- Base
- Albrighton, Shropshire, UK
- Remote delivery
- UK & international
- Working language
- English
- Accreditation
- CREST — internationally recognised
Remote by default
Web application, API, cloud and external infrastructure testing is delivered remotely. There is no technical reason for a tester to be in the room, and clients who insist on it are usually paying for reassurance rather than results.
That means a client in Helsinki gets the same engagement as one in Wolverhampton: same tester, same methodology, same report, same direct line during testing. Every territory we work in sits within an hour of UK time, so there is no handover gap and no overnight lag on questions during testing.
Onsite work
Internal infrastructure testing, tabletop exercises and hands-on incident response benefit from being in the building. Within the West Midlands and Shropshire that carries no travel charge. Elsewhere in the UK and internationally we quote travel transparently as a separate line item rather than burying it in an inflated day rate.
For international internal testing, shipping a preconfigured device that connects back to us frequently works as well as attending and costs considerably less. We will tell you when that is the better option.
United Kingdom
Clients across England, Scotland, Wales and Northern Ireland. CREST accreditation is widely specified in UK public sector procurement and by cyber insurance underwriters, and ours is independently verifiable on the CREST marketplace.
Ireland
Substantial technology, pharmaceutical and financial services presence, much of it operating to group security standards set elsewhere. NIS2 has significantly raised assurance expectations for in-scope entities and their suppliers, and that pressure passes down to suppliers who are not themselves in scope. English-language delivery with no adjustment required.
Gibraltar and Malta
Both jurisdictions concentrate regulated gaming, financial services and insurance, and both operate in English with legal systems familiar to a UK provider. Licensees in these sectors typically face specific, recurring technical assurance obligations from their regulators, and independent penetration testing is a routine part of demonstrating them.
We would encourage you to send us the exact regulatory wording you are working to. Requirements differ meaningfully between licence classes, and the useful first step is establishing precisely what is being asked for rather than assuming.
Spain
We work with English-speaking businesses in Spain, particularly the professional services, property, hospitality and technology companies serving international communities along the coast and in the islands. Reports and all communication are in English; if you need Spanish-language documentation for a regulator, tell us at scoping so we can be clear about what we can and cannot provide.
What we will not pretend
We do not have local offices in these territories, and we will not claim otherwise. What we offer is a CREST accredited UK provider delivering in English, remotely, at UK rates, with travel quoted honestly when onsite work is genuinely needed. For a great many organisations that is a better proposition than a local firm without accreditation or an international consultancy with a minimum engagement size. For some it will not be, and we will say so.
Common questions
Does UK CREST accreditation mean anything outside the UK?
CREST is an international body with member companies across Europe, Asia, Australia and the Americas, and its accreditation is recognised well beyond the UK. Whether it satisfies a specific regulator or contract is a separate question — send us the requirement and we will tell you honestly whether we meet it.
What about data protection when testing across borders?
Testing frequently involves access to systems containing personal data. We work under a data processing agreement, keep evidence to the minimum necessary, store it encrypted in the UK, and delete it on an agreed schedule. Where you need specific contractual terms or transfer mechanisms, raise it at scoping rather than after.
Do you deliver in languages other than English?
No. All testing, communication and reporting is in English. Across the territories we cover this is rarely an obstacle, but if you need a report in another language for a regulator or board, you should factor in your own translation and we will format the document to make that straightforward.
Are your rates different internationally?
No. Day rates are the same wherever you are. The only variable is travel, quoted separately and only where onsite work is genuinely required.
Can you attend onsite in these territories?
Yes, where it is genuinely warranted — internal testing, incident response, tabletop exercises. Travel and accommodation are quoted transparently. We will also tell you when shipping a device or working remotely would achieve the same outcome for less, because that is often the case.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day