Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

Penetration Testing Services

Identify and fix vulnerabilities before attackers exploit them.

Penetration Testing

You cannot fix the vulnerabilities you do not know about. Penetration testing simulates real-world attacks on your systems to find the weaknesses before someone with bad intent does. We deliver penetration testing through our partner network of CREST-certified consultants, across internal systems, web applications, cloud, and mobile, with results presented clearly so you know exactly what to fix.

What testing covers

Real-world attack simulation across your internal systems, web applications, cloud, and mobile platforms. The findings are delivered through secure portals showing the risks and the remediation steps, so the output is genuinely actionable rather than a wall of technical noise.

Delivered by certified experts

Testing is carried out through our partner network of CREST-certified consultants, recognised for rigour and quality. Alongside technical testing, we offer phishing simulation through Citation Cyber to test and improve staff awareness over time.

Why it matters

Regular testing is how you stay ahead of attackers and demonstrate due diligence to clients, partners, and regulators. It turns unknown risk into a clear, prioritised list of things to put right.

Which type of test do you need?

The right test depends on what you rely on and what worries you most. An external test looks at what anyone on the internet can reach, such as firewalls, remote access and public services. An internal test asks what someone could do once inside your network, for example through a compromised laptop or a careless click. Web application testing examines the sites and portals your customers and staff log in to, while cloud testing looks at how your hosted services and accounts are set up. Mobile testing covers the apps you publish and the data they hold. Most organisations do not need everything at once. When you come to us for penetration testing services, we start by understanding your systems and your risks, then help you choose the tests that will tell you the most for your budget.

What CREST certification means for you

CREST is an independent, not for profit body that accredits penetration testing providers and certifies individual testers. Accredited companies have to show that their methods, their handling of client data and the competence of their people meet its standards, and certified testers have passed demanding practical examinations. For a buyer, that gives assurance that the work follows a recognised methodology rather than one tester's habits. We are open about how we deliver this: Vinula does not employ its own penetration testers. Testing is carried out through our partner network, which includes CREST-certified testing through Citation Cyber, alongside PenTest People. Our role is to help you scope the work, make sense of the findings and turn them into a plan that fits the rest of your security and compliance programme. We support organisations in Sussex, London and across the UK, and much of the coordination is handled remotely.

Scoping and rules of engagement

A good test starts well before anyone touches your systems. Scoping agrees exactly what will be tested, such as named addresses, applications or cloud accounts, and what is out of bounds. The rules of engagement then set how the test will run: the testing window, who to call if something unexpected happens, whether any techniques are excluded, and how sensitive data found along the way will be handled. You give written authorisation for all of it, which matters both legally and practically, because it protects your organisation and the testers and means nobody is surprised. If you use hosted or third party services, their terms may also need checking before testing begins. We help you work through these questions in plain language, so the scope reflects your real risks rather than whatever is easiest to test.

What the report tells you, and what happens next

The output of a test is a report, and a useful one is written for two audiences. A summary explains in plain terms what was found and what it means for the business, so leadership can make decisions. The technical detail then sets out each finding, how it was discovered, how serious it is and how to put it right, so your IT team or supplier can act. With our partners, results are delivered through secure portals that show the risks and track remediation progress over time, rather than a document that is read once and filed. Fixing the issues is the point of the exercise, so it is worth agreeing at the scoping stage how fixes will be checked, for example through a retest of the most serious findings. We then help you prioritise the work and fold it into your wider risk treatment.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

Penetration testing delivered through our partner network of CREST-certified and CHECK-accredited consultants, across internal systems, web applications, cloud and mobile. Plus phishing simulation through Citation Cyber to test and improve staff awareness over time.

Pricing: There is no fixed price guide. Cost depends on the scope, size and complexity of the test. Enquire and we will scope it with you.

What is included

Bronze
  • Penetration testing across internal systems, web applications, cloud environments and mobile platforms
  • Real-world attack simulation with clear, actionable findings
  • Results delivered through secure portals showing risks and remediation progress
  • Phishing simulation through Citation Cyber to build staff awareness

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

There is no fixed price guide. Cost depends on the scope, size, and complexity of what is being tested. Get in touch and we will scope it with you so you know exactly what is involved.

Testing is delivered through our partner network of CREST-certified consultants, a recognised mark of quality and rigour in the penetration testing industry.

Yes. Alongside technical penetration testing, we offer phishing simulation through Citation Cyber, so you can test and strengthen your people's awareness over time, not just your technology.

As general good practice, most organisations test at least once a year and again after any significant change, such as a new application, a move to the cloud, a major network change or recovery from an incident. A test only shows your position on the day it runs, so the right frequency depends on how quickly your systems change and how sensitive your data is. We can help you set a schedule that fits your risk.

A vulnerability scan is an automated check that looks for known weaknesses and produces a list. A penetration test is carried out by skilled people who try to exploit weaknesses, combine them and show what an attacker could actually achieve. Scans are useful for regular hygiene between tests, while a penetration test gives deeper assurance and separates the findings that matter from those that do not.

Yes, when it is properly authorised. Accessing computer systems without permission is an offence under the Computer Misuse Act, which is why every test runs under written authorisation from the system owner, with an agreed scope and rules of engagement. If any systems are hosted by a third party, their permission or terms may also apply. We help you put the right authorisation in place before testing starts.

Testing is planned to keep disruption to a minimum. The rules of engagement agree when testing happens, which systems are included and who to contact if anything behaves unexpectedly, and fragile or business critical systems can be handled with extra care or tested at quieter times. No test is entirely without risk, so it is sensible to confirm your backups first, and we will talk this through with you when scoping.

Neither makes a penetration test mandatory, but both benefit from one. ISO 27001 expects you to manage technical vulnerabilities, and testing is strong evidence that you do. Cyber Essentials Plus includes a hands on technical check by an assessor, which is narrower than a penetration test, so testing beforehand can surface issues early. We can help you decide what testing best supports your certification goals.

Interested in Penetration Testing?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation