A maintained scope
Your estate tracked rather than re-described every year. New assets are noticed, and an asset leaving the estate stops being tested.
Offensive Security
Most organisations test once a year, deploy four hundred times, and describe the result as their security posture. Continuous testing closes the gap between when something breaks and when anybody finds out.
The annual penetration test exists because it satisfies a requirement. It produces a PDF in March, the findings are fixed over six weeks, and for the remaining ten months nobody tests anything. In that time you ship hundreds of changes, add infrastructure, onboard suppliers and expose new endpoints. The report on file describes a system that no longer exists.
Continuous testing is not "the same test, more often" — running an identical scan twelve times produces eleven reports nobody reads. It is a subscription in which the scope is maintained rather than re-scoped: your estate is tracked, changes trigger testing, scheduled assessments run against the things that matter, and you can ask for an unscheduled one the week before a release without raising a new purchase order.
The part that changes how it feels day to day is delivery. Findings reach you as they are confirmed, not in a document three weeks later — so remediation starts on the day the weakness is found, while the engineer who wrote the code still remembers it.
Coverage
The testing, and the delivery machinery around it.
Your estate tracked rather than re-described every year. New assets are noticed, and an asset leaving the estate stops being tested.
On a cadence that matches the asset — a payment path is not tested on the same rhythm as a marketing site.
Ask for one. No new statement of work, no procurement cycle, no three-week lead time.
They appear in the portal as they are confirmed. You do not wait for the report to start fixing.
Every fix verified. A finding is closed when a retest proves it, not when somebody ticks a box.
Automation gives coverage; a person establishes what is real and what it is worth. Nothing reaches you unverified.
Each one lands on the clauses it affects across every framework you track — and flags any control you had marked as working that it just contradicted.
A public link, not a PDF, that reflects where remediation actually stands and updates as it moves.
Approach
Set the scope once, then it keeps going.
What is in, what is explicitly out, and written authorisation to test it. Nothing runs without that, and the authorisation is renewable rather than one-off.
A full first pass, so everything afterwards is measured against something real.
Scheduled assessments, change-triggered testing, and whatever you ask for in between. Findings arrive as they are confirmed.
Fixes verified as they land. The register is the record, and it is always current.
Point-in-time reports for auditors, boards and customers — generated from the live register rather than assembled by hand.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Always current, with severity, status, owner and the retest verdict on each item.
For an auditor, a board pack or a customer, generated from the register.
A shareable link that reflects where remediation stands, not where it stood the day it was issued.
Which of your framework controls each assessment touched, and which it contradicted.
The person who scopes it is the person who delivers it.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
A scanner produces candidates. This produces verified findings: a person establishes whether each candidate is real, whether it is reachable, and what it is worth in your environment. The scanning is the cheap part and we do plenty of it — what you are subscribing to is the judgement applied to the output, and the delivery machinery around it.
Generally yes, and often better than an annual test, because continuous testing produces dated evidence throughout the year rather than one artefact that ages. What matters to an assessor is scope, competence, and findings tracked to closure and retested — all of which this produces as a by-product. If your auditor has a specific format in mind, tell us during scoping.
When an assessment is running, confirmed findings appear in your portal as they are verified rather than being held back for the report. On a multi-day engagement that routinely means the first fix is deployed before the testing has finished.
Within your subscribed scope, yes. Charging for a retest creates an incentive we do not want: it makes closing a finding cost money, which is exactly backwards. A finding is closed when a retest proves it is closed.
Yes, on demand and as often as you like. The difference is that it is generated from a register that is always current rather than assembled at the end of an engagement — so the report and reality do not drift apart between the last day of testing and the day somebody reads it.
It goes into scope, gets authorised, and gets a baseline assessment. That is the point of a maintained scope rather than an annual one — the alternative is an application that is in production for eleven months before anybody tests it.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.