Uncover Your Cyber Risks Before Attackers Do

Penetration Testing Services in the UK

CREST and CHECK-accredited UK cyber security consultancy offering expert-led penetration testing for networks, applications, and cloud systems.

Penetration Testing by Arcanum Cyber Security - Leaders in CHECK adn CREST Approved Pen Tests

Get a quote for Penetration Testing today

    What is Penetration Testing?

    Penetration testing (“pen testing”) is a controlled and authorised cyber security audit that simulates cyber attacks on your network, applications, or infrastructure. Our ethical hackers (also known as penetration testers) attempt to uncover weaknesses just as a real attacker would – with your consent. They provide expert guidance for fixing what we find and help you maintain a secure environment.

    Penetration Testing Company in the UK. CHECK and CREST approved

    Industry-Leading Accreditations

    NCSC CHECK Penetration Testing
    NCSC Consultancy Risk Management. Penetration Testing Company UK
    CREST accredited penetration testing services by certified cyber security consultants
    Cyber Essentials Certification Body
    Cyber Essentials Plus Certification Body
    IASME Cyber Assurance Certification Body
    DCC - Defence Cyber Certification Logo
    CAA Assure. Cyber Security Consultancy
    ISO 9001 Certified Logo
    ISA Cybersecurity Expert 62443
    Employer Recognition Scheme Gold Award

    A pen test is a security audit where we come in and attempt to find as many security issues in a web application, network, or system as we can. We then write a report… and provide advice and remediation guidance on the steps we can take to fix those issues.”

     

    – Tamar Everson, Head of Penetration Testing, Arcanum Cyber

    Why Your Organisation Needs Penetration Testing

    Every business is a potential target for cyber attacks.

    Pen testing helps you:

    1 2

    Identify Vulnerabilities Before Hackers Do

    Proactively uncover exploitable flaws in your systems before malicious actors find and exploit them.

    Cyber Essentials Plus - #2

    Maintain Customer and Partner Trust

    Demonstrate a robust security posture to clients, partners, and stakeholders – building long-term confidence in your brand.

    Cyber Essentials Plus - #3

    Meet Industry and Regulatory Compliance

    Satisfy the requirements of standards like ISO 27001, PCI DSS, and NCSC CHECK with verified security testing.

    4

    Validate Defences Through Real-World Simulation

    Test how your systems hold up against simulated cyber attacks based on real-world threat tactics.

    5

    Empower Your IT and Security Teams

    Give internal teams actionable insights and prioritised remediation steps to improve long-term security.

    6

    Demonstrate Due Diligence to Stakeholders

    Prove that your organisation takes cyber security seriously – supporting insurance, board-level assurance, and client audits.

    Trusted by Government, Defence & Critical Infrastructure

    Penetration testing for Government and Public ector

    Government & Public Sector organisations

    Ensuring compliance with NCSC guidelines.

    Penetration Testing for Defence and Aerospace

    Defence & Aerospace

    Delivering cyber security assurance to mission-critical environments.

    Pen Tests for Manufacturing & Industrial Control Systems (ICS/SCADA)

    Manufacturing & Industrial Control Systems (ICS/SCADA)

    Safeguarding operational technology.

    Pen Testing for Finance and Legal Industries

    Finance & Legal Industries

    Protecting against cyber threats targeting high-value data.

    Proven Security Expertise Across Sectors

    What leading organisations say about Arcanum Cyber

    Mark Eagles, Information Security Analyst, ZSL:

    “ZSL has benefitted a huge amount from this assessment and your patient support and advice over the past year, which has left us in a much better state for Cyber Security than when we started. Please accept my sincere thanks to the penetration testing team and everyone that helped from Arcanum throughout the assessments over the past year, and for your support with Cyber Essentials Plus. We look forward to working with you again in the future.”

    Prof. Ingo Waldmann, CTO & Co-founder, Spaceflux:

    Arcanum’s penetration testing service has been instrumental in validating that our systems are secure by design and verify we meet our cyber security compliances. Their expert team didn’t just test our defences — they helped us proactively identify and resolve vulnerabilities. They have always been very flexible and accommodating to our needs and specific requirements, giving us the independent assurance needed to demonstrate the robustness of our security architecture.”

    Led by Experts Who Know How Hackers Think

    Tamar Everson - Our Lead Penetration Tester

    Our Penetration Testing Team is led by Tamar Everson. He leads a highly skilled team of ethical hackers at Arcanum who emulate the tactics of real-world attackers to uncover vulnerabilities that scanners often miss.

    Tamar is a NCSC CHECK Team Leader and was one of the first in the UK to be awarded Chartered Cyber Security Professional Status for Security Testing. He is CREST Registered and holds a BEng (Hons) in Digital Security, Forensics & Ethical Hacking from Glasgow Caledonian University, where he also founded the Ethical Hacking Society.

    Over the past decade, Tamar has assessed the resilience of web platforms, mobile apps, SCADA systems, cloud infrastructure, and internal networks.

    As a passionate advocate for cyber education, Tamar regularly mentors university students, encourages military veterans to enter the security field, and helps shape the next generation of ethical hackers.

    Real-World Testing

    Real results from past clients

    Travel Industry

    Payment Processor Bypass

    We helped a travel agency identify a critical flaw in their checkout process. By manipulating a third-party payment response, our testers simulated unauthorised free purchases of holiday packages. The client resolved the issue within days – potentially saving tens of thousands of pounds.

    Travel Industry

    Full System Compromise via Chained Attack

    One assessment revealed an overlooked admin panel accessible without login. Exploiting a chained attack:

    • Forced-browsed hidden pages
    • Executed SQL injection to access the database
    • Dumped and cracked MD5 password hashes
    • Gained full admin control of the system

    Data Analytics

    Full System Compromise

    We helped a data analytics firm identify a critical flaw in their virtualisation infrastructure. We were able to leverage this to escalate privileges within the system and gain full control over the client’s infrastructure.

    Contact Centre

    Full System Compromise

    We identified an attack chain which allowed a printer to be exploited externally. This could be leveraged to conduct network scans and move laterally across the client’s network.

    Our Penetration Testing Process

    ^
    Step 1

    Discovery & Scoping

    We start with a call to understand your systems, risks, and goals – often helping clients refine what they really need.

    ^
    Step 2

    Proposal & Planning

    A tailored proposal is sent, outlining what we’ll test and how.

    ^
    Step 3

    Pre-Test Preparation

    One week before testing, we confirm access credentials, allowlisting, and scheduling.

    ^
    Step 4

    Testing Begins

    Our testers notify you when they commence testing, and provide regular updates throughout the engagement.

    ^
    Step 5

    Daily Updates

    We share key findings each day—with immediate alerts for any high or critical issues.

    ^
    Step 6

    Analysis & Exploration

    We simulate attacks, escalate privileges, and explore lateral movement – just like a real threat actor.

    ^
    Step 7

    Risk Contextualisation

    We assess both technical and business risk, drawing on Arcanum’s deep consultancy background.

    ^
    Step 8

    Detailed Reporting

    Our comprehensive reports show how to reproduce each issue and how to fix it – tailored to your tech stack.

    ^
    Step 9

    Internal QA Review

    Every report goes through a dual QA process for technical accuracy and clarity.

    ^
    Step 10

    Follow-Up & Remediation Support

    We’re available to walk you through findings and re-test key fixes if needed.

    Why Choose Arcanum for Penetration Testing?

    Choosing the right penetration testing provider is about more than just ticking a compliance box. At Arcanum, we combine government-grade credentials with deep technical expertise and a personal, hands-on approach.

    ^

    CREST & CHECK Accredited

    Certified to perform testing under the UK’s highest recognised cyber security standards, including government-approved schemes.

    ^

    Trusted by Government & CNI

    Relied on by public sector bodies, defence contractors, OT operators, Critical National Infrastructure and highly regulated financial institutions.

    ^

    A Team of Dedicated Experts

    As the cyber security consultancy with the most Chartered Cyber Security Professionals in the UK, Arcanum consultants have the depth and breadth of expertise to be able to improve your cyber security resilience.

    ^

    Plain-English Reporting

    We provide clear, jargon-free reports that help both technical teams and executives understand and act on risks.
    ^

    Manual Testing Focus

    Our experts perform hands-on testing to uncover complex vulnerabilities often missed by automated scanners alone.

    ^

    Remediation Support

    Beyond reporting, we assist with remediation planning, retesting, and verification to ensure vulnerabilities are resolved properly.

    ^

    Flexible Delivery

    We adapt to your timeline with minimal disruption – offering remote or on-site testing based on your needs.

    ^

    OT Penetration Testing

    We have the specialist knowledge and expertise required to test in Operational Technology (OT) environments.

    Ready to Secure Your Systems?

    Get expert-led penetration testing services from a trusted UK cyber consultancy. Whether you’re a fintech firm, manufacturer, or public sector organisation, we tailor our services to your risk profile and business goals.

    Office of business people | Penetration testing services for all types of organisations

    FAQs

    What is a penetration test?

    A penetration test (or pen test) is a controlled, ethical cyberattack carried out by skilled professionals to evaluate the security of your systems, applications, or network infrastructure. The goal is to uncover vulnerabilities that a real attacker could exploit and provide you with a report detailing the issues, their severity, and how to fix them – before a breach occurs.

    How often should we pen test?

    It’s recommended to conduct penetration tests annually, or whenever there are significant changes such as:

    • Deploying a new system
    • Migrating to the cloud
    • Following a merger or incident.

    Some industries, like finance and healthcare, may require more frequent testing to meet compliance standards.

    How does it differ from vulnerability scanning?

    Vulnerability scanning is an automated process that checks for known issues based on databases of common vulnerabilities. Penetration testing, on the other hand, involves human experts actively attempting to exploit those weaknesses and uncover more complex, context-specific flaws. Pen tests often reveal chains of vulnerabilities, logic flaws, or misconfigurations that automated tools simply can’t detect.

    How long does penetration testing take?

    Most standard engagements last 3–5 working days, but more complex environments, multiple applications, or extended scope can take longer. We’ll provide a timeline at the proposal stage and keep you updated throughout the process. You’ll also receive daily updates during testing, so there are no surprises.

    Do you provide daily updates during testing?

    You’ll receive daily summaries of findings and progress, plus immediate alerts for any critical vulnerabilities discovered. We believe communication is essential to good testing.

    Our testers let you know exactly what we’re doing, when we’re doing it, and if anything needs your attention. You’re never left wondering how things are going – we aim for complete transparency and responsiveness.

    What can I expect from the penetration test report?

    At Arcanum, our reports are written to be both technically rigorous and genuinely useful. Each vulnerability includes a clear description, severity rating, evidence (such as screenshots or payloads), and step-by-step remediation guidance tailored to your exact tech stack – whether you’re running IIS, Apache, or something custom.

    Unlike generic or scanner-generated reports, ours are manually written and reviewed by two internal experts for accuracy and clarity. We also provide contextual insights, explaining how each issue could impact your business in plain English – making them suitable for both IT teams and board-level stakeholders.

    “We don’t just drop a list of findings and walk away. We write every report to suit the client’s environment, so they know exactly what to fix and how. That’s something we’re proud of.” — Tamar Everson

    What compliance standards require penetration testing?

    Penetration testing is essential to demonstrate cyber security compliance with: 

    • PCI DSS (Payment Card Industry Data Security Standard) 
    • GDPR (General Data Protection Regulation) 
    • Cyber Essentials & Cyber Essentials Plus 
    • ISO 27001 (Information Security Management) 
    • NIST (National Institute of Standards and Technology) 
    • HIPAA (Health Insurance Portability and Accountability Act)

    If your business handles sensitive data, regular penetration testing ensures compliance and risk mitigation.

    How do I choose the best penetration testing company?

    When selecting a penetration testing company, look for:

    Arcanum Cyber Security is a CHECK & CREST-approved firm trusted by Government, Defence, and UK enterprises.

    Do you provide retesting or validation after we apply fixes?

    Yes. Once you’ve addressed the vulnerabilities identified in your report, we offer retesting to confirm they’ve been properly resolved. We’ll attempt to re-exploit the issue (in a controlled way) to ensure it’s no longer a threat. 

    This gives you confidence that your fixes are effective, and it provides documented evidence of remediation – useful for compliance, insurers, and internal reporting.

    Will it impact our operations?

    Our testing is designed to be low-impact and non-disruptive. We can schedule around your peak hours and only perform high-risk tests (e.g., denial of service) with explicit permission. For most clients, testing is invisible to end users. You’ll have full control over what gets tested and when.

    Can testing be done remotely?

    Yes. The majority of testing can be completed securely via VPN, remote desktop, or cloud access – no matter where you’re located. Only physical security tests or some ICS/OT engagements require an on-site presence. We’ll advise the best setup based on your infrastructure and risk appetite.

    Whilst most assessments can be conducted remotely, we do often find that the best results are achieved from an onsite assessment where we can more readily interact with your staff and see the physical systems under test. We will work with you to determine whether a remote or onsite assessment is best for your specific scenario.

    Which pen test do I need?

    That depends on your environment and business goals. You might need a web application test, an internal infrastructure assessment, a wireless security audit, or a full IT Health Check. We’ll help you define the right test type based on your systems, regulatory obligations, and concerns.

    What’s the difference between a pen test and a red team?

    A pen test is targeted and focused on specific systems or applications. A red team engagement is broader and simulates an advanced attacker trying to breach your organisation stealthily over time, often including physical intrusion or social engineering. Arcanum specialises in deep manual penetration testing but does not offer red teaming at this time.

    What is an IT Health Check?

    An IT Health Check (ITHC) is a government-sanctioned form of penetration test required for many public sector organisations and critical infrastructure projects. Delivered under the NCSC’s CHECK scheme, it must be conducted by accredited providers – like Arcanum. These assessments support compliance with UK government cyber assurance requirements.

    How do I get started?

    To book a penetration test with Arcanum,

    Fill out the contact form

    Or call us: 📞 029 2278 4452

    Our CHECK and CREST-certified penetration testers will help you secure your business, applications, and IT infrastructure against evolving cyber threats.

    Get a quote for Penetration Testing today

    Email contact@arcanum-cyber.com or use the form below

      Our core Penetration Testing Services

      Arcanum’s penetration testing services cover a full spectrum of attack surfaces across operating systems, applications, cloud platforms, and physical environments. Our methodology is grounded in real-world simulation, advanced toolsets, and ethical hacking best practices.

      Web Application Assessment

      A thorough analysis is conducted against Arcanum’s application assessment checklist to ensure completeness and consistency of application testing.

      Web Services Assessments

      Arcanum takes a mainly manual approach to web services testing, with our methodology based on OWASP’s testing frameworks, expanded with our extensive experience of web services testing

      External Assessment

      Network discovery and enumeration will be conducted on the selected IP range(s) to identify active hosts and devices.

      Internal Assessment

      Internal Infrastructure Assessment of all networked devices carried out at the customer site.

      Mobile Application Assessment

      Arcanum can assess Android and iOS mobile applications in two key areas – Client Side and Server Side.

      Cloud Security Assessment (Configuration Review)

      Arcanum will conduct a build and configuration review of the in-scope Cloud Estate in line with Centre for Internet Security (CIS) hardening benchmarks and vendor recommendations.

      Device Configuration Review

      Devices including routers, firewalls, switches, and VPNs should have their configurations reviewed for security vulnerabilities.

      Build and Configuration Reviews

      Arcanum will conduct a build and configuration review of the in-scope device(s) in line with Center for Internet Security (CIS) hardening benchmarks and vendor recommendations.

      Scenario Based Assessments

      This is a tailored approach which focuses on answering specific questions about the security of a system.

      Physical Security Assessment

      Physical security assessment of the customer’s premises. In addition, we can investigate whether any security vulnerabilities can be found from publicly accessible websites.

      Social Engineering Assessment

      Clients who are looking to determine their staff’s susceptibility to social engineering attacks, Arcanum is capable of performing a variety of these assessments, such as phishing (email based) and vishing (call based).

      Continuous Security Testing

      Suitable for systems which are undergoing ongoing development, continuous security testing involves a comprehensive penetration test initially, followed by regular testing throughout the year of the system’s changes.

      Bespoke Engagements

      Arcanum’s skilled consultants work alongside the client to formulate the scope of work and gain an in-depth understanding of the testing requirements to produce a bespoke service.

      Other Services

      We can also provide a number of other services.

      Penetration Testing – Core Service

      Web Application Assessment

      Arcanum will assess the required web applications. Scope is determined based on number of dynamic pages, unique input fields, and user roles. Arcanum will test the security of the in-scope web application(s), and how they impact both the applications themselves and the underlying infrastructure.

      A number of areas are considered in web application assessment, including:

      • Authentication and authorisation
      • Session management
      • Data validation
      • Encryption of sensitive data
      • Security of the presentation tier

      A thorough analysis is conducted against Arcanum’s application assessment checklist to ensure completeness and consistency of application testing.  Arcanum places emphasis on understanding the business threats and identifying flaws in the logic of the application that could be used to realise those threats, using manual testing techniques.

      Penetration Testing – Core Service

      Web Services Assessments

      Arcanum can test web services built on REST, SOAP, or GraphQL technologies.

      Arcanum takes a mainly manual approach to web services testing, with our methodology based on OWASP’s testing frameworks, expanded with our extensive experience of web services testing. At a high level, web services assessments cover the following broad areas:

      • Authentication Analysis
      • Session Handling Analysis
      • Authentication and Authorisation Controls Analysis
      • Data Handling, Storage, and Encryption Analysis
      • Information Disclosure Analysis
      • Input Validation and Sanitisation Analysis
      • Web Services Logic Analysis
      • Server Configuration Analysis
      • Bespoke Client Analysis

      Penetration Testing – Core Service

      External Assessment

      Network discovery and enumeration will be conducted on the selected IP range(s) to identify active hosts and devices. A detailed security assessment of the discovered devices will be conducted from the internet using a range of tools and techniques by our experienced consultants.

      This includes:

      • Up to 10 IPs per day.
      • Passive information gathering of publicly available data such as in DNS and WHOIS registries.
      • Active vulnerability scanning of identified services.
      • Active testing of associated Internet services such as DNS; and
      • Active testing of exposed firewalls, routers, and other filtering devices included in the target range.

      Identified vulnerabilities will then be manually verified to determine the actual impact and likelihood of exploitation, and an appropriate severity rating assigned based on the context.

        Penetration Testing – Core Service

        Internal Assessment

        Internal Infrastructure Assessment of all networked devices. This assessment needs to be carried out at the customer site.

        • Network discovery and enumeration will be conducted on the selected networks to identify active hosts and devices.
        • A detailed security assessment of the discovered devices will be conducted from the internal network using a range of tools and techniques by our experienced consultants.
        • This includes active vulnerability scanning of identified services. Identified vulnerabilities will then be manually verified to determine the actual impact and likelihood of exploitation, and an appropriate severity rating assigned based on the context.

        Penetration Testing – Core Service

        Mobile Application Assessment

        Arcanum can assess Android and iOS mobile applications.

        We focus primarily on two main areas during mobile application assessments:

        • Client Side – analysis of the client application with a focus on how it stores and processes sensitive data on the device, as well as the security configuration options of the app itself.
        • Server Side – analysis of the authentication, authorisation, and session management controls, as well as data validation and how sensitive data is handled.

          Penetration Testing – Core Service

          Cloud Security Assessment (Configuration Review)

          Cloud configuration review of the target cloud platform.

          Arcanum will conduct a build and configuration review of the in-scope Cloud Estate in line with Centre for Internet Security (CIS) hardening benchmarks and vendor recommendations. Commonly assessed cloud services include:

          • Azure Configuration.
          • AWS Configuration.
          • Google Cloud Configuration.
          • MS365 Configuration.
          • Intune MDM Configuration.

          Arcanum can review additional cloud platforms on request.

              Penetration Testing – Core Service

              Device Configuration Review

              Devices including routers, firewalls, switches, and VPNs should have their configurations reviewed for security vulnerabilities.

              Arcanum will conduct a build and configuration review of the in-scope device(s) in line with Center for Internet Security (CIS) hardening benchmarks and vendor recommendations.

              Penetration Testing – Core Service

              Build and Configuration Reviews

              Arcanum will conduct a build and configuration review of the in-scope device(s) in line with Center for Internet Security (CIS) hardening benchmarks and vendor recommendations. This review usually includes a combination of automated and manual review techniques.

              Penetration Testing – Core Service

              Scenario Based Assessments

              Where clients have particular security concerns regarding a system Arcanum can perform a scenario-based assessment. This is a tailored approach which focuses on answering specific questions about the security of a system. Some common scenarios are:

              • Can user A access user B’s data?
              • Can the security checks around X function be bypassed?
              • Is it possible to access data on network B from network A?
              • What systems and data could someone with a stolen company laptop access?

              Penetration Testing – Core Service

              Physical Security Assessment

              Physical security assessment of the customer’s premises.

              Due to the often used ‘Defence in Depth’ approach to security, the Physical Security Assessment will assess the effectiveness of the various layers of physical security features from the outside in, dependent upon customer requirements. Security features that can be assessed include, but are not limited to:

              • Perimeter fence.
              • External and internal gates, doors, and locks.
              • Unofficial/unrecognised entry points and entry methods.
              • Site security personnel.
              • CCTV systems.
              • Security Lighting.
              • Access Control measures. 
              • Security Standard Operating Procedures (SOPs).
              • Site security posture and general security awareness.
              • Key handling and security cabinets.
              • Access to sensitive areas.
              • Security feature configuration.

              In addition, we can investigate whether any security vulnerabilities can be found from publicly accessible websites.

                Penetration Testing – Core Service

                Social Engineering Assessment

                Clients who are looking to determine their staff’s susceptibility to social engineering attacks, Arcanum is capable of performing a variety of these assessments, such as phishing (email based) and vishing (call based). Social engineering is a common attack performed by sophisticated threat groups in an attempt to gain internal access to an organisation’s network, as such Arcanum can perform similar attacks in order to provide insight into how successful such attempts might be; this includes: 

                • Varying levels of sophistication ranging from “low-effort, wide net” style engagements which target thousands of users across many hosts and domains; to sophisticated targeted engagements against a handful of employees with tailored attacks.
                • Phishing can be specified against the entire organisation, select departments, or a random selection of staff depending on needs
                • As part of phishing, Arcanum can create phishing websites designed to securely collect any data entered, such as usernames and passwords – a common attack used by external threats attempting to gain a foothold in an organisations network.
                • Arcanum can perform vishing against users and attempt to have them disclose confidential or sensitive information or otherwise engage with a phishing domain previously set up
                • Techniques such as domain and number spoofing can be employed to give the appearance of more genuine or expected contacts, such as changing number during a vishing attempt to appear to come from the same county/city as the organisation’s office
                • Statistical analysis and review to determine which users/departments were more or less likely to interact with an attacker as well as the general trends regarding how many users clicked or interacted with any created phishing sites.

                Penetration Testing – Core Service

                Continuous Security Testing

                Suitable for systems which are undergoing ongoing development, continuous security testing involves a comprehensive penetration test initially, followed by regular testing throughout the year of the system’s changes to ensure that security vulnerabilities are identified as soon as possible in the development lifecycle.

                Our can consultants come in at the end of each sprint (or the appropriate point if other development methodologies to Agile are in use) and conduct a penetration test of the features which have been added or changed over the course of the sprint. This has a number of advantages including:

                • Time & Cost Savings
                • Developer education & awareness
                • Overall security improvements – issues get identified before they even hit production environments
                • Easier to digest reporting – we can log issues straight into your bug tracker rather than writing standalone reports which you then convert into issues

                We still recommend that a comprehensive annual test is conducted of the system as a whole, but would expect less issues to be identified in the annual test than without continuous testing.

                  Penetration Testing – Core Service

                  Bespoke Engagements

                  Clients often require testing which doesn’t fall neatly into a standard service line. This doesn’t mean that we can’t help to assess the security vulnerabilities within the system, merely that Arcanum’s skilled consultants will need to work alongside the client to formulate the scope of work and gain an in-depth understanding of the testing requirements.

                  Penetration Testing – Other Services

                  Other Services

                  We can also provide a number of other services, including:

                  • Thick Client Assessments
                  • Code Reviews
                  • Security Awareness Training
                  • Writing Secure Configuration Documentation
                  • OT/ICS Security Assessments
                  • Breakout Assessments
                  • WiFi Assessments

                  These assessments tend to follow a more bespoke approach based on client requirements.

                  Ready to Secure Your Systems?

                  Get expert-led penetration testing services from a trusted UK cyber consultancy. Whether you’re a fintech firm, manufacturer, or public sector organisation, we tailor our services to your risk profile and business goals.

                  Penetration Testing by Arcanum Cyber Security - Leaders in CHECK adn CREST Approved Pen Tests

                  Get a quote for Penetration Testing today