Website and web application testing
We test your website, customer portal or online shop for issues such as injection flaws, broken logins, weak session handling and exposed data, following the OWASP Top 10.
Cyber Security
Our ethical hackers test your websites, networks and premises the same way a real attacker would, then explain exactly what they found and how to fix it. Testing is carried out remotely across the UK or in person at your site.
What's included
We test your website, customer portal or online shop for issues such as injection flaws, broken logins, weak session handling and exposed data, following the OWASP Top 10.
Everything your business exposes to the internet, including firewalls, remote access, email servers and cloud services, is tested from an attacker's point of view.
On site or through a secure remote device, we show what someone could reach if they got inside your network, from file shares to admin accounts.
In-person testing of your premises. Can someone tailgate through a door, plug into a spare network port or walk out with a laptop? We find out, safely and with your written agreement.
Phishing campaigns, phone pretexting and reception visits that test how your team responds to a convincing approach.
We check your wireless networks for weak encryption, poor separation between guest and staff networks and rogue access points.
A configuration review of Microsoft 365, Azure or other cloud platforms against recommended security settings.
Once you have fixed the issues we found, we retest them so you have evidence that each one is resolved.
The detail
Most attacks combine more than one route. A phishing email gets a password, a weak website gives access to data, or an unlocked door lets someone plug in a device. Testing your website, network and premises together gives a realistic picture of your real risk, not just a list of technical issues.
Who it's for
Since moving to Blink Web's managed cyber services we finally feel confident that our systems are truly protected. The team explained everything clearly and we now sleep easier knowing someone is always watching over our business.
Questions
A penetration test, or pen test, is an authorised simulated attack on your systems. Our testers use the same tools and techniques as criminals to find vulnerabilities, then give you a report explaining the risk and how to fix each issue.
Yes, when it is properly authorised. Before any testing starts we agree the scope, dates and rules of engagement in writing and you sign an authorisation, so the work is carried out within the Computer Misuse Act.
We plan tests to avoid disruption, agree times that suit you and avoid anything that could take systems offline. Live websites can be tested out of hours if you prefer.
A short summary for directors and managers, followed by the technical detail for each finding, a risk rating and clear steps to fix it. We are happy to walk you through it on a call or in person.
At least once a year, and after any major change such as a new website, office move or new system going live.
Yes. Website, external network and cloud testing can be done remotely anywhere in the UK, and our testers travel for on-site internal and physical testing.
Works well with
Talk to a real person