Penetration testing. CREST-aligned. Evidence-led.
Web, infrastructure, cloud, mobile and wireless tests scoped to your environment. Methodology drawn from OWASP, NIST and the CREST Defensible Penetration Test specification. Free scoping call.

What we mean by Penetration Testing
A penetration test is an authorised, manual attempt to find and demonstrate how an attacker could compromise a target system. Real exploitation, not just identification — that is what separates a test from a scan, and that is the bar PCI DSS, ISO 27001, and customer assurance teams expect when they ask for one.
Our methodology draws on three published references: OWASP Web Security Testing Guide v4.2 for application work, NIST SP 800-115 for technical testing structure, and the CREST Defensible Penetration Test specification (v5.2) for scoping, delivery and sign-off. Engagements are delivered directly by 1 Sequence Cyber Limited.
Key facts
- CREST DPT spec
- v5.2
- Engagement types
- 9
- PCI DSS requirement
- 11.4
- OWASP WSTG
- v4.2
How engagements run
Four high-level delivery modes. Each one is scoped, planned and reported the same way — the difference is what we are testing.
Application & API testing
Web applications, REST and GraphQL APIs, and thick-client applications, tested per OWASP Web Security Testing Guide v4.2 methodology.
Infrastructure testing
External and internal network testing per NIST SP 800-115. Discovery, exploitation, and post-exploitation against in-scope hosts.
Cloud configuration testing
AWS, Azure and GCP configuration review against published benchmarks, plus targeted exploitation of identified weaknesses.
Red-team scenario testing
Goal-driven engagements that combine social engineering, infrastructure access and lateral movement against an agreed objective.
Compliance contexts we cover
Most Penetration Testing is driven by a compliance requirement, an assurance ask, or an internal risk decision. We see all three. The methodology is the same; the audit trail differs.
PCI DSS 4.0.1
Requirement 11.4 mandates external and internal penetration testing at least annually and after any significant change. Our QSAC team writes the report your auditor will accept, because it is the same firm.
ISO 27001:2022
Annex A.8.29 (security testing in development and acceptance) and A.8.8 (management of technical vulnerabilities) both rely on Penetration Testing as evidence. Reports map cleanly into ISMS documentation.
UK GDPR
Article 32 requires “regular testing, assessing and evaluating the effectiveness of technical and organisational measures”. Annual testing of systems holding personal data is the practical baseline.
NIS-CAF
Operators of essential services use Penetration Testing as evidence under principle B4 (system security) and B5 (resilient networks and systems). See our NIS-CAF service for the wider programme view.
How a test runs
Five stages. The same flow whether the engagement is a single web app or a multi-week red-team scenario.
- 1
Scoping call
30 minutes, freeTargets, methodology, rules of engagement, and any constraints. Output is a written scope draft we both work from.
- 2
Authorisation & test plan
1 weekWritten test plan signed by both parties. Scoping criteria from the CREST Defensible Penetration Test specification (v5.2) applied — what is in scope, what is out, what is excluded.
- 3
Test execution
1–3 weeks (scope-dependent)Active testing per OWASP WSTG, NIST SP 800-115, and CREST DPT. Daily check-ins with your nominated point of contact. Immediate escalation on any critical-severity finding so you can react before report delivery.
- 4
Report & debrief
1 weekFull technical report, executive summary, evidence pack, and a debrief session with engineering and leadership. We walk findings end-to-end so the remediation path is clear.
- 5
Re-test
Within 30 days post-remediationRe-test scope agreed at engagement start. We re-validate remediated findings and update the report and Attestation Letter accordingly.
Engagement types
Nine specific test types we deliver. The right combination depends on what you need defended — and what your auditor, customer or board is asking for.
Why 1 Sequence Cyber
Aligned to the CREST DPT specification
CREST-published methodology applied to scoping, delivery, and sign-off. Engagements run against the CREST Defensible Penetration Test specification (v5.2). Indemnity is held at firm level.
Same firm that runs the audits
Findings hand off cleanly into PCI DSS Requirement 11.4 evidence packs because the assessor is in the same building. No translation step between testers and auditors — the defensibility argument is consistent.
Ready to scope a penetration test?
Tell us what you need tested and what is driving the requirement. We’ll come back with a fixed-fee proposal within 48 hours.
Back to all services.