Skip to content
Pentesys
Services

Cybersecurityservicesbuiltaroundyourbusiness

From a single test to a fully managed continuous testing programme, our services combine AI-assisted automation with qualified consultant validation.

Our Services

Five specialist services, one testing partner

Every engagement is human-led, delivered through the Mirage Portal and scoped around the systems, regulations and threat model that matter to you.

External Attack Surface Management

Discover, monitor and reduce your internet-facing exposure before an attacker maps it first.

  • Full asset inventory — domains, subdomains, IPs, cloud resources and APIs
  • 300+ technology fingerprints with version-level vulnerability flagging
  • Breach database scanning for leaked credentials tied to your domains
Explore External Attack Surface Management

Penetration Testing

Human-led testing to uncover vulnerabilities across networks, applications, cloud and infrastructure.

  • 20+ test types across web, API, mobile, network, cloud, IoT and wireless
  • Every finding carries CVSS scoring plus CWE and CVE references
  • Full lifecycle managed: scoping, testing, reporting and remediation support
Explore Penetration Testing

Red & Purple Teaming

Objective-based adversary simulation that tests detection, response and real-world resilience.

  • Full 7-phase kill chain simulation across 8 threat profiles
  • Every technique mapped to the MITRE ATT&CK framework
  • SOC validation measuring Mean Time to Detect and Mean Time to Respond
Explore Red & Purple Teaming

Cyber Essentials

Assessments and readiness support to meet UK compliance and regulatory standards.

  • Gap analysis against Cyber Essentials and Cyber Essentials Plus
  • Clear certification roadmap with remediation support throughout
  • Evidence collection and verification managed in the portal
Explore Cyber Essentials

AI Pentesting

Continuous AI-assisted testing combined with human validation, so you get speed without sacrificing accuracy.

  • Continuous AI-assisted scanning that never sleeps
  • Every critical finding validated by a qualified consultant
  • Human-led triage removes false positives before they reach you
  • Scales coverage across networks, apps, APIs and cloud
Explore AI Pentesting
AI Pentesting

AI acceleration included in every service line

We embed AI-assisted automation across Pentesys services to speed up testing and make continuous security assurance more affordable — without sacrificing the human validation that makes findings trustworthy.

Discuss AI pentesting
  • AI built into every service line

    From attack surface discovery to vulnerability scanning and report drafting, AI acceleration is included in every engagement — not an add-on.

  • Faster testing cycles

    Automated assessment runs continuously across your external surface, networks, applications and APIs, so coverage keeps pace with releases.

  • Human validation on every finding

    Qualified consultants review, triage and confirm every AI-generated result before it reaches you, so you only act on real risk.

  • Security assurance made affordable

    By automating repetitive reconnaissance and scanning work, we keep consultant time focused where it matters — giving you continuous assurance at a sustainable cost.

The Mirage Platform

Four modules, one continuous security programme

Surface finds what you're exposing, Validate proves what's exploitable, Adversary tests whether you would ever notice, and Assure keeps it all audit-ready.

Mirage Surface badge

Mirage Surface

External Attack Surface Monitoring

Continuous discovery and mapping of your entire external attack surface, so unknown exposure never becomes an incident.

  • Continuous discovery of domains, subdomains, IPs, cloud resources and APIs
  • 300+ technology fingerprints with version-level vulnerability flagging
  • SSL certificate monitoring with proactive expiry alerts
  • Breach database scanning for leaked credentials tied to your domains
  • Open port detection with risk-scored exposure analysis
  • Scanning on your schedule — hourly, daily, weekly or monthly
  • Real-time risk score with trend analysis you can act on
Mirage Validate badge

Mirage Validate

Penetration Testing & AI Penetration Testing as a Service

Human-led penetration testing and continuous AI penetration testing, validated by qualified consultants and delivered through a flexible credit model.

  • Human-led testing across 20+ types — not just automated scans
  • Continuous AI penetration testing across web, API, network and cloud
  • Every AI-generated finding validated by a qualified consultant
  • Flexible credit-based model: buy credits and test when you need
  • Web, API, mobile, network, cloud, IoT, wireless and social engineering
  • Full lifecycle managed: scoping, testing, reporting and remediation
  • Every finding tracked with CVSS scoring, CWE and CVE references
  • Scanner integration (Nessus, Acunetix) for hybrid validation
  • Remediation deadlines and SLA compliance tracked automatically
  • Findings export directly into Jira and ServiceNow workflows
Mirage Adversary badge

Mirage Adversary

Red & Purple Teaming as a Service

Intelligence-led adversary simulation that measures whether your people, process and technology actually detect an attack.

  • Real-world adversary simulation across a full 7-phase kill chain
  • 8 threat profiles — ransomware, APT, insider threat and more
  • Every technique mapped to the MITRE ATT&CK framework
  • SOC validation measuring Mean Time to Detect and Respond
  • Managed campaigns with approval gates, scope controls and rules of engagement
  • Detection effectiveness scoring with benchmarked response metrics
  • Full timeline event logging with kill chain phase assignment
  • Comprehensive reporting with detection analytics
Mirage Assure badge

Mirage Assure

Governance, Risk & Compliance

Continuous assurance that maps every finding to the frameworks your auditors, regulators and customers care about.

  • Control mapping across ISO 27001, SOC 2, NIS2, DORA and PCI DSS
  • Cyber Essentials and Cyber Essentials Plus readiness tracking
  • Evidence collection and audit-ready reporting on demand
  • Risk register with owners, treatment plans and due dates
  • Policy and remediation SLA monitoring across the estate
  • Board-ready posture reporting with trend analysis
Module detail

Inside every Mirage module

The workflows, capabilities, coverage and deliverables behind Surface, Validate, Adversary and Assure.

Mirage Surface badge

Mirage Surface

External Attack Surface Management (EASM)

Continuously discover, inventory and monitor every internet-facing asset your organisation owns. Mirage Surface identifies exposures before attackers do, with automated discovery, risk scoring and real-time alerting.

  1. 01

    Asset discovery

    Subdomains, IPs, ports, CT logs, DNS

  2. 02

    Tech detection

    300+ fingerprints across frameworks & servers

  3. 03

    Tech analysis

    Version tracking, CVE correlation, risk scoring

  4. 04

    Credential scanning

    Breach databases, leaked password detection

  5. 05

    Dark web

    Forums, Pastebin, GitHub, Telegram monitoring

Asset discovery

Multi-source subdomain enumeration via SecurityTrails, Certificate Transparency logs and DNS resolution, with automatic deduplication and normalisation.

Port & service scanning

Quick and full port scans with service identification, banner grabbing and protocol detection. Risk-scored exposure analysis for every open port.

Technology fingerprinting

300+ detection patterns across web servers, frameworks, CMS, CDN, analytics, cloud platforms and security tooling, with version-level vulnerability correlation.

SSL/TLS monitoring

Certificate health grading (A+ to F), expiry alerting, TLS version detection, HSTS checks and self-signed certificate identification.

Credential leak monitoring

Continuous scanning of breach databases for leaked credentials tied to your domains, with severity-rated alerts and breach source attribution.

Dark web monitoring

Ongoing monitoring of dark web forums, paste sites, GitHub and Telegram channels for leaked credentials, data dumps and mentions of your organisation.

Technology detection coverage

  • Servers (20+) — nginx, Apache, IIS, LiteSpeed, Caddy, OpenResty, Traefik
  • Frameworks (100+) — React, Vue, Angular, Next.js, Laravel, Django, Spring Boot, Rails
  • CMS & commerce (50+) — WordPress, Drupal, Shopify, Magento, Ghost, WooCommerce
  • Cloud & CDN (25+) — AWS, Azure, GCP, Cloudflare, Akamai, Vercel, Fastly

Attack surface risk score

  • 30% — high-risk assets: critical and high-severity exposure
  • 20% — critical ports: dangerous services exposed to the internet
  • 20% — leaked credentials: confirmed breaches with severity rating
  • 15% — SSL issues: expired or misconfigured certificates
  • 15% — port exposure: distribution of risky open ports

Monitoring & reporting

  • Scheduling: hourly monitoring, daily scans, weekly sweeps, monthly audits
  • Per-domain scan configuration
  • Attack surface, SSL health and port exposure reports
  • Executive summary with PDF and JSON export

Engagement deliverables

  • Full asset inventory
  • Attack surface risk score
  • Port exposure report
  • SSL health report
  • Technology stack map
  • Credential leak alerts
  • Executive summary
  • Continuous monitoring
Mirage Validate badge

Mirage Validate

Penetration Testing as a Service (PTaaS)

Human-led penetration testing with a flexible credit-based model. Buy credits and test when you need — across web, API, mobile, network, cloud and more, with full lifecycle management from scoping to remediation.

  1. 01

    Scope

    Guided wizard, dynamic effort calculation

  2. 02

    Allocate

    Credits reserved, prerequisites collected

  3. 03

    Auto-scan

    Free Nessus & Acunetix scanning

  4. 04

    Manual test

    Human-led validation & exploitation

  5. 05

    QA & report

    Internal QA, findings released

  6. 06

    Remediate

    Track fixes, retest when ready

Vulnerability management

Full finding lifecycle with CVSS scoring, CWE/CVE tracking, evidence attachments and severity-based prioritisation through a Draft → QA → Open → Fixed workflow.

Integrated scanning

Built-in Nessus and Acunetix integration. Automated scans are free — only human validation consumes credits — and scan findings flow straight into the pentest workflow.

Dynamic effort estimation

A scoping questionnaire drives automated effort calculation using per-unit, range and boolean factors, with 15% planning overhead built in and manual adjustment supported.

Prerequisites gateway

Structured collection of VPN access, credentials, test accounts and API documentation, with an approval workflow that guarantees readiness before testing starts.

Evidence management

Attach screenshots, logs, HTTP requests/responses and code snippets to every finding, with inline viewing, captions and descriptions for clear communication.

Recurring engagements

Schedule continuous testing weekly, monthly, quarterly or annually, with occurrence tracking and comparison analytics across test cycles.

Supported test types

  • Web application — OWASP Top 10, business logic, authn/authz
  • API testing — REST, GraphQL and SOAP endpoints
  • Mobile — iOS and Android with MASVS coverage
  • Network — internal and external infrastructure
  • Cloud — AWS, Azure and GCP misconfiguration and IAM
  • Wireless — WPA/WPA2, rogue AP, segmentation
  • IoT — embedded devices, firmware and protocols
  • Social engineering — phishing, vishing and physical access

Finding lifecycle

  • CVSS v3.1 scoring with full vector string
  • CWE classification and CVE cross-referencing
  • QA approval gate — findings hidden until reviewed
  • Remediation notes with timestamped audit trail
  • Automatic Jira and ServiceNow ticket creation

Credit model

  • Credits are pre-approved and pre-purchased at a discounted rate
  • 12-month validity from purchase date
  • Volume discounts: 5% (10+), 10% (25+), 15% (50+)
  • Pre-configured bundles with bonus credits
  • Real-time balance tracking and expiry warnings

Engagement deliverables

  • Executive summary
  • Technical findings report
  • Risk-rated vulnerability matrix
  • Remediation roadmap
  • Free retest verification
  • Attestation letter
  • Automated scan results
  • Full audit trail
Mirage Adversary badge

Mirage Adversary

Red Team as a Service (RTaaS)

Full-spectrum adversary simulation with MITRE ATT&CK mapping, kill chain tracking and detection validation — measuring your SOC's ability to detect and respond to real-world threat actors.

  1. 01

    Recon

    Target research and intelligence gathering

  2. 02

    Weaponise

    Tooling and payload preparation

  3. 03

    Deliver

    Initial access attempts

  4. 04

    Exploit

    Execution and privilege escalation

  5. 05

    Install

    Persistence establishment

  6. 06

    C2

    Command and control channels

  7. 07

    Actions

    Objectives on target

MITRE ATT&CK mapping

Full 14-tactic ATT&CK matrix integration. Every technique and sub-technique is mapped to the framework with execution status, detection indicators and evidence.

Detection validation

Measure SOC effectiveness in real time, tracking Mean Time to Detect and Respond across 11 detection sources including SIEM, EDR, NDR, IDS/IPS and WAF.

Campaign timeline

Chronological attack narrative with kill chain phase assignment, outcomes, target systems and operator tracking — a full audit trail of every action taken.

Objective tracking

Define up to five campaign objectives from 50+ templates across seven categories, tracked with evidence, success criteria and priority levels.

TTP profile library

Eight pre-built attack scenarios from ransomware to APT to purple team. One-click loading populates techniques with full ATT&CK mapping.

Rules of engagement

Formal approval workflow with scope definition, ROE documentation, kickoff scheduling and contract reference, under a state-controlled campaign lifecycle.

Pre-built TTP profiles

  • Ransomware operator — 19 techniques
  • APT data exfiltration — 19 techniques
  • Insider threat — 13 techniques
  • Cloud infrastructure — 14 techniques
  • Web app attack — 15 techniques
  • Active Directory takeover — 15 techniques
  • Business email compromise — 11 techniques
  • Purple team validation — 21 techniques

Detection sources tracked

  • SIEM — log correlation and alerting
  • EDR — endpoint detection and response
  • NDR — network detection and response
  • IDS/IPS — intrusion detection and prevention
  • DLP — data loss prevention
  • SOC analyst — manual detection by operators
  • Threat hunting — proactive search operations

Blue team metrics measured

  • Detection rate — % of techniques detected
  • MTTD — Mean Time to Detect (minutes)
  • MTTR — Mean Time to Respond (minutes)
  • Technique success rate — % achieving objective
  • Kill chain penetration — deepest phase reached
  • Objective achievement — goals met vs attempted
  • Response breakdown — detected, investigated, contained, recovered

Engagement deliverables

  • ATT&CK coverage matrix
  • Attack narrative timeline
  • MTTD / MTTR metrics
  • Objective achievement report
  • Detection gap analysis
  • Executive summary
  • Remediation roadmap
Mirage Assure badge

Mirage Assure

Compliance & Assurance

Fixed-scope, expert-led compliance engagements covering Cyber Essentials, Cyber Essentials Plus, PCI-ASV quarterly scans and ISO 27001 readiness. Every engagement is structured, transparent and delivered through the Mirage portal.

  1. 01

    Scoping & proposal

    Scope defined, deliverables agreed, fixed-price proposal — no hidden fees

  2. 02

    Assessment & evidence

    Requirements tracked in portal; you upload evidence, we assess each control

  3. 03

    Remediation & delivery

    Gaps identified with clear advice, plus reports, certificates and submission packs

Engagement dashboard

Real-time compliance progress tracking across all active engagements with per-framework breakdowns and status indicators.

Requirement tracking

Every requirement mapped, categorised and tracked to completion, with pre-loaded templates for CE, CE+, PCI-ASV and ISO 27001.

Evidence management

Upload, review and manage evidence linked to specific requirements, with files tracked by status, reviewer notes and audit trail.

Assessor notes

Direct feedback from assessors with per-requirement remediation guidance, compliance status and priority indicators.

Artefact delivery

Reports, gap analyses, certificates and submission packs delivered through the portal with version tracking.

Activity audit

A full audit trail of every action taken during the engagement — evidence uploads, status changes, assessments and deliveries.

Cyber Essentials & CE+

  • SAQ preparation and review
  • Policy and procedure gap analysis
  • Boundary device and access control review
  • IASME submission support
  • CE+: technical controls verification and external vulnerability scanning
  • CE+: simulated phishing test, MFA verification, on-site or remote audit

PCI-ASV scanning

  • Quarterly external vulnerability scans by an Approved Scanning Vendor
  • Scan scope definition
  • Vulnerability remediation support
  • Passing scan attestation
  • Dispute resolution and compliance reporting

ISO 27001 readiness

  • ISO 27001:2022 gap analysis
  • Risk assessment methodology
  • Statement of Applicability review
  • ISMS documentation guidance
  • Control implementation advice
  • Certification readiness report

Engagement deliverables

  • Readiness report
  • Gap analysis
  • Remediation plan
  • Submission pack
  • Certificate
  • ASV scan report
  • Compliance report
  • Full audit trail
In Depth

What each engagement actually involves

Expert-led services designed to uncover vulnerabilities, support compliance and strengthen your posture through continuous testing and real-time insight.

EASM

External Attack Surface Monitoring

Pentesys delivers advanced external attack surface monitoring through a continuous discovery approach supported by the Mirage platform. We continuously identify and track your internet-facing assets, uncovering exposures and risks before they can be leveraged by attackers.

Combining automated discovery with risk intelligence, we provide ongoing visibility of your external footprint, real-time exposure monitoring and actionable insight to reduce your attack surface.

  • Continuous discovery of internet-facing assets
  • Full visibility of domains, subdomains, IPs and cloud resources
  • Real-time identification of exposed services and misconfigurations
  • Proactive alerts for emerging risks and attack surface changes
  • Improved posture through continuous exposure management
Request consultation

PTaaS

Penetration Testing as a Service

Our certified security experts simulate real-world attack techniques to identify weaknesses before malicious actors can exploit them, delivered continuously through the Pentesys Portal rather than as a single annual exercise.

Using a combination of manual testing and smart automation, we provide ongoing visibility of your security posture, real-time vulnerability tracking and collaborative remediation support.

  • Identify critical vulnerabilities early
  • Continuous testing and retesting capabilities
  • Real-time vulnerability insight through the portal
  • Detailed remediation guidance and reporting
  • Protection across networks, applications and cloud systems
Request consultation

RTaaS

Red & Purple Teaming as a Service

Our experienced red and purple team operators emulate real-world threat actors to test your organisation's ability to prevent, detect and respond to sophisticated attacks.

Blending manual tradecraft with intelligence-led scenarios, we deliver ongoing insight into your resilience, continuous validation of controls and detailed feedback to strengthen detection and response.

  • Real-world attack simulation tailored to your organisation
  • Continuous testing of detection and response capability
  • Gaps identified across people, process and technology
  • Actionable reporting with clear improvement guidance
  • Enhanced resilience against advanced and targeted threats
Request consultation

Compliance

Helping you meet regulatory security requirements

Pentesys supports organisations in achieving and maintaining compliance with frameworks such as Cyber Essentials and other regulatory security standards. Our audits evaluate your current posture, identify gaps and give clear guidance for certification.

We work closely with your team to simplify compliance while strengthening your overall security framework.

  • Support for regulatory and insurance requirements
  • Structured security assessments and gap analysis
  • Clear compliance roadmaps and remediation support
  • Improved trust with customers, partners and stakeholders
  • Reduced risk of regulatory penalties
Request consultation

Consulting

Strategic security expertise tailored to your business

Our consulting services help organisations design, implement and improve cybersecurity strategies that align with business objectives and regulatory demands.

Pentesys works as a trusted partner to assess risk, enhance security controls and build long-term resilience against cyber threats.

  • Customised cybersecurity strategies
  • Risk assessment and security programme development
  • Security architecture and infrastructure guidance
  • Incident response planning and preparation
  • Long-term cybersecurity improvement strategies
Request consultation

AI Pentesting

Continuous testing at machine speed, validated by people

Our AI pentesting capability runs continuous automated assessment across your external attack surface, networks, applications and APIs. It gives you constant coverage between traditional engagements, so new exposure is caught fast.

Speed is only half the story. Every AI-generated finding is reviewed, triaged and validated by a qualified Pentesys consultant before it becomes a report item — removing false positives and keeping the insight actionable.

  • Continuous automated testing across web, API, network and cloud assets
  • AI-assisted vulnerability discovery and business-impact prioritisation
  • Every finding validated by a qualified consultant before delivery
  • False positives filtered out so your team focuses on real risk
  • Seamless hand-off into remediation, retesting and compliance workflows
Request consultation
PTaaS

Penetration Testing as a Service

Continuously assess your security posture through an ongoing, managed testing service tailored to your environment — with ease and flexibility.

  • Continuous testing

    Move beyond point-in-time tests to ongoing, adaptive assurance.

  • Flexible scheduling

    Test on your terms. No rushed fixes driven by a fixed test date.

  • Human validation

    Every AI-assisted finding is validated by a qualified consultant.

  • Credits

    Buy testing capacity once, then spend it as your programme evolves.

  • Portal integration

    Manage scope, progress, findings and retests in one place.

  1. 1

    Scope

    Define assets, test types and objectives in the portal.

  2. 2

    Testing

    Human-led testing supported by AI coverage.

  3. 3

    Reporting

    Live findings with actionable remediation guidance.

  4. 4

    Retesting

    Validate fixes as soon as they ship.

  5. 5

    Continuous monitoring

    Track posture and exposure between engagements.

“Our mission is continuous penetration testing — enabling businesses to evolve from static, point-in-time tests. Assurance is the key, not just testing.”

James Hinton · Founder

Compliance

Mapped to the frameworks you're audited against

Centralise evidence, map findings to controls and produce audit-ready reporting across every standard in scope.

ISO 27001

Continuous assurance against Annex A controls

Cyber Essentials

Simplify evidence collection and tracking

Cyber Essentials +

Manage remediation and verification activities

NIS2

Support operational resilience and compliance

TIBER-EU

Manage threat-led red team assessments

PCI DSS

Track vulnerabilities and compliance requirements

CIS Controls

Align findings to prioritised security controls

SOC 2

Evidence continuous monitoring for auditors

How We Secure You

From testing and reporting to remediation and continuous monitoring

We secure your business at every step, with a repeatable methodology on every engagement.

01

Plan & Scope

Define testing type, assets and objectives quickly via the portal.

02

Test & Assess

Human-led penetration testing across networks and applications.

03

Report & Remediate

Clear findings with actionable remediation guidance for your team.

04

Monitor & Retest

Track progress in real time, retest issues and maintain security.

Why Pentesys

More than an annual penetration test

Compare a modern PTaaS programme with a traditional consultancy engagement.

Feature comparison between Pentesys and a traditional consultancy
CapabilityPentesysTraditional Consultancy
Human TestingIncluded with PentesysSometimes included
AI AssistedIncluded with PentesysSometimes included
PTaaSIncluded with PentesysNot included
Continuous TestingIncluded with PentesysNot included
Client PortalIncluded with PentesysNot included
Live ReportingIncluded with PentesysNot included
CreditsIncluded with PentesysNot included
RetestingIncluded with PentesysNot included
API IntegrationsIncluded with PentesysNot included
Flexible SchedulingIncluded with PentesysNot included
Executive DashboardsIncluded with PentesysNot included
Compliance MappingIncluded with PentesysNot included
CREST approved accreditation logo

CREST Approved

Independently assessed against the highest technical and operational standards in the penetration testing industry.

Accreditation

CREST approved penetration testing

CREST accreditation means our people, processes and reporting have been independently validated — so you can trust the results and prove them to anyone who asks.

CREST-approved methodology

Every engagement follows CREST-aligned scoping, testing and reporting standards — repeatable, auditable and accepted by regulators, insurers and enterprise procurement teams.

Qualified, vetted consultants

Testing is delivered by certified consultants working to CREST codes of conduct and ethics, with background-checked personnel and strict handling of client data.

Evidence your stakeholders accept

CREST-aligned reports and attestation letters map findings to risk, so boards, auditors and customers get assurance in a format they already recognise.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.