01 — Services · Catalogus plantarum
Everything here has been grown before it was sold.
What follows is a catalogue. Each entry is something we test, what it involves, roughly how long it takes, and what we need from you before the first day.
If your estate is not on the list, write anyway. Half of this work is deciding what the right test actually is.
GROUP I
Applications
Tested as each kind of user in turn, because almost every serious finding is something one role can do to another.
PLATE 01
Web application testing
Rosa applicata
Authenticated testing of the application as every kind of user, aimed at the logic a scanner cannot reach: broken access control, injection, session handling, and everything a role is not supposed to be able to do.
5–10 days · remote · one account per role, ideally two
PLATE 02
API testing
Rosa interfaciei
REST, GraphQL and gRPC surfaces tested against their documentation and against what they actually accept. Authorisation between accounts, mass assignment, object-level access, and rate limiting that only looks like rate limiting.
3–8 days · remote · a schema or collection, two accounts per role
PLATE 03
Mobile application testing
Rosa portabilis
iOS and Android, examined as a running app and as a file on disk. Binary and static review, traffic interception, local storage, pinning and anti-tamper, and the backend the app trusts more than it should.
5–12 days · remote · an installable build and test accounts
PLATE 04
Desktop & thick client
Rosa sedentaria
Installed Windows and cross-platform clients. Local privilege, file and registry permissions, embedded secrets, update mechanisms, and the protocol running back to the server once nobody is watching it.
4–8 days · remote or on site · installer, licence, a representative host
PLATE 05
Secure code review
Rosa scripta
Reading the source rather than inferring it from the outside. Targeted at authentication, authorisation, and every path that handles input from someone you do not employ. Usually paired with Plate 01 or 02.
3–10 days · remote · read-only repository access
GROUP II
Infrastructure
The estate itself: what is exposed, what an intruder reaches once inside, and whether the boundaries on the diagram exist on the wire.
PLATE 06
External infrastructure
Rosa ad muros
Everything reachable from the internet: exposed services, patch levels, forgotten hosts nobody has owned since a migration, and credentials already sitting in public. What a stranger learns before breakfast.
2–6 days · remote · IP ranges and domains, confirmed in writing
PLATE 07
Internal infrastructure
Rosa interior
From the position of someone already inside — a contractor’s laptop, a reused VPN certificate, one phished account. Domain privilege, lateral movement, and how far an entirely unremarkable user can travel.
4–10 days · on site or via jump host · network access, one standard user
PLATE 08
Build & device review
Rosa fabricata
A laptop, VDI image or kiosk build, examined as an attacker holding it would. Local escalation, disk encryption, application allow-listing, peripheral access, and what the lock screen genuinely keeps out.
2–4 days · on site or shipped device · one representative build
PLATE 09
Firewall & segmentation review
Rosa saepes
Rule base review paired with traffic testing across each boundary, including the paths nobody remembers approving. Required annually by PCI DSS, and quietly useful to everyone else.
2–5 days · remote · configuration exports and a host in each segment
GROUP III
Cloud & identity
Where the perimeter went. Reviewed as configuration and then tested as a live environment, because the two rarely agree.
PLATE 10
Azure & Entra ID
Rosa caerulea
Tenant, subscription and identity configuration. Conditional access and its exemptions, privileged role assignment, consent grants, managed identities, and the escalation routes that run between all four.
3–7 days · remote · a reader role and one standard user account
PLATE 11
Microsoft 365
Rosa officii
Exchange, SharePoint and Teams, with the sharing defaults nobody has revisited since rollout. External sharing, mail flow rules, legacy authentication, and precisely what one compromised mailbox hands over.
2–5 days · remote · read-only administrative access
PLATE 12
AWS & Google Cloud
Rosa nubila
IAM policy and role assumption chains, storage exposure, network boundaries, secrets handling, and the metadata service that turns a small application flaw into an account-wide one.
3–8 days · remote · a read-only audit role
PLATE 13
Build pipeline review
Rosa germinans
CI/CD treated as an attack surface. Who can change what runs, where the secrets live, what an untrusted pull request is permitted to execute, and what the pipeline can deploy to without a human present.
2–5 days · remote · pipeline definitions and read access
GROUP IV
Adversarial
Objectives rather than checklists. These engagements test whether anybody notices, which is a different question from whether anything is vulnerable.
PLATE 14
Red team
Rosa adversaria
Agreed objectives, no announced scope beyond the rules of engagement, and a written account of what was detected and when. Run alongside your defenders, or without their knowledge, as you prefer.
15–30 days · blended · an executive sponsor and written authorisation
PLATE 15
Social engineering
Rosa suasoria
Pretexted email, telephone and message campaigns against agreed targets, measured on what people did rather than what they clicked. Reported as patterns and numbers. We do not name individuals to their employer.
3–8 days · remote · a target list and an agreed pretext boundary
PLATE 16
Physical intrusion
Rosa ianuae
Doors, badges, receptions, and the helpful colleague holding one open. Reconnaissance, entry, and an honest account of what could be reached from a desk once inside the building.
3–6 days · on site · site owner authorisation, carried in writing
GROUP V
Specialist estates
The environments most consultancies decline, subcontract without telling you, or test with the wrong instincts entirely.
PLATE 17
Wireless
Rosa aetheris
Corporate and guest networks, the authentication protecting each, the segregation supposedly between them, and rogue access points. Including what can be captured from the car park without entering the building.
2–4 days · on site · site access and a floor plan
PLATE 18
Operational technology
Rosa machinalis
ICS and SCADA environments tested with the caution they demand: passive observation first, active testing only where agreed, and nothing at all against a running process without a written safety case.
5–12 days · on site · an engineering contact and an agreed safety case
PLATE 19
Embedded & IoT
Rosa inclusa
Hardware in hand. Debug interfaces, firmware extraction, secure boot, keys held in storage that was never meant to be read, and the cloud service the device trusts without ever verifying.
5–12 days · lab · two or three sample units we may destroy
PLATE 20
Z-Series mainframe
Rosa maiorum
z/OS security testing: RACF configuration, dataset and resource protection, APF authorisation, surrogate access, and the routes from an ordinary TSO login to something it was never intended to touch.
5–15 days · remote or on site · a TSO account and a systems programmer to talk to
GROUP VI
Before and afterwards
A test is a moment. Most of the value is in what happens either side of it.
PLATE 21
Threat modelling & design review
Rosa praevisa
Before it is built. A structured session over the architecture with the people who designed it, producing the list of things that must be true for the design to hold, and what happens to each if it is not.
1–3 days · remote or on site · architecture documentation and its authors
PLATE 22
Retest
Rosa iterata
Every remediated finding retested and the report reissued with each one marked closed, partially addressed, or still open. Included with every engagement in this catalogue. Not a separate line on an invoice.
included · remote · notice that the fixes are live
PLATE 23
Advisory retainer
Rosa perennis
A set number of days each quarter, drawn down as you need them: a question, a design review, a second opinion on a supplier’s report, or a short test at short notice without going back through procurement.
by arrangement · remote · an annual agreement
02 — Included throughout · Comitantia
The same six things arrive with every engagement.
Not a premium tier, not an upgrade, and not itemised separately. They are simply what a penetration test is when it is done properly.
- IA named testerYou are told who is testing before it starts, and you can speak to them during it.
- IIContact while the work runsA short daily note during the testing window, and an immediate telephone call for anything critical. You never wait for the report to hear bad news.
- IIIA report written by the testerAn executive summary your board can read, technical detail your engineers can act on, and reproduction steps for every finding.
- IVEvidence behind every ratingEach severity is tied to something demonstrated. We also record what we tried and could not achieve, because that is a result too.
- VA debriefAn hour with your engineers to walk the findings, argue about the ratings, and agree what order to fix them in.
- VIA retestYour fixes verified and the report reissued. Included, not invoiced.
03 — Schemes & standards · Regula mensurae
If a framework is driving this, say so early.
It changes what evidence the report has to carry, and it is far easier to build that in from the scope than to retrofit it afterwards.
PCI DSS
Segmentation testing and application testing scoped to the requirements, with findings mapped to the control they answer.
ISO 27001
Testing positioned as evidence for the technical controls, in a form an auditor will accept without a follow-up question.
Supplier assurance
Customer security questionnaires, due diligence packs, and the annual test a contract has started demanding.
CHECK
Testing is led by a dual-qualified CHECK Team Leader in both Application and Infrastructure. Where an engagement must be delivered under the NCSC CHECK scheme itself, we will tell you plainly and introduce you to a firm that holds it.
04 — Not on offer · Quae non serimus
Some things are not in the catalogue on purpose.
- An automated scan sold as a penetration test. If a tool could have found it alone, that is a scan, and it should be priced like one.
- A severity rating we cannot demonstrate. If we could not prove the impact, the report says so.
- Work we are not qualified for. We will tell you, and point you at someone who is, which costs us a fee and saves you a report worth nothing.
- Testing without written authorisation. The Computer Misuse Act requires it and so do basic manners.
- Your findings as our marketing. Nothing from your engagement becomes a case study, a slide, or a conference talk without your written permission.
Bring the plate number, or bring nothing at all.
Most engagements begin with half an hour on the telephone with the person who would do the testing. No charge, no slide deck, and no discovery call about the discovery call.
If you already know what you want, quote the plate number. If you do not, describe what is worrying you and we will work out the scope together — that is part of the job, not a prerequisite for asking.
Start a scope