Penetration Testing Company Manchester
A CREST-accredited penetration testing company serving Manchester, where you deal directly with the tester, not a sales team or a call centre.
A CREST-accredited penetration testing company serving Manchester, where you deal directly with the tester, not a sales team or a call centre.
A penetration testing company you can actually talk to
Plenty of firms will sell you a test and hand you a report. We are different: with Solusec you deal directly with the senior tester doing the work, so you get straight answers before, during and after the engagement. That matters as much for a Manchester startup as for an established firm.
CREST-accredited, and genuinely independent
Solusec holds CREST company accreditation and our lead tester is CREST registered as an individual, so you get both layers. We also hold CREST AI-Enabled Penetration Testing accreditation. And because we do not sell or implement the fixes, our testing stays independent.
What we test for Manchester businesses
Web applications and APIs, internal and external networks, cloud and Microsoft 365 environments, and more. We also offer Cyber Essentials and IASME Cyber Assurance certification if you need the baseline as well as the test.
Fixed scope, fixed price, plain English
We scope on a quick call, agree a fixed price up front, and deliver a prioritised report anyone can act on. No jargon, no surprises.
Who sells the work, and who actually performs it
There are a lot of firms in and around Manchester who will sell you a penetration test, and their websites say much the same things. A good number do not employ the person who would carry it out. Managed service providers, IT support companies and general consultancies commonly resell testing, passing the work to a testing firm. That is not automatically a problem, and we use vetted senior specialists ourselves at times, but you should know before you sign. Five questions tell you which sort of firm you are dealing with.
- Who will perform this test, by name, and what qualifications do they hold?
- Are they employed by the company on this proposal, or subcontracted?
- If something breaks mid-test, do I speak to the tester or to an account manager?
- Who writes the report: the tester, or somebody working from their notes?
- Can I speak to them before I commit?
The answers go vague at the name. "One of our senior consultants" and "we will assign the right resource" both mean the person has not been chosen, and may not be until after you have paid. Our answer does not change between engagements: Daly Whyte does the work, CREST registered as an individual, holding OSCP, CRT and PraCSP, and the tester writes the report.
What the word CREST in a proposal does and does not commit anyone to
Almost every proposal mentions CREST somewhere, which makes the word nearly useless for telling suppliers apart unless you read what it is attached to. Company accreditation is meaningful: methodology, quality assurance, reporting and data handling assessed by somebody other than the supplier, plus a complaints route you can use if the work is poor. What it does not promise on its own is any of the following.
- That your test will be performed by a CREST registered individual. An accredited company can still put an unregistered junior on it unless the proposal says otherwise.
- That this service sits inside the accredited scope, which is granted per service area rather than across everything a firm sells.
- That the accreditation belongs to the company on your contract rather than a parent.
The wording to look for is specific. "We are CREST accredited" is a statement about the company. "This engagement will be delivered under our CREST company accreditation by a named CREST registered tester" is a commitment about your test. Ask for the second. The difference between CREST and CHECK matters if a public sector customer is asking.
Ask to see a redacted report before you buy
The report is the entire deliverable, so it is odd how rarely buyers ask to see one first. Any serious supplier keeps a redacted sample and will send it without fuss, and reluctance is an answer in itself. You are looking for the difference between testing and tooling. Reformatted scanner output has a recognisable shape: findings in severity order as a tool produced them, a score with no explanation of what it means for you, remediation text saying little more than upgrade to the latest version, and informational entries padding the count. A real report states the scope, dates and method, gives each finding reproduction steps and evidence, explains what an attacker could do with it in your business, and includes what no scanner finds, such as one customer account reaching another's data.
Ask about the retest in the same breath, because practice varies. Some include one retest of the original findings within a window, some charge a day rate, some only offer a full repeat engagement. Ours is free once you have fixed the issues, and it produces the second document a customer or investor usually wanted.
Buying testing more than once
Most first tests here are prompted by somebody else. The mistake is buying a one-off certificate when you will be in the same position within a year, usually with more customers asking, so choose a supplier you would be happy to return to.
- Continuity is worth more than it looks. A tester who saw last year's estate spends day one testing rather than learning it.
- Ask the lead time for a repeat engagement. Ours is two to three weeks from agreed scope, often within a week at short notice, with no premium for the hurry.
- Keep reports and retest confirmations together, so the next questionnaire is a filing exercise.
The warning signs are consistent. A quote arriving without a scoping conversation means the figure was guessed, and it will be revised later or the scope quietly cut to fit. A price for "a penetration test" with no day count and no named systems cannot be compared with anything, and a supplier who will not name the tester has not picked one. See also choosing a provider.
Common questions
Are you a local pen testing company for Manchester?
We serve Manchester and the surrounding area. Pen test, pentest and penetration testing all mean the same thing, and we work remotely first with onsite where it helps.
What makes you different from a big testing firm?
You deal directly with the senior tester, not an account manager. Senior-led, CREST-accredited, and independent of the fixes.
Do you also do Cyber Essentials?
Yes. We are a Cyber Essentials and IASME Certification Body, so we can handle certification as well as testing.
Penetration testing for Manchester organisations
Testing requirements in Manchester usually arrive through enterprise client security questionnaires, and investor or acquirer due diligence. Given the largest digital, software and professional services concentration outside London, alongside substantial manufacturing and logistics, the scope is most often a web application, an external infrastructure range, or both together where a customer has asked for evidence covering everything they can see.
The day count is driven mostly by how many user roles an application has and how much genuinely distinct functionality sits behind them, not by page count. We scope on a call rather than through a form, and the quote is fixed for the scope agreed. Manchester engagements usually run remotely, with an on-site day only where the estate needs it.
Where a Manchester requirement names CREST, check the provider holds accreditation at company level rather than relying on an individual certification: ours is verifiable on the CREST marketplace. See what a penetration test costs for ranges by test type.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
How do I tell a penetration testing company from an IT company reselling testing?
Ask who will perform the test by name, whether they are employed or subcontracted, who writes the report, and whether you can speak to them before you sign. A reseller becomes vague at the name and offers phrases like one of our senior consultants. Subcontracting is not automatically bad, but it should be disclosed before you commit rather than discovered afterwards.
Everyone says they are CREST accredited. What should I ask beyond that?
Ask for three things in writing: that the accreditation belongs to the company named on your contract rather than a parent or partner, that the service you are buying sits inside their accredited scope, and that your test will be performed by a named CREST registered tester. Company accreditation on its own does not guarantee who is assigned to your engagement.
Can I see an example report before I commit?
Yes, and you should ask every supplier you are considering. Any serious provider keeps a redacted sample for this purpose. Look for reproduction steps, evidence, findings explained in terms of what an attacker could do in your business, and issues that no automated tool would have produced. Severity-ordered tool output with generic remediation text is a scanner run rather than a test.
Is a retest included, or charged separately?
It varies enough between suppliers that you should ask before signing rather than assume. Some include one retest of the original findings within a set window, some charge at a day rate, and some only offer a full repeat engagement. With Solusec a retest is free once you have fixed the issues, and it gives you a second document confirming the findings are closed.
We got a quote without any scoping call. Is that a problem?
It is one of the clearest warning signs. A figure produced without a conversation about your systems is a guess, and it usually gets revised upwards later or the scope gets quietly trimmed to fit the number. Expect a scoping conversation first, and expect the resulting proposal to name the systems and the number of days.
Need a pen test? Let’s talk.
CREST-accredited, senior-led, scoped to your systems and budget.