Skip to main content

Cyber Resilience & Supplier Assurance · Security testing

Penetration Testing

Authorised, controlled testing of the systems your organisation depends on — with evidence-based findings your technical teams can remediate and your leadership can act on.

  1. Authorise
  2. Scope
  3. Test
  4. Escalate
  5. Report
  6. Retest
View penetration-testing evidence

When this service fits

When independent testing evidence is needed

  • A new system or major change is going live

    Independent testing before launch or after significant change.

  • Customers, procurement or tenders require independent security evidence

    Buyers and frameworks ask for proof that systems have been tested.

  • Security or assurance programmes need technical validation

    ISO/IEC 27001, Cyber Essentials or NHS DSPT work needs technical evidence.

  • Previous findings or remediation need independent verification

    Confirm that fixes work, rather than assume they do.

  • Leadership needs an independent view of technical exposure

    A clear, evidenced position the Board can act on.

  • A changing digital estate needs recurring assurance

    Consistent testing that keeps pace with change.

Evidence, not a scan report

Know what can be exploited, what matters most and what needs to happen next.

Automated vulnerability scanning identifies potential weaknesses at scale. Penetration testing goes further: it seeks to validate which weaknesses are exploitable within the authorised scope, and produces evidence that supports remediation and assurance decisions.

Testing gives an evidence-based view of security at the time of testing within the agreed scope. It is not a guarantee that systems are free of vulnerabilities.

What we test

Testing matched to your environment

  • External network testing

    How internet-facing infrastructure stands up to an attacker’s approach.

  • Internal network testing

    What an attacker could reach and exploit from inside the network.

  • Web application testing

    Customer-facing and internal web applications, within the agreed scope and accounts.

  • Mobile application testing

    Mobile applications and the services they rely on, where in scope.

  • Wireless testing

    Wireless environments and their separation from sensitive networks.

Assurance-context reporting

Where agreed, findings can be contextualised against relevant security or assurance requirements, including UK GDPR security obligations, Cyber Essentials-related controls, NHS DSPT expectations, ISO/IEC 27001 or other agreed frameworks.

Penetration testing provides technical assurance evidence. It does not itself constitute a complete compliance assessment and does not guarantee certification.

IG-Smart controlled testing path

Authorised, controlled and reported

  1. Authorise

    Written permission and rules of engagement are agreed before testing.

  2. Scope

    Targets, exclusions, access, testing windows and escalation routes are defined.

  3. Test

    Controlled testing is performed within the agreed scope.

  4. Escalate

    Material or critical findings identified during testing are escalated through the agreed engagement route rather than being held solely for the final report. Escalation arrangements and any response expectations are agreed in the rules of engagement.

  5. Report

    Evidence-based findings are documented with CVSS scoring where applicable, technical context and prioritised remediation guidance.

  6. Retest

    Remediation can be independently retested where included or separately agreed.

Severity, interpreted

CVSS scoring, read in context

Findings are assigned CVSS scores where applicable to support consistent severity assessment and prioritisation. Severity is then interpreted alongside the factors that determine real priority:

  • Exploitability
  • Affected asset
  • Business context
  • Exposure
  • Operational impact
  • Remediation priority

Penetration testing can also sit within IG-Smart’s wider Assess → Build → Manage → Assure → Improve assurance model.

Qualified testing specialists

The right expertise, selected for your environment

Testing is delivered by appropriately qualified IG-Smart practitioners and specialist testing partners selected for the engagement, with recognised UK and international cybersecurity, information-security and penetration-testing qualifications.

IG-Smart coordinates the agreed scope, engagement governance, client communication and delivery assurance, working with appropriately qualified practitioners and specialist partners selected for the requirement.

Where required by procurement, assurance or engagement criteria, CREST-accredited penetration-testing delivery can be provided through a trusted specialist partner.

Practitioner selection takes account of

  1. Environment & technologies

    The systems, applications and infrastructure in scope.

  2. Testing discipline

    The specialist technical capability required.

  3. Complexity & risk

    The sensitivity and complexity of the environment.

  4. Sector & assurance context

    Relevant regulatory, customer and assurance requirements.

  5. Independence & reporting

    Conflict considerations and the evidence stakeholders require.

What you receive

Reporting engineers and decision-makers can both use

Executive Testing SummaryIllustrative output — not a client document
Executive testing positionMaterial exposure identified

Findings by severity

  • Critical0
  • High2
  • Medium5
  • Low4

Highest CVSS score

7.5 (illustrative)

Priority themes

  • Authentication
  • Access control
  • Input validation

Remediation status

Closed
3
In progress
5
Open
3

Retest position

Partially verified

Illustrative output

Executive Testing Summary

Leadership view

The overall testing position, the most significant exposure and the decisions leadership needs to take.

What it helps you see

  • Overall testing position
  • Findings by severity
  • Priority themes
  • Remediation and retest position

Likely format

IG-Smart branded PDF

Technical Findings RegisterIllustrative output — not a client document
Illustrative technical findings register
RefFindingAffected assetSeverityCVSSStatus
F-01Weak session handlingCustomer web appHigh7.5Open
F-02Missing access-control checkAdmin API routeHigh7.1In progress
F-03Outdated service versionInternal serverMedium5.3Closed
F-04Guest network not isolatedWirelessMedium4.8Open

+ Evidence+ Technical context+ Business context+ Recommended remediation+ Owner+ Retest position recorded for every finding

Illustrative output

Technical Findings Register

Engineering detail

Each finding with evidence, CVSS score where applicable, business context and recommended remediation.

What it helps you see

  • Finding and affected asset
  • Severity and CVSS score
  • Evidence and business / operational context
  • Recommended remediation, owner and status
  • Retest position

Likely format

IG-Smart branded PDF · Spreadsheet / register

Prioritised Remediation PlanIllustrative output — not a client document
Illustrative prioritised remediation plan
PriorityActionOwnerTargetStatus
1Strengthen session handlingApplication ownerAgreed dateOpen
2Add access-control checkPlatform teamAgreed dateIn progress
3Isolate guest wirelessInfrastructureAgreed dateOpen
4Upgrade internal serviceInfrastructureAgreed dateClosed

Illustrative output

Prioritised Remediation Plan

What to fix first

Fixes ordered by risk and practicality, with owners and target dates for your teams.

What it helps you see

  • Priority order
  • Agreed action
  • Accountable owner
  • Target date and status

Likely format

Spreadsheet / register

Retest / Closure ConfirmationIllustrative output — not a client document
Illustrative retest and closure confirmation
FindingOriginal severityRetest resultPosition
F-01HighNot reproducibleClosed
F-02HighPartially fixedPartially verified
F-03MediumNot reproducibleClosed
F-04MediumNot yet remediatedPending

Illustrative output

Retest / Closure Confirmation

Verified closure

The status of remediated findings after verification, where retesting is included or agreed.

What it helps you see

  • Original severity
  • Retest result
  • Closure position

Likely format

IG-Smart branded PDF

Illustrative output — not a client document. Scores, findings and formats shown are illustrative; exact outputs depend on the agreed scope.

Working together

Clear about who does what

IG-Smart / testing team

  • Agreed test planning
  • Controlled testing
  • Evidence gathering
  • CVSS severity scoring where applicable
  • Technical interpretation
  • Escalation through agreed routes
  • Reporting
  • Retesting where scoped

Your organisation

  • Written authorisation
  • Asset and scope confirmation
  • Access and information
  • Production-impact constraints
  • Operational ownership
  • Remediation decisions
  • Risk acceptance
  • Third-party permissions

Included in the agreed test service

  • Written authorisation and rules of engagement
  • Scoping and test planning
  • Controlled testing within the agreed scope
  • Escalation of material or critical findings through the agreed engagement route
  • Technical and executive reporting
  • Prioritised remediation guidance
  • CVSS scoring where applicable

Available where separately agreed

  • Retesting
  • Recurring testing programmes
  • Additional management briefings
  • Extended assurance reporting

Not provided or implied

  • Unauthorised testing
  • Testing third-party systems without appropriate permission
  • Guaranteed absence of vulnerabilities
  • Incident containment or forensic investigation unless separately contracted
  • Remediation implementation unless separately scoped, with appropriate independence considerations

Relevant evidence

Direct penetration-testing evidence

Client perspective

“IG-Smart Ltd has proven to be an indispensable ally in safeguarding our digital assets.”

Edward KendallProduct Manager, Jigsaw Technology LimitedPenetration testing and cyber assurance
View Jigsaw evidence — Jigsaw Technology Limited case study

Your IG-Smart team

Specialist expertise coordinated around your requirement

  • Governance & executive assurance

    Michael Abtar

    Subject-matter oversight of scope, governance and executive reporting.

    View profile
  • Senior Cyber Security Consultant

    Dr Bright Mawudor

    Technical cyber-security expertise and assurance perspective.

    View profile
  • Client & programme contact

    Julia Andrade

    Coordinates scope, practitioners, scheduling and communication.

    View profile

Questions buyers ask

Before you engage

Who carries out the testing?

Appropriately qualified IG-Smart practitioners and specialist testing partners selected for the engagement, with recognised UK and international cybersecurity, information-security and penetration-testing qualifications. IG-Smart coordinates the agreed scope, engagement governance, client communication and delivery assurance.

Can we see tester qualifications?

Where your procurement or supplier-assurance process requires it, relevant assurance information can be shared where commercially and contractually appropriate. Start through the Trust Centre or a conversation with a senior practitioner.

Can you provide CREST-accredited penetration testing?

Yes. Where the engagement or procurement requirement calls for it, CREST-accredited testing can be provided through a trusted specialist partner. The delivery model and assurance requirements are agreed as part of the scope.

How is penetration testing different from vulnerability scanning?

Automated scanning identifies potential weaknesses at scale. Penetration testing seeks to validate which weaknesses are exploitable within the authorised scope, and produces evidence that supports remediation and assurance decisions. The two are complementary.

Can testing be performed safely in production?

Testing runs within agreed windows, targets and exclusions set in the rules of engagement, with contacts available throughout. Any testing that carries operational risk is discussed and agreed before it starts.

How are findings scored and prioritised?

Findings are assigned CVSS scores where applicable to support consistent severity assessment. We also interpret findings in the context of the affected systems, exploitability, exposure and the organisation’s risk environment so remediation priorities are not based on a score alone.

What happens if you find something critical?

Material or critical findings are escalated to your nominated contacts through the engagement route agreed in the rules of engagement, rather than being held solely for the final report. Escalation arrangements and any response expectations are agreed in the rules of engagement.

Is retesting included?

Retesting is included where it is agreed in the scope, or can be separately agreed. It verifies whether remediated findings have been fixed and updates their status.

Investment

Scoped to requirement

Every engagement is scoped to the systems, depth and reporting required. Scope, deliverables, assumptions and fees are agreed in writing before testing begins.

The fee depends on

  • Number and type of targets
  • Testing disciplines
  • Complexity
  • Access and authentication
  • Testing depth
  • Reporting requirements
  • Testing windows
  • Retesting
  • Recurring cadence
  • Specific assurance or accreditation requirements

Need independent evidence of how your systems stand up to attack?

Procurement or supplier-assurance review?

Visit our Trust Centre