Call us now on 0161 209 5111, or email: securetest@nccgroup.com

Penetration Testing

We offer a range of Penetration Testing covering an array of real threats designed to identify all areas of vulnerability. Using the up-to-date techniques, technologies and information sources used by genuine hackers to mitigate the identified risks and improve security measures, our services involve far more than simply 'scanning' the network for weaknesses.

Our tests are performed 'hands-on' by experienced senior consultants utilising the same methods and tools as hackers in addition to developing their own and our 'effective responsible disclosure policy' results in major vulnerabilities being identified and resolved with vendors.

Key areas of expertise include:

  • Network security testing: We analyse the security of your networks, considering the potential for both an internal and external attack. Important for all organisations, it is essential for high profile or Internet businesses where breaches of customer confidentiality or fraud could result in bad publicity, loss of reputation and business
  • Remote access and remote worker security: We ensure your organisation is equipped to manage the security risks that arise from remote and home working. Issues such as laptop security, home and remote worker security, VPN security and access to remote servers are considered
  • Application security testing: We rigorously test your applications to ensure they are secure enough to cope with the transactions they are required to undertake (e.g. online banking and order processing)
  • Social engineering: We cover the 'human element' associated with risk and how real threats such as unauthorised physical entry into buildings, obtaining sensitive information, impersonation and deception can be addressed
  • Payment Card Industry Data Security Standard (PCI DSS): As a Qualified Security Assessor (QSA), our Approved Scanning Vendor team helps organisations who sell or take donations or payments by credit card to become and stay compliant with the PCI DSS, ensuring they do not risk fines or being permanently barred from the card acceptance programme in the event of a security breach.
  • Forensics (Incident Response & Investigation Services): If your systems have been attacked or if you require forensically sound investigation of suspected computer abuse our Computer Forensic Incident Response & Investigation Services deliver a professional service based on real technical expertise and investigation experience.

We also offer bespoke testing services to meet our clients' custom testing requirements. We can assist with a range of testing requirements, including functional testing, interoperability testing, acceptance testing, test process reviews and certification programmes . Utilising our experienced testing consultants, tools and scripts leaves clients free to get on with the day to day running and development of their business.