Penetration Testing Company Birmingham

A CREST-accredited penetration testing company serving Birmingham, where you deal directly with the tester, not a sales team or a call centre.

A CREST-accredited penetration testing company serving Birmingham, where you deal directly with the tester, not a sales team or a call centre.

A penetration testing company you can actually talk to

Plenty of firms will sell you a test and hand you a report. We are different: with Solusec you deal directly with the senior tester doing the work, so you get straight answers before, during and after the engagement. That matters as much for a Birmingham startup as for an established firm.

CREST-accredited, and genuinely independent

Solusec holds CREST company accreditation and our lead tester is CREST registered as an individual, so you get both layers. We also hold CREST AI-Enabled Penetration Testing accreditation. And because we do not sell or implement the fixes, our testing stays independent.

What we test for Birmingham businesses

Web applications and APIs, internal and external networks, cloud and Microsoft 365 environments, and more. We also offer Cyber Essentials and IASME Cyber Assurance certification if you need the baseline as well as the test.

Fixed scope, fixed price, plain English

We scope on a quick call, agree a fixed price up front, and deliver a prioritised report anyone can act on. No jargon, no surprises.

Checking that an accreditation is what it appears to be

Company level CREST accreditation is the most useful single line on a supplier questionnaire, because somebody independent has already done the checking for you. A firm has its methodology, quality assurance, reporting, data handling and staff vetting examined, and signs up to a code of conduct. What it does not do is transfer to whoever puts the logo on a web page, and three things are regularly presented as company accreditation while being nothing of the sort.

  • An individual tester's certificate. Someone holding a CREST registered qualification, or OSCP, has proved their own competence, which is worth having. It says nothing about the company's reporting standards, quality assurance or data handling.
  • Accreditation held by a parent, a sister company or a delivery partner. The group holds it and the entity named on your contract does not. Ask for the registered name and company number of the accredited entity and check it against the proposal. If they differ, the accreditation is not covering your engagement.
  • Membership of an adjacent body. Trade associations, regional cyber clusters and supplier schemes are memberships, mostly paid for rather than assessed. So is "working towards" anything.

The check takes minutes. CREST publishes a directory of accredited companies, so look the supplier up yourself and confirm the service you are buying falls inside the scope they are accredited for. Solusec holds CREST accreditation at company level, is a CREST member company, and was among the first ten firms worldwide accredited by CREST for AI-Enabled Penetration Testing. Daly Whyte is separately CREST registered, so both layers apply to the same engagement. Our page on CREST and CHECK explains where the government scheme fits alongside it.

What a Birmingham procurement process tends to ask for

Professional and financial services firms in the city centre, and manufacturers sitting inside a larger customer's supply chain, commonly buy through a formal process: a supplier questionnaire, an approved supplier list, sometimes a portal that will not let you proceed until every field has a document attached. The delay is nearly always a missing certificate rather than a disagreement about the work.

Documents a supplier is commonly asked for, and what each one is actually for
DocumentWhy it is asked for
Professional indemnity insurance certificateCovers the advice and the work itself. Your customer's contract may set a minimum level you have to pass on.
Public liability insurance certificateCovers injury or damage if anyone attends your premises, so it matters for a site visit even when the work is mostly remote.
Accreditation certificate in the contracting company's nameSo the assurance and the contract belong to the same legal entity.
Authorisation and rules of engagementSigned before testing begins by somebody with authority over the systems. It is what makes the engagement lawful.
Data handling termsA report is a list of your weaknesses, so procurement will ask where it is held and who can see it.

Ask for the insurance certificates themselves, with cover levels and renewal dates on them, rather than a sentence in a proposal.

The proposal deserves reading closely, because vagueness there becomes an argument later. It should state the number of days, the systems in scope by name rather than "your systems", the testing window, what you get at the end, and who signs the authorisation. Named systems are also what let you compare two quotes honestly, since a cheaper proposal is usually a smaller one. Scope drives the figure, as our page on what a penetration test costs explains.

When this has been handed to you and security is not your job

Across the wider conurbation the person buying a test is often an operations or IT manager handed the requirement by a customer, with no security background and no intention of acquiring one. That is a perfectly good position to buy from, because buying a test well is a procurement skill rather than a technical one. Two things are worth doing first: write down the systems you think are in scope and who owns each one, then find out who can sign for testing of them, particularly where a machine supplier or group IT owns part of the estate.

That is enough to hold a scoping call as an equal. You should not be asked to specify a methodology, and a supplier who needs you to translate the requirement for them is the wrong supplier. The report comes back prioritised and in plain English, the fixes go to whoever runs each system, and the free retest gives you a second document confirming the issues are closed, which is usually what your customer wanted. Our notes on choosing a provider cover the rest.

Common questions

Are you a local pen testing company for Birmingham?

We serve Birmingham and the surrounding area. Pen test, pentest and penetration testing all mean the same thing, and we work remotely first with onsite where it helps.

What makes you different from a big testing firm?

You deal directly with the senior tester, not an account manager. Senior-led, CREST-accredited, and independent of the fixes.

Do you also do Cyber Essentials?

Yes. We are a Cyber Essentials and IASME Certification Body, so we can handle certification as well as testing.

Penetration testing for Birmingham organisations

Testing requirements in Birmingham usually arrive through a client or framework requirement, for the professional firms, and a flow-down clause from a larger customer for the manufacturers. Given a city centre dominated by professional, legal and financial services sitting on top of a metals, castings and component manufacturing base spread across the wider conurbation, the scope is most often a web application, an external infrastructure range, or both together where a customer has asked for evidence covering everything they can see.

The day count is driven mostly by how many user roles an application has and how much genuinely distinct functionality sits behind them, not by page count. We scope on a call rather than through a form, and the quote is fixed for the scope agreed. Birmingham is forty minutes from our office, so on-site work here is routine rather than a special arrangement.

Where a Birmingham requirement names CREST, check the provider holds accreditation at company level rather than relying on an individual certification: ours is verifiable on the CREST marketplace. See what a penetration test costs for ranges by test type.

Related

How do I check a penetration testing company really holds CREST accreditation?

Look the company up in the CREST directory of accredited companies yourself rather than relying on a logo or a certificate sent to you. Check that the registered company name matches the entity named on your proposal, because group companies and delivery partners are often different legal entities. Also confirm that the service you are buying sits inside the scope they are accredited for, since accreditation is granted per service area.

Is a tester holding a CREST qualification the same as the company being accredited?

No, and the difference matters when procurement asks. An individual qualification proves that person has been examined on their technical competence. Company accreditation means the firm has had its methodology, quality assurance, reporting, data handling and staff vetting assessed and is bound by a code of conduct. You want both, and with Solusec you get both on the same engagement.

What insurance should a penetration testing supplier have?

Procurement will normally ask for professional indemnity, which covers the work and the advice, and public liability, which covers injury or damage if anyone attends your site. Ask for the certificates with cover levels and renewal dates on them rather than a statement in a proposal, and check whether your own customer contract sets a minimum you need to pass down.

What should a penetration testing proposal actually specify?

The number of days, the systems in scope named individually rather than described as your systems or your infrastructure, the testing window, what you receive at the end, whether a retest is included, and who signs the authorisation and rules of engagement. Anything less makes two quotes impossible to compare, because a lower figure is usually a smaller scope rather than better value.

Our customer has asked for a test and nobody here knows anything about security. Where do we start?

Get the exact wording of the requirement from your customer, list the systems you think are involved and who owns each one internally, and find out who has authority to sign for testing where a supplier or group IT function owns part of the estate. That is enough for a scoping call. You should not be expected to specify how the testing is done.

Need a pen test? Let’s talk.

CREST-accredited, senior-led, scoped to your systems and budget.