School Website Penetration Testing

Web application penetration testing for school websites, parent portals, online payments and admissions forms.

Web application penetration testing for school websites, parent portals, online payments and admissions forms.

Your website is your most exposed system

A school website is public by design, and it often does far more than show information: parent logins, online payments, admissions and enquiry forms, newsletters and document areas. Every one of those is a way in if it is not built and configured securely, and it is the first thing an opportunistic attacker will probe.

What we test

We test your website and its connected web applications the way an attacker would, covering the common, high-impact issues (the kind in the OWASP Top Ten): injection flaws, broken access controls, exposure of personal data, weak authentication on parent and staff logins, and insecure handling of payments and uploads.

Clear findings, plainly explained

You get a clear report of what we found, how serious each issue is, and what to do about it, written so your web provider or IT team can act on it straight away. We work with whoever built or hosts the site rather than around them.

Common questions

Do we need to involve our web provider?

It helps, but is not essential to start. We can test the live site and share findings with whoever maintains it, and we are happy to work alongside them on fixes.

Will testing take the site down?

No. We test carefully to avoid disruption, and we agree timing with you in advance.

Related

Independent assurance for your school.

A CREST-accredited test, scoped to your budget, explained in plain terms.