Skip to content

Cyber Consulting · Penetration Testing

Know where an attacker
would get in, before they do.

Most organisations have security tools in place. Far fewer have validated proof that those tools hold up when a real attacker applies pressure.

SysGroup penetration testing is CREST certified, simulating real-world attacks across your external perimeter, internal network and web applications, then translating what we find into clear, risk-rated remediation.

CREST

Certified methodology

OWASP

Top 10 coverage

CVSS

Severity rating

Scoped

To your size & obligations

A tool deployed is not a tool that works

Annual tick-box testing tells you how you looked last year, not whether today’s controls would stop today’s attacker.

Automated scanners flag theoretical exposure. They rarely show how individual weaknesses chain together into a real compromise.

And when evidence is assembled in a hurry for an auditor or insurer, it reflects effort rather than genuine assurance.

Common challenges

  • Controls assumed to work, never tested under real pressure
  • Scanner output with no proof of real-world impact
  • Findings with no prioritised, actionable remediation
  • No independent validation, with teams testing their own work

The result is a security posture you hope is sound, rather than one you can demonstrate.

What we test

Penetration testing covers your full attack surface. Each engagement is delivered by CREST-certified consultants using a blend of automated tooling and manual technique, so findings are accurate, validated and context-aware.

01

Web Application Testing

Controlled assessment of web applications and their supporting components against real-world attacker techniques.

  • Authentication, authorisation & session management
  • Input validation & business logic
  • OWASP-defined vulnerability classes
  • Static, dynamic and authenticated scopes

Protect sensitive data and reduce the likelihood of a breach.

02

Infrastructure Testing

Assessment of internal and external IT infrastructure, from internet-facing assets to internal segmentation.

  • External perimeter & internet-facing assets
  • Internal segmentation & lateral movement
  • Privilege escalation & credential testing
  • Vulnerability-assessment option for breadth

Reduce your attack surface and validate your network controls.

03

Automated Security Testing

Continuous, scalable visibility across your applications and infrastructure.

  • Continuous application scanning
  • Infrastructure & cloud scanning
  • Frequent, low-impact coverage at scale
  • Early issue detection between manual tests

Maintain visibility of your estate between manual engagements.

04

Red Teaming

Adversary-led, objective-driven simulation across people, process and technology.

  • External & internal exploitation
  • Social engineering & lateral movement
  • Detection & response validation
  • Goal-driven attack scenarios

Test technical defences, detection and resilience together.

05

Mobile Application Testing

Focused assessment of iOS and Android applications and their integration points.

  • Application logic & local data storage
  • API interactions & encryption
  • Authentication & authorisation controls
  • Mobile-specific vulnerability classes

Release mobile apps with confidence they protect user data.

06

Social Engineering

Real-world manipulation scenarios that test human behaviour rather than technical controls.

  • Phishing, vishing & smishing
  • Physical social engineering
  • User awareness & behavioural risk
  • Evidence-led input to training

Understand how attackers exploit trust, and close the gap.

Independent security validation

Assurance you didn't mark yourself

Independent security validation gives an objective assessment of your controls, configurations and resilience against real-world threats.

Testing is delivered by our Cyber Security Consulting division, separate from operational delivery, so you get genuine assurance, not a team marking its own homework.

This programme provides

  • Independent validation by our Cyber Security Consulting division
  • Separation of testing and operational delivery
  • Transparent reporting of findings
  • Formal remediation tracking and validation
  • Board-ready assurance outputs

Delivery standards

  • CREST-certified service and consultants assigned to the engagement
  • Three-step internal quality review process
  • Automated and manual testing to minimise false positives
  • Commercial and open-source tooling
  • Testing scheduled in conjunction with your team

How we test

One consistent methodology, every engagement

All packages follow the same structured methodology, built around CREST and OWASP standards, from initial scope through to validated remediation.

01

Scope & schedule

Engagement scoped to your size and obligations, then scheduled with you. CREST-certified consultants assigned.

02

Test

Combined automated and manual testing across the agreed attack surface, following CREST and OWASP standards.

03

Quality review

A three-step internal quality review minimises false positives before anything reaches you.

04

Report

Findings rated with CVSS: a board-level executive summary plus a full technical report with prioritised remediation.

05

Re-test & validate

Formal remediation tracking, with re-testing to confirm fixes hold. Coverage and window depend on your package.

Internal testing uses an assumed-breach posture.

Our cyber consulting team

The penetration testing specialists who keep your light on

Every SysGroup penetration test is run by named, certified consultants, not a faceless queue. The specialists who scope and run your test are the same people who sit with you for the readout.

Alan Lim, Associate Director · Leads the Penetration Testing & Compliance Consulting Practice at SysGroup
  • Leads the Penetration Testing & Compliance Consulting Practice
  • External & internal pen testing across financial services
  • IT Health Checks (ITHC) for local councils

Team spotlight

Alan Lim

Associate Director · Leads the Penetration Testing & Compliance Consulting Practice

Alan leads the Penetration Testing and Compliance Consulting Practice at SysGroup. He has extensive experience delivering penetration testing across financial services and insurance, running external and internal assessments from multiple attack vectors to identify and demonstrate points of weakness.

His technical expertise spans private and public cloud, Windows and Linux systems and network management devices. He also delivers IT Health Checks for local councils of all sizes, covering infrastructure, network device and end-user build reviews, remote access and Active Directory configuration, and password analysis.

15+ yrs

Cyber security experience

Infrastructure, web app & cloud security

Industry speciality

Financial services, insurance & public sector

Sector focus

Certifications & qualifications

CREST CRTCISSPISACA CISACyber Essentials Lead Assessor
Gavin Solomon, Managing Consultant & Network Penetration Tester at SysGroup
  • Ex-IBM UK Labs graduate research trainee
  • C programmer at the London Stock Exchange
  • Full-stack .NET / ASPX development background

Team spotlight

Gavin Solomon

Managing Consultant & Network Penetration Tester

Gavin is a penetration tester with a background in .NET and full-stack development. That mix of testing tools, penetration-testing methodology and hands-on engineering makes him effective at probing web applications, infrastructure and operational technology for the vulnerabilities that matter.

Though not sector-specific, his work with engineering, banking and retail clients has included security tests on mobile applications, identifying leaks of sensitive data and hardening defences against reverse engineering to protect intellectual property. More recently he has folded AI into his methodology, experimenting with inference engines and LLMs to sharpen security-testing outcomes.

8+ yrs

Cyber security experience

Operational technology & infrastructure

Industry speciality

Insurance, legal & engineering

Sector focus

Certifications & qualifications

CISSPISC2 CCSPCREST CRTCREST CPSA

Service packages

Four tiers. Scoped to your environment.

Every package is an engagement covering three attack surfaces: external infrastructure, internal network and web applications.

Choose the tier that matches your size, regulatory obligations and risk appetite.

Package 1

Essential

For SMEs or organisations running their first formal penetration test. A tightly scoped perimeter, a single internal site and one web application.

Speak to a Specialist
Package 2

Advanced

A step up for a broader perimeter and larger internal estate. Adds full Active Directory enumeration, SMB auditing, wireless testing and WAF evasion.

Speak to a Specialist
Package 3

Professional

Suited to organisations subject to cyber insurance, ISO 27001 or regulatory audit. Multi-site coverage with authenticated web app testing.

Speak to a Specialist
Package 4

Enterprise

For complex, distributed environments. Appropriate for PCI DSS scope, ISO 27001 certification and pre-M&A technical due diligence.

Speak to a Specialist

AD enumeration ranges from light (Essential) to a full domain-compromise attempt (Enterprise). Need bespoke scope, or mobile, red teaming or social engineering? We'll scope it with you.

At a glance

Package comparison

Penetration testing package comparison
PackageExternalInternalWeb appsWeb app depthFindings re-testedRe-test window
EssentialUp to 10 IPs1 site / 1–25 hosts1 appUnauthenticated / 30 pagesCritical & HighWithin 30 days
AdvancedUp to 15 IPs1 site / 26–75 hosts1 appUnauthenticated / 50 pagesCritical & HighWithin 60 days
ProfessionalUp to 25 IPs2 sites / 76–150 hostsUp to 2 appsAuthenticated (1 role)Critical, High & MediumWithin 90 days
EnterpriseUp to 50 IPs3 sites / 151–500 hostsUp to 2 appsMulti-role authenticatedAll severitiesWithin 90 days

All packages include a board-level executive summary and full technical report with prioritised remediation guidance.

What you get out of it

Penetration testing turns assumptions into evidence: exploitable weaknesses found and validated before an attacker reaches them.

01

Exploitable weaknesses identified before attackers reach them

02

Clear, risk-rated findings prioritised by real-world impact

03

Practical remediation guidance your team can act on

04

Validated proof that security controls perform under pressure

05

Evidence for regulatory, insurance and assurance requirements

06

Board-ready confidence that your environment is resilient

Validated assurance, not a report that sits in a drawer.

Built for organisations that need proof

  • Running a first formal penetration test
  • Entering enterprise supply chains and answering security reviews
  • Meeting cyber insurance, ISO 27001 or PCI DSS requirements
  • Preparing for an audit or pre-M&A technical due diligence
  • Stress-testing a complex, multi-site environment

Don't assume your controls hold.

Test them, and prove it.

Frequently asked questions

What does CREST certified mean?

+

Our service and consultants are certified by CREST, the accreditation body for technical security testing. It gives you confidence that testing is rigorous, repeatable and delivered to a recognised professional standard.

How are findings prioritised?

+

Every finding is rated using CVSS and presented by real-world impact, so your team can fix what matters most first. You receive both a board-level executive summary and a full technical report with remediation guidance.

What is an assumed-breach posture?

+

Internal testing starts from the position that an attacker already has a limited foothold, for example from a phished user or a SysGroup implant on the network. It is a realistic way to assess segmentation, privilege management and lateral movement.

Can I get a tailored scope?

+

Yes. If your environment falls outside the package scopes, we agree a bespoke scope with you up front. Talk to a specialist and we will recommend the right tier or shape a custom engagement around your estate.

Do you re-test after we fix issues?

+

Yes. Every package includes re-testing to confirm remediation holds. The severities covered and the window depend on your tier, from Critical and High within 30 days on Essential, to all severities within 90 days on Enterprise.

Can you test mobile apps, run a red team or social engineering?

+

Yes. These advanced services are scoped individually around your objectives, targets and scenarios.

Ready to find out where you stand?