Get a free audit

Continuous Penetration Testing · United Kingdom

Continuous penetration testing. Your estate changes every week. Your proof should too.

An annual penetration test is true for about a day. Then a deploy ships, a supplier connects, a credential leaks, and the report describes a company that no longer exists. Continuous penetration testing keeps the proof current: one engagement, then a CREST-certified operator re-runs the attack whenever you fix something or something changes, for a full year.

CREST-certified operators · unlimited re-tests for 12 months · every finding human-verified, on every re-run

CRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNIST

What is continuous penetration testing?

Continuous penetration testing is a penetration test that does not end when the report lands. A qualified tester attacks your systems, proves which weaknesses open a door, and then keeps re-running that attack as your estate changes: after every fix you ship, on a schedule you agree, and whenever a new exposure appears. The result is a standing record of what is exploitable today, rather than a snapshot of what was exploitable last spring.

The gap it closes is measured in days. Mandiant put the median time an attacker spent inside a victim network in 2025 at 14 days before discovery. Cyber Essentials v3.3 gives you 14 days from release to install a high-risk patch. And the median organisation in the 2026 Verizon dataset had 50 per cent more critical vulnerabilities to remediate than the year before. Against that clock, a test that runs once every twelve months leaves you unproven for the other 351 days.

Most of what is sold as "continuous pentesting" is a vulnerability scanner with a subscription. A scanner tells you what might be wrong. It does not chain three medium findings into domain admin, and it does not tell you that the fix you shipped on Tuesday actually holds. Ours does, because a person re-runs the attack and confirms it. That is the line between continuous scanning and continuous penetration testing, and the whole page is about that line.

14 days

Median time an attacker spent inside a victim network in 2025 before being discovered, up from 11 the year before. An annual test cannot see inside that window.

Mandiant M-Trends 2026

+50%

More critical vulnerabilities to remediate at the median organisation than a year earlier. The backlog grows faster than a yearly cadence can prove it closed.

Verizon 2026 Data Breach Investigations Report

13%

Of UK businesses carried out a penetration test in the last twelve months, while 43% reported a breach or attack. Most of the 43% were never tested at all.

Cyber Security Breaches Survey 2025/2026, GOV.UK (DSIT)

What stays under test

Everything that moves between annual tests

The first engagement is a full penetration test of the agreed scope. What follows is where the value sits.

TriggerWhat happens
You ship a fixYou close the ticket in the findings queue. A CREST-certified operator re-runs the original attack against the patched system and confirms the door is shut before the finding is allowed to close. Unlimited for twelve months.
Your surface changesA new subdomain, a fresh cloud account, a supplier integration, a login page nobody registered. Scheduled re-runs of the reconnaissance phase catch what was added since the last pass, and anything new goes through the same proof.
A credential leaksCompany credentials surfacing in a third-party breach are tested against your live login pages under the agreed rules, so a leaked password becomes a ticket, not an incident.
A patch cycle landsEdge devices, remote-access appliances and exposed services are re-checked after each patch window against the weaknesses that are actually being exploited, so "we patched it" becomes "we proved it".
An assessor asksCyber Essentials Plus, PCI DSS, an FCA questionnaire, a client due-diligence form. You export the current, verified state of the scope, dated today, instead of a PDF from March.
The scope growsWhen you add a system to the agreed scope, it enters the same cycle: first attack, proof, fix, re-test. The record stays one record.

What of yours is already exposed?

We search the breach corpus and the criminal markets for your domain, your staff addresses and the credentials attached to them. You get the list back, whether or not we ever speak.

How it runs

One engagement, then a year that keeps testing

The first six weeks look like a normal penetration test. The next forty-six are the difference.

  1. 01

    Scope and authorisation

    You tell us what matters. We agree what is in scope, what is off-limits, and the schedule for re-runs. You sign the authorisation once; it covers the year.

  2. 02

    The first attack

    A full penetration test of the scope: reconnaissance, exploitation, escalation. Every finding proven and verified by a CREST-certified operator before you see it.

  3. 03

    Findings become a queue

    Each finding arrives as a tracked ticket with severity, evidence and the fix, pushed into your own backlog if you prefer. Your team owns the record from day one.

  4. 04

    Fix, then re-test

    You ship a fix and trigger a re-test from the ticket. The operator re-runs the attack and closes the finding only when it holds. Unlimited for twelve months.

  5. 05

    Scheduled re-runs

    Reconnaissance and exposure checks re-run on the cadence you agreed, so new subdomains, new cloud accounts and leaked credentials enter the queue before an attacker finds them.

  6. 06

    The record, dated today

    At any point you export the current verified state of the scope for your board, your assessor or a client. Time-to-fix is tracked, so you can show the trend, not just the snapshot.

Which one are you actually buying?

Annual test vs continuous scanning vs continuous penetration testing

Three products share a vocabulary. They answer different questions and they cost you in different places.

ModelWhat it provesWhere it fails you
Annual penetration testWhich weaknesses opened a door on the day of the test, proven by a person.True for one day. The other 364 you are working from memory. Fixes are never re-verified unless you pay for a second test.
Continuous automated scanning ("PTaaS" from a platform)Which known signatures a tool can match against your systems, every week.It produces a list, not evidence. It cannot chain findings, cannot test business logic, and cannot confirm a fix holds. Sold as a tester, priced as a subscription.
Continuous penetration testing (this page)Which weaknesses open a door today, proven by a person, and re-proven after every fix and every change for twelve months.You cannot switch it on like a tool. It needs a scope, an authorisation and an operator, which is why it starts with a real engagement.

What you get

A standing record of what is exploitable today

Your deliverable
  • A full CREST-certified penetration test of the agreed scope, findings proven and ranked
  • Every finding as a tracked ticket: severity, evidence, the fix, and its current status
  • Unlimited re-tests for twelve months, each one re-run and confirmed by a person, not a scanner
  • Scheduled re-runs of reconnaissance and exposure checks as your estate changes
  • Time-to-fix tracking, so you can show your board the trend and your assessor the current state
  • Findings pushed into Jira or Azure DevOps if you want them there; the record stays yours either way

Before you ask

Continuous penetration testing, answered

What is continuous penetration testing?

Continuous penetration testing is a penetration test that keeps running after the first report. A qualified tester proves which weaknesses in your systems open a door, and then re-runs that attack after every fix you ship and on a schedule as your estate changes, typically for twelve months. Unlike a vulnerability scanner on a subscription, each re-run is performed and verified by a person, so the record shows what is exploitable today rather than what a tool flagged.

What is the difference between continuous penetration testing and penetration testing as a service (PTaaS)?

The terms overlap and vendors use them loosely. Penetration testing as a service usually describes a platform: you subscribe, a scanner runs against your systems, and findings appear in a dashboard. Some PTaaS providers add human testers to that; many do not. Continuous penetration testing, as we deliver it, starts with a full human-led engagement and keeps a CREST-certified operator in the loop for every re-test. The test is continuous; the automation is only the plumbing that gets findings into your backlog.

Is continuous penetration testing just vulnerability scanning?

No. A scanner matches signatures and produces a list of what might be wrong. It cannot chain a low-severity finding and two misconfigurations into domain admin, cannot test business logic, and cannot tell you whether the fix you shipped actually closed the path. Continuous penetration testing does all three, because a person performs and verifies each attack. Scanning belongs in the cycle as a data source. It is not the test.

How often should a penetration test be run?

The regulatory floor is at least once every twelve months and after any significant change: that is what PCI DSS v4.0.1 Requirement 11.4 asks for, and what most UK client questionnaires and Cyber Essentials Plus assessors expect. The operational answer is "every time something changes", because Mandiant's 2025 median dwell time is 14 days and your perimeter changes weekly. Continuous penetration testing satisfies the floor with the first engagement and the operational answer with the re-tests.

How much does continuous penetration testing cost?

It is priced as one engagement, and the twelve months of unlimited re-tests and scheduled re-runs are included in that engagement rather than sold as a second product. The cost depends on the size of the scope and the type of test, which we agree with you in a short call. You pay for the work, not for a platform seat. We do not publish a rate card, because two organisations with the same headcount rarely have the same attack surface; the free audit is how we size it.

Does the first engagement satisfy Cyber Essentials Plus, PCI DSS or an FCA request?

The first engagement is a full CREST-certified penetration test, so it produces the report those frameworks ask for. What the continuous model adds is that the report does not age: when an assessor or client asks six months later, you export the current verified state of the scope, dated that day, including which findings were fixed and re-tested and how long each took.

Rather talk it through?

Book a 30-minute scoping call with an operator. You leave with a scope and a fixed price.

A security lead in a London office at dusk.

Find out what is exploitable in your estate today, and keep the answer current for a year.