Penetration Testing

Penetration testing. CREST-aligned. Evidence-led.

Web, infrastructure, cloud, mobile and wireless tests scoped to your environment. Methodology drawn from OWASP, NIST and the CREST Defensible Penetration Test specification. Free scoping call.

A laptop displaying abstract security visualisations on a dark desk with cable and notebook, illustrating manual application security testing

What we mean by Penetration Testing

A penetration test is an authorised, manual attempt to find and demonstrate how an attacker could compromise a target system. Real exploitation, not just identification — that is what separates a test from a scan, and that is the bar PCI DSS, ISO 27001, and customer assurance teams expect when they ask for one.

Our methodology draws on three published references: OWASP Web Security Testing Guide v4.2 for application work, NIST SP 800-115 for technical testing structure, and the CREST Defensible Penetration Test specification (v5.2) for scoping, delivery and sign-off. Engagements are delivered directly by 1 Sequence Cyber Limited.

Key facts

CREST DPT spec
v5.2
Engagement types
9
PCI DSS requirement
11.4
OWASP WSTG
v4.2

How engagements run

Four high-level delivery modes. Each one is scoped, planned and reported the same way — the difference is what we are testing.

Application & API testing

Web applications, REST and GraphQL APIs, and thick-client applications, tested per OWASP Web Security Testing Guide v4.2 methodology.

Infrastructure testing

External and internal network testing per NIST SP 800-115. Discovery, exploitation, and post-exploitation against in-scope hosts.

Cloud configuration testing

AWS, Azure and GCP configuration review against published benchmarks, plus targeted exploitation of identified weaknesses.

Red-team scenario testing

Goal-driven engagements that combine social engineering, infrastructure access and lateral movement against an agreed objective.

Compliance contexts we cover

Most Penetration Testing is driven by a compliance requirement, an assurance ask, or an internal risk decision. We see all three. The methodology is the same; the audit trail differs.

PCI DSS 4.0.1

Requirement 11.4 mandates external and internal penetration testing at least annually and after any significant change. Our QSAC team writes the report your auditor will accept, because it is the same firm.

ISO 27001:2022

Annex A.8.29 (security testing in development and acceptance) and A.8.8 (management of technical vulnerabilities) both rely on Penetration Testing as evidence. Reports map cleanly into ISMS documentation.

UK GDPR

Article 32 requires “regular testing, assessing and evaluating the effectiveness of technical and organisational measures”. Annual testing of systems holding personal data is the practical baseline.

NIS-CAF

Operators of essential services use Penetration Testing as evidence under principle B4 (system security) and B5 (resilient networks and systems). See our NIS-CAF service for the wider programme view.

How a test runs

Five stages. The same flow whether the engagement is a single web app or a multi-week red-team scenario.

  1. 1

    Scoping call

    30 minutes, free

    Targets, methodology, rules of engagement, and any constraints. Output is a written scope draft we both work from.

  2. 2

    Authorisation & test plan

    1 week

    Written test plan signed by both parties. Scoping criteria from the CREST Defensible Penetration Test specification (v5.2) applied — what is in scope, what is out, what is excluded.

  3. 3

    Test execution

    1–3 weeks (scope-dependent)

    Active testing per OWASP WSTG, NIST SP 800-115, and CREST DPT. Daily check-ins with your nominated point of contact. Immediate escalation on any critical-severity finding so you can react before report delivery.

  4. 4

    Report & debrief

    1 week

    Full technical report, executive summary, evidence pack, and a debrief session with engineering and leadership. We walk findings end-to-end so the remediation path is clear.

  5. 5

    Re-test

    Within 30 days post-remediation

    Re-test scope agreed at engagement start. We re-validate remediated findings and update the report and Attestation Letter accordingly.

Engagement types

Nine specific test types we deliver. The right combination depends on what you need defended — and what your auditor, customer or board is asking for.

Why 1 Sequence Cyber

Aligned to the CREST DPT specification

CREST-published methodology applied to scoping, delivery, and sign-off. Engagements run against the CREST Defensible Penetration Test specification (v5.2). Indemnity is held at firm level.

Same firm that runs the audits

Findings hand off cleanly into PCI DSS Requirement 11.4 evidence packs because the assessor is in the same building. No translation step between testers and auditors — the defensibility argument is consistent.

Frequently asked questions

Related services: PCI DSS · incident response · ASV scanning.

Ready to scope a penetration test?

Tell us what you need tested and what is driving the requirement. We’ll come back with a fixed-fee proposal within 48 hours.

Back to all services.