-makers can both use
Findings by severity
Highest CVSS score
7.5 (illustrative)
Priority themes
Remediation status
- Closed
- 3
- In progress
- 5
- Open
- 3
Retest position
Partially verified
Illustrative output
Executive Testing Summary
Leadership view
The overall testing position, the most significant exposure and the decisions leadership needs to take.
What it helps you see
- Overall testing position
- Findings by severity
- Priority themes
- Remediation and retest position
Likely format
IG-Smart branded PDF
| Ref | Finding | Severity | Status |
|---|---|---|---|
| F-01 | Weak session handling | High | Open |
| F-02 | Missing access-control check | High | In progress |
| F-03 | Outdated service version | Medium | Closed |
| F-04 | Guest network not isolated | Medium | Open |
+ Evidence+ Technical context+ Business context+ Recommended remediation+ Owner+ Retest position recorded for every finding
Illustrative output
Technical Findings Register
Engineering detail
Each finding with evidence, CVSS score where applicable, business context and recommended remediation.
What it helps you see
- Finding and affected asset
- Severity and CVSS score
- Evidence and business / operational context
- Recommended remediation, owner and status
- Retest position
Likely format
IG-Smart branded PDF · Spreadsheet / register
| Priority | Action | Owner | Status |
|---|---|---|---|
| 1 | Strengthen session handling | Application owner | Open |
| 2 | Add access-control check | Platform team | In progress |
| 3 | Isolate guest wireless | Infrastructure | Open |
| 4 | Upgrade internal service | Infrastructure | Closed |
Illustrative output
Prioritised Remediation Plan
What to fix first
Fixes ordered by risk and practicality, with owners and target dates for your teams.
What it helps you see
- Priority order
- Agreed action
- Accountable owner
- Target date and status
Likely format
Spreadsheet / register
| Finding | Retest result | Position |
|---|---|---|
| F-01 | Not reproducible | Closed |
| F-02 | Partially fixed | Partially verified |
| F-03 | Not reproducible | Closed |
| F-04 | Not yet remediated | Pending |
Illustrative output
Retest / Closure Confirmation
Verified closure
The status of remediated findings after verification, where retesting is included or agreed.
What it helps you see
- Original severity
- Retest result
- Closure position
Likely format
IG-Smart branded PDF
Illustrative output — not a client document. Scores, findings and formats shown are illustrative; exact outputs depend on the agreed scope.
Working together
Clear about who does what
IG-Smart / testing team
- Agreed test planning
- Controlled testing
- Evidence gathering
- CVSS severity scoring where applicable
- Technical interpretation
- Escalation through agreed routes
- Reporting
- Retesting where scoped
Your organisation
- Written authorisation
- Asset and scope confirmation
- Access and information
- Production-impact constraints
- Operational ownership
- Remediation decisions
- Risk acceptance
- Third-party permissions
Included in the agreed test service
- Written authorisation and rules of engagement
- Scoping and test planning
- Controlled testing within the agreed scope
- Escalation of material or critical findings through the agreed engagement route
- Technical and executive reporting
- Prioritised remediation guidance
- CVSS scoring where applicable
Available where separately agreed
- Retesting
- Recurring testing programmes
- Additional management briefings
- Extended assurance reporting
Not provided or implied
- Unauthorised testing
- Testing third-party systems without appropriate permission
- Guaranteed absence of vulnerabilities
- Incident containment or forensic investigation unless separately contracted
- Remediation implementation unless separately scoped, with appropriate independence considerations
Relevant evidence
Direct penetration-testing evidence
View evidence — Jigsaw CreateJigsaw Create
Penetration testing across networks, web, mobile and wireless
Relevant assurance / ISO/IEC 27001 context
- View evidence — Addvanced Solutions Community Network CIC
Addvanced Solutions Community Network CIC
Network, application and wireless testing
Technical testing within broader cyber-resilience assurance
View evidence — The Co-operative GroupThe Co-operative Group
Routine penetration testing
Preferred supplier relationship · 2+ years
Client perspective
Your IG-Smart team
Specialist expertise coordinated around your requirement

Governance & executive assurance
Michael Abtar
Subject-matter oversight of scope, governance and executive reporting.
View profile
Senior Cyber Security Consultant
Dr Bright Mawudor
Technical cyber-security expertise and assurance perspective.
View profile
Client & programme contact
Julia Andrade
Coordinates scope, practitioners, scheduling and communication.
View profile
Questions buyers ask
Before you engage
Who carries out the testing?
Appropriately qualified IG-Smart practitioners and specialist testing partners selected for the engagement, with recognised UK and international cybersecurity, information-security and penetration-testing qualifications. IG-Smart coordinates the agreed scope, engagement governance, client communication and delivery assurance.
Can we see tester qualifications?
Where your procurement or supplier-assurance process requires it, relevant assurance information can be shared where commercially and contractually appropriate. Start through the Trust Centre or a conversation with a senior practitioner.
Can you provide CREST-accredited penetration testing?
Yes. Where the engagement or procurement requirement calls for it, CREST-accredited testing can be provided through a trusted specialist partner. The delivery model and assurance requirements are agreed as part of the scope.
How is penetration testing different from vulnerability scanning?
Automated scanning identifies potential weaknesses at scale. Penetration testing seeks to validate which weaknesses are exploitable within the authorised scope, and produces evidence that supports remediation and assurance decisions. The two are complementary.
Can testing be performed safely in production?
Testing runs within agreed windows, targets and exclusions set in the rules of engagement, with contacts available throughout. Any testing that carries operational risk is discussed and agreed before it starts.
How are findings scored and prioritised?
Findings are assigned CVSS scores where applicable to support consistent severity assessment. We also interpret findings in the context of the affected systems, exploitability, exposure and the organisation’s risk environment so remediation priorities are not based on a score alone.
What happens if you find something critical?
Material or critical findings are escalated to your nominated contacts through the engagement route agreed in the rules of engagement, rather than being held solely for the final report. Escalation arrangements and any response expectations are agreed in the rules of engagement.
Is retesting included?
Retesting is included where it is agreed in the scope, or can be separately agreed. It verifies whether remediated findings have been fixed and updates their status.
Investment
Scoped to requirement
Every engagement is scoped to the systems, depth and reporting required. Scope, deliverables, assumptions and fees are agreed in writing before testing begins.
The fee depends on
- Number and type of targets
- Testing disciplines
- Complexity
- Access and authentication
- Testing depth
- Reporting requirements
- Testing windows
- Retesting
- Recurring cadence
- Specific assurance or accreditation requirements
Need independent evidence of how your systems stand up to attack?
Procurement or supplier-assurance review?
Visit our Trust CentreNot sure this is the right service? Find the Right Service
