0333 335 5020letstalk@networklondon.co.ukRemote supportClient portal

Network London

Penetration testing for firms that need to prove their defences

A penetration test is a controlled attempt to break into your systems, with a report your board and your clients can read. Network London scopes the test, runs it at a time that suits you, explains every finding in plain English and fixes what it finds, because we look after your IT too.

  • Scoped to what your clients, insurers or auditors actually asked for
  • Findings explained, then fixed by the same team
  • Scheduled to suit you, with notice of start and finish if you want it
Two engineers reviewing findings on a large screen
Call 0333 335 5020Get in touch
Two office workers looking at something concerning on their laptop screen

Someone has asked when you last had a penetration test

Does any of this sound familiar?

  • A client questionnaire, an investor or your cyber insurer wants a recent penetration test report and you don't have one.
  • You had a test done once. The report sat in a folder because nobody owned the fixes.
  • A vulnerability scan was sold to you as a pen test. The person asking knows the difference.

A pen test with nobody to fix the findings is an expensive list. We do the test and the fixing.

An IT engineer working together with staff members to solve a problem

What our penetration testing covers

We test the things an attacker would try: your internet-facing systems, your internal network, your Microsoft 365 setup, your web applications and, as a separately priced extra, your people through a phishing campaign. A test goes further than a vulnerability scan. A scan tells you a door is unlocked; a test walks through it and shows what could be reached: weak passwords, sensitive files on open shares, data in databases, permissions that let one account get to everything, and the paths between them.

You get a report that explains each finding, what it means for your business and how it compares with your last test. If you ask for them, we also give notice when testing starts and ends and activity logs you can match against your own monitoring. Then we fix the findings in priority order and test again to show they are closed. Network London holds Cyber Essentials Plus.

Tell us who is asking for the test and what systems you run. We'll scope it with you on a call.

Tell us what you need

What you get from a penetration test run by the team who look after your IT

  • Scoped properly

    Tested against what was actually asked: the questionnaire, the insurer's wording or the auditor's list. Not more than you need, and nothing that matters left out.

  • A report people can read

    One section for the board, one for the engineers. Every finding rated, explained and tied to a fix, with a summary you can send to the client who asked.

  • Fixed, not filed

    The findings go straight into our work on your systems. You get a closed list and the evidence to show it, rather than a PDF and a to-do.

  • 20years looking after business IT
  • 100+businesses across the world trust us with their IT
  • 24/7support, with a real person on the phone

Who we work with

Three of the 100+ businesses we look after, and what we do for them.

Rossair

IT support, the phone system and a website that brings in enquiries, all looked after by one team.

Read the story

LAMDA

Everyday support for 180 people, with access reviews and backup testing built into how they work.

Read the story

A private equity firm

A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.

Read the story

How a penetration test works with us

  1. Scoping call

    Jessica, our Operations Director, replies the same day. We agree what is in scope, who has asked for the test, what they need to see and when.

  2. The test, at a time you choose

    Testing is scheduled around your business, and we can give notice when it starts and ends. Internal tests can run outside hours.

  3. Report, fixes and evidence

    You get the report, a walkthrough of the findings and a plan. We fix them in priority order, retest, and give you the summary to send on.

What's included in our penetration testing service

  • External infrastructure test

    Everything of yours that faces the internet: firewalls, remote access, email, web servers and cloud services, tested as an outside attacker would.

  • Internal network test

    What an attacker could reach once inside, from a stolen laptop or a phished account: shares, servers, databases and admin rights.

  • Web application test

    Your own applications and client portals tested for the common and the less common ways in, with each finding tied to a fix.

  • Microsoft 365 and cloud review

    Your tenant's configuration checked for the gaps that cause most account takeovers: authentication, sharing, mail rules and admin roles.

  • Phishing simulation

    A controlled phishing campaign against your people, with results by department and training for those who clicked. Available as an extra, priced separately.

  • Vulnerability scanning between tests

    Regular automated scanning of your systems between tests, so new weaknesses are found in weeks rather than at the next test. Available as an extra, priced separately.

  • Remediation

    The fixes, done by our engineers, in the order the report sets, with a closed list at the end.

  • A report for clients and insurers

    A summary letter you can send to whoever asked, confirming the scope, the date and that the findings have been addressed.

Tell us what you need

Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.

Prefer to talk? Call 0333 335 5020. A real person answers, always.

LM04.202, The Leather Market
Weston Street, London SE1 3ER
A short walk from London Bridge and Borough stations

Been asked for a penetration test?

Tell us who is asking and what they need to see. Jessica, our Operations Director, replies to every enquiry personally, the same day.

Tell us what you need

How much does a penetration test cost?

It depends on scope: how many internet-facing systems, internal hosts and applications are tested, and whether phishing is included. We give you a fixed quote after a scoping call. If the fixes are done as part of our managed IT service, there is no separate charge for them.

How often should we have a penetration test?

At least once a year, quarterly if you can, and after any major change such as a new office, a new application or a move to the cloud. Many client contracts and most cyber insurers ask for at least an annual test.

What's the difference between a vulnerability scan and a penetration test?

A scan is automated and lists known weaknesses. A penetration test is carried out by a person who uses those weaknesses, and others a scanner can't see, to find out what could actually be reached. Clients and insurers who ask for a pen test will usually not accept a scan in its place. We offer both: scanning between tests, and a full test each year.

Will the test disrupt our business?

It shouldn't. Testing is scheduled for a time you choose, internal tests can run outside hours, and you are told when testing starts and ends. We don't run anything destructive without agreeing it first.

Can we share the report with our clients?

Yes. The full report is for you. Alongside it you get a summary letter confirming the scope, the date and that the findings have been addressed, which is what clients, investors and insurers usually want to see.

The Cyber Security Vault: 22+ tools and apps

Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.

Get the Cyber Security Vault