---
title: "Penetration Testing London | Network London"
url: https://www.networklondon.co.uk/cybersecurity/penetration-testing
description: "Penetration testing for firms of 20 to 250 people. Scoped to what your clients or insurers asked for, with a plain-English report and the findings fixed."
publisher: Network London
legal_name: Verdani Solutions Group Limited
---

# Penetration testing for firms that need to prove their defences

A penetration test is a controlled attempt to break into your systems, with a report your board and your clients can read. Network London scopes the test, runs it at a time that suits you, explains every finding in plain English and fixes what it finds, because we look after your IT too.

- Scoped to what your clients, insurers or auditors actually asked for
- Findings explained, then fixed by the same team
- Scheduled to suit you, with notice of start and finish if you want it

## Someone has asked when you last had a penetration test

Does any of this sound familiar?

- A client questionnaire, an investor or your cyber insurer wants a recent penetration test report and you don't have one.
- You had a test done once. The report sat in a folder because nobody owned the fixes.
- A vulnerability scan was sold to you as a pen test. The person asking knows the difference.

A pen test with nobody to fix the findings is an expensive list. We do the test and the fixing.

## What our penetration testing covers

We test the things an attacker would try: your internet-facing systems, your internal network, your Microsoft 365 setup, your web applications and, as a separately priced extra, your people through a phishing campaign. A test goes further than a vulnerability scan. A scan tells you a door is unlocked; a test walks through it and shows what could be reached: weak passwords, sensitive files on open shares, data in databases, permissions that let one account get to everything, and the paths between them.

You get a report that explains each finding, what it means for your business and how it compares with your last test. If you ask for them, we also give notice when testing starts and ends and activity logs you can match against your own monitoring. Then we fix the findings in priority order and test again to show they are closed. Network London holds **Cyber Essentials Plus**.

Tell us who is asking for the test and what systems you run. We'll scope it with you on a call.

## What you get from a penetration test run by the team who look after your IT

- **Scoped properly**: Tested against what was actually asked: the questionnaire, the insurer's wording or the auditor's list. Not more than you need, and nothing that matters left out.
- **A report people can read**: One section for the board, one for the engineers. Every finding rated, explained and tied to a fix, with a summary you can send to the client who asked.
- **Fixed, not filed**: The findings go straight into our work on your systems. You get a closed list and the evidence to show it, rather than a PDF and a to-do.

- **20** years looking after business IT
- **100+** businesses across the world trust us with their IT
- **24/7** support, with a real person on the phone

## Who we work with

Three of the 100+ businesses we look after, and what we do for them.

### Rossair

IT support, the phone system and a website that brings in enquiries, all looked after by one team.

[Read the story](https://www.networklondon.co.uk/case-studies#rossair)

### LAMDA

Everyday support for 180 people, with access reviews and backup testing built into how they work.

[Read the story](https://www.networklondon.co.uk/case-studies#lamda)

### A private equity firm

A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.

[Read the story](https://www.networklondon.co.uk/case-studies#private-equity)

## How a penetration test works with us

1. **Scoping call**: Jessica, our Operations Director, replies the same day. We agree what is in scope, who has asked for the test, what they need to see and when.
2. **The test, at a time you choose**: Testing is scheduled around your business, and we can give notice when it starts and ends. Internal tests can run outside hours.
3. **Report, fixes and evidence**: You get the report, a walkthrough of the findings and a plan. We fix them in priority order, retest, and give you the summary to send on.

## What's included in our penetration testing service

- **External infrastructure test**: Everything of yours that faces the internet: firewalls, remote access, email, web servers and cloud services, tested as an outside attacker would.
- **Internal network test**: What an attacker could reach once inside, from a stolen laptop or a phished account: shares, servers, databases and admin rights.
- **Web application test**: Your own applications and client portals tested for the common and the less common ways in, with each finding tied to a fix.
- **Microsoft 365 and cloud review**: Your tenant's configuration checked for the gaps that cause most account takeovers: authentication, sharing, mail rules and admin roles.
- **Phishing simulation**: A controlled phishing campaign against your people, with results by department and training for those who clicked. Available as an extra, priced separately.
- **Vulnerability scanning between tests**: Regular automated scanning of your systems between tests, so new weaknesses are found in weeks rather than at the next test. Available as an extra, priced separately.
- **Remediation**: The fixes, done by our engineers, in the order the report sets, with a closed list at the end.
- **A report for clients and insurers**: A summary letter you can send to whoever asked, confirming the scope, the date and that the findings have been addressed.

## Tell us what you need

Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.

Prefer to talk? Call [0333 335 5020](tel:+443333355020). A real person answers, always.

Thank you. Your message has been received and we'll be in touch shortly.

Something went wrong sending that. Please call [0333 335 5020](tel:+443333355020) or email [letstalk@networklondon.co.uk](mailto:letstalk@networklondon.co.uk?subject=Network%20London%20-%20IT%20services%20query).

## Been asked for a penetration test?

Tell us who is asking and what they need to see. Jessica, our Operations Director, replies to every enquiry personally, the same day.

### How much does a penetration test cost?

It depends on scope: how many internet-facing systems, internal hosts and applications are tested, and whether phishing is included. We give you a fixed quote after a scoping call. If the fixes are done as part of our managed IT service, there is no separate charge for them.

### How often should we have a penetration test?

At least once a year, quarterly if you can, and after any major change such as a new office, a new application or a move to the cloud. Many client contracts and most cyber insurers ask for at least an annual test.

### What's the difference between a vulnerability scan and a penetration test?

A scan is automated and lists known weaknesses. A penetration test is carried out by a person who uses those weaknesses, and others a scanner can't see, to find out what could actually be reached. Clients and insurers who ask for a pen test will usually not accept a scan in its place. We offer both: scanning between tests, and a full test each year.

### Will the test disrupt our business?

It shouldn't. Testing is scheduled for a time you choose, internal tests can run outside hours, and you are told when testing starts and ends. We don't run anything destructive without agreeing it first.

### Can we share the report with our clients?

Yes. The full report is for you. Alongside it you get a summary letter confirming the scope, the date and that the findings have been addressed, which is what clients, investors and insurers usually want to see.

## Also from Network London

- [Microsoft 365 security](https://www.networklondon.co.uk/cybersecurity/microsoft-365-security): The Microsoft 365 security settings that matter, switched on and kept on.
- [Cyber Essentials cost and process](https://www.networklondon.co.uk/cybersecurity/cyber-essentials-cost): What Cyber Essentials and Cyber Essentials Plus cost, and how we get you through them.
- [Cyber security](https://www.networklondon.co.uk/service/cyber-security): We look after your cyber security and help you answer the security questions your clients, insurers and investors send you.
- [IT compliance](https://www.networklondon.co.uk/service/managed-it-compliance): Help with IT compliance, including Cyber Essentials, ISO 27001 and GDPR, from policies to the questionnaires your clients send.

## The Cyber Security Vault: 22+ tools and apps

Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.

---

Network London, LM04.202, The Leather Market, Weston Street, London SE1 3ER. Telephone 0333 335 5020. letstalk@networklondon.co.uk. Network London is a trading name of Verdani Solutions Group Limited, which owns the Network London trade mark. Verdani Solutions Group Limited is registered in England and Wales, company number 11357867.
