Get a free audit

Vulnerability Assessment and Penetration Testing · United Kingdom

Vulnerability assessment and penetration testing. Both halves.

A vulnerability assessment tells you what is known to be weak. A penetration test tells you which of those a person can actually use, and what it reaches once they do. Buy one without the other and you are guessing at your own risk register.

CREST-certified operators · authenticated scanning plus manual exploitation · every finding proven · free retest at 60 days

Get a fixed quote in 48 hours.

Three fields. An itemised price in writing, no call needed to get it.

CRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNIST

What is VAPT?

VAPT is one engagement with two halves. The vulnerability assessment enumerates what is known-vulnerable across your estate: missing patches, weak configuration, exposed services, components with published exploits. The penetration test then takes those findings and proves which of them a person can chain into real access.

The order matters. An assessment on its own hands you a list ranked by a generic severity score, with no sense of which entries an attacker could actually use against you. A test on its own goes deep on a narrow path and may walk straight past a patch gap sitting elsewhere in the estate.

Run together, they answer the two questions a board actually asks. What is wrong, and what happens if someone uses it.

What is covered

What a UK VAPT engagement includes

HalfWhat we do
Assessment: external estateEvery internet-facing host, service and certificate in the agreed scope, authenticated where credentials exist. Missing patches, end-of-life components, exposed management interfaces and misconfiguration.
Assessment: internal estateServers, workstations, identity and the network fabric between them, scanned with credentials so the result reflects what is installed rather than what responds to a probe.
Test: exploitationA CREST-certified operator takes the assessment findings and proves which are reachable and usable, chaining them the way an attacker would rather than reporting them in isolation.
Test: privilege and lateral movementWhat one working credential reaches. Where it escalates. Which systems trust it that should not.
Test: business logicThe class no scanner reports, because the application is doing exactly what it was built to do in a situation nobody considered.
Evidence and remediationEvery finding reproduced with the request or command that worked, ranked by what it reaches, with the fix written for the team that owns that layer.

What of yours is already exposed?

We search the breach corpus and the criminal markets for your domain, your staff addresses and the credentials attached to them. You get the list back, whether or not we ever speak.

How it runs

Four stages, two to three weeks

  1. 01

    Scope and rules of engagement

    We agree what is in scope, what is explicitly out, the testing window and who to call if something looks live. Signed before anything is touched.

  2. 02

    Assessment

    Authenticated and unauthenticated scanning across the agreed estate. The output is the input to the next stage, not a deliverable we hand you and invoice for.

  3. 03

    Manual testing and exploitation

    An operator works the findings by hand, proves what is usable, and chains what chains. Anything that cannot be reproduced does not reach the report.

  4. 04

    Report, walkthrough and retest

    A written report plus a session with the people who have to fix it. Every fixed finding is retested free at 60 days, so you can close it properly.

The difference

Two halves, two questions

If a supplier quotes you VAPT and the deliverable is a tool export, you are buying half of it at the price of both.

Vulnerability assessmentPenetration test
Question answeredWhat is known to be weak?What can someone actually do with it?
MethodAuthenticated and unauthenticated scanning across the agreed estateA CREST-certified operator working by hand, chaining findings into access
CoverageBroad. Every host, every service in scopeDeep. The paths that lead somewhere
Finds logic flawsNo. A tool cannot know your approval workflow is skippableYes. That is the half a person is for
False positivesCommon, and yours to triageNone reaches you. Every finding is reproduced before it is written up
OutputA ranked list of known weaknessesThe route in, what it reached, and the fix at the layer it belongs
On its own it tells youYour patch and configuration positionYour exposure on the paths tested

What you get

A report your auditor accepts and your engineers can act on

Your deliverable
  • An executive summary written for a board, not a scoring rubric
  • Every finding reproduced: the request or command, the result, and the steps to repeat it
  • Findings ranked by what they reach, not by a generic severity number
  • The remediation written for the team that owns that layer
  • A named CREST-certified operator behind the work, and a signed scope
  • A free retest of every fixed finding at 60 days
  • Under your own brand if you are reselling, with your logo on every page

Before you ask

VAPT, answered

What does VAPT stand for?

Vulnerability Assessment and Penetration Testing. It describes a single engagement with two halves: a broad assessment that enumerates what is known-vulnerable across the agreed estate, then a penetration test in which a person proves which of those weaknesses can actually be used and what they reach. The term is used most often in procurement and in supplier questionnaires, which is why it tends to appear in a scope document rather than in a tester’s own vocabulary.

Is VAPT the same as a penetration test?

No. A penetration test is one half of it. The assessment half gives you breadth across the whole estate, which a test on its own does not, because a test follows the paths that lead somewhere and will walk past a patch gap sitting in a corner nobody attacked. The test half gives you proof, which an assessment on its own cannot, because a scanner reports what is known-vulnerable and has no way of knowing which entries a person could chain into access.

Does VAPT satisfy Cyber Essentials Plus or PCI DSS?

They ask for different things and it is worth being precise. Cyber Essentials Plus requires an independent technical verification against a defined set of controls, carried out by a certified assessor, and is narrower than a VAPT engagement. PCI DSS requires both quarterly vulnerability scanning and annual penetration testing, which maps closely onto the two halves. A VAPT engagement will usually produce the evidence both frameworks want, but the scope has to be written against the framework rather than assumed to cover it.

How much does VAPT cost in the UK?

Price follows scope: the number of live hosts, the number of applications and user roles, whether internal testing is included, and whether it is a first engagement or a repeat. A small estate with one application typically runs two weeks. We quote a fixed price against a written scope rather than a day rate, so the number does not move once testing starts, and the retest at 60 days is included rather than billed as a second engagement.

How often should VAPT be repeated?

Annually as a floor, and after any material change: a new application, a migration, a merger, a significant change to who can reach what. The gap between annual tests is where most exposure accumulates, which is why the assessment half is worth running more frequently than the test half. Continuous testing covers that gap if the estate changes often.

Rather talk it through?

Book a 30-minute scoping call with an operator. You leave with a scope and a fixed price.

A security lead in a London office at dusk.

Find out which of your weaknesses someone can actually use.