Offer First month of web hosting for £1 with code WELCOME
Blink Web

Cyber Security

Find the weak spots before an attacker does

Our ethical hackers test your websites, networks and premises the same way a real attacker would, then explain exactly what they found and how to fix it. Testing is carried out remotely across the UK or in person at your site.

  • Website and web app testing
  • External and internal networks
  • On-site physical testing
  • Plain English reports

What's included

What we can test

Website and web application testing

We test your website, customer portal or online shop for issues such as injection flaws, broken logins, weak session handling and exposed data, following the OWASP Top 10.

External network testing

Everything your business exposes to the internet, including firewalls, remote access, email servers and cloud services, is tested from an attacker's point of view.

Internal network testing

On site or through a secure remote device, we show what someone could reach if they got inside your network, from file shares to admin accounts.

Physical security testing

In-person testing of your premises. Can someone tailgate through a door, plug into a spare network port or walk out with a laptop? We find out, safely and with your written agreement.

Social engineering

Phishing campaigns, phone pretexting and reception visits that test how your team responds to a convincing approach.

Wi-Fi testing

We check your wireless networks for weak encryption, poor separation between guest and staff networks and rogue access points.

Cloud and Microsoft 365 review

A configuration review of Microsoft 365, Azure or other cloud platforms against recommended security settings.

Retesting

Once you have fixed the issues we found, we retest them so you have evidence that each one is resolved.

The detail

How a penetration test works

  1. Scoping call. We agree what is in scope (websites, IP addresses, buildings or staff) and the type of test that suits your goals.
  2. Authorisation. You sign a rules of engagement document so everyone knows exactly what will be tested and when.
  3. Testing. Our testers carry out the work remotely or on site, keeping you updated and stopping immediately if anything critical is found.
  4. Report and debrief. You receive a clear report with prioritised findings and practical fixes, and we talk you through it.
  5. Retest. Once you have made the fixes, we check them again.

Website and in-person testing together

Most attacks combine more than one route. A phishing email gets a password, a weak website gives access to data, or an unlocked door lets someone plug in a device. Testing your website, network and premises together gives a realistic picture of your real risk, not just a list of technical issues.

Who it's for

Built for teams like yours

  • Small and medium businesses
  • E-commerce and retail
  • Schools and academies
  • Healthcare and care providers
  • Professional services
  • Organisations preparing for ISO 27001 or supplier security checks

Since moving to Blink Web's managed cyber services we finally feel confident that our systems are truly protected. The team explained everything clearly and we now sleep easier knowing someone is always watching over our business.

Gavin JManaged cyber customer

Questions

Common questions

What is a penetration test?

A penetration test, or pen test, is an authorised simulated attack on your systems. Our testers use the same tools and techniques as criminals to find vulnerabilities, then give you a report explaining the risk and how to fix each issue.

Is penetration testing legal?

Yes, when it is properly authorised. Before any testing starts we agree the scope, dates and rules of engagement in writing and you sign an authorisation, so the work is carried out within the Computer Misuse Act.

Will testing disrupt my business?

We plan tests to avoid disruption, agree times that suit you and avoid anything that could take systems offline. Live websites can be tested out of hours if you prefer.

What does the report include?

A short summary for directors and managers, followed by the technical detail for each finding, a risk rating and clear steps to fix it. We are happy to walk you through it on a call or in person.

How often should we test?

At least once a year, and after any major change such as a new website, office move or new system going live.

Do you test outside Hampshire and London?

Yes. Website, external network and cloud testing can be done remotely anywhere in the UK, and our testers travel for on-site internal and physical testing.

Talk to a real person

Tell us what you need. We'll give you a straight answer.