Eight productised service lines � three delivery tiers � a standardised deliverable stack aligned to CHECK, CREST, ISO 27001, and Cyber Essentials. Board-ready reporting. Transparent pricing. Free retest included.
Eight productised service lines � each with three delivery tiers and a standardised deliverable stack. Every engagement includes an executive summary, technical report, remediation guide, ISO 27001 risk register, free retest, attestation letter, live debrief, and compliance mapping to CHECK / ISO 27001 / Cyber Essentials.
Manual and automated security assessment of web applications, portals, and SaaS platforms. Conducted in accordance with OWASP Testing Guide v4.2 and CREST methodology. Covers authentication, authorisation, input validation, business logic, and session management.
Network-level security assessment covering external perimeter, internal network segmentation, Active Directory, and on-premise servers. Aligned to NIST SP 800-115 and CREST methodology. Delivered in black, grey, or white box configuration.
Configuration review and active penetration testing of AWS, Azure, and GCP environments. Combines CIS Benchmark automation with targeted manual exploitation of IAM, storage, compute, and containerisation layers.
Security assessment of iOS and Android applications using static analysis, dynamic instrumentation, and network traffic interception. Follows OWASP MASVS and Mobile Top 10. Available in black, grey, and white box configurations.
Targeted assessment of REST, GraphQL, SOAP, and gRPC APIs. Covers BOLA/IDOR, mass assignment, excessive data exposure, injection, and authentication weaknesses. Aligned to OWASP API Security Top 10.
Human-layer security testing measuring staff susceptibility to phishing, vishing, and pretexting. All campaigns conducted under strict ethical and legal boundaries with full written client authorisation. Delivers measurable baseline metrics to justify security awareness investment.
Adversary simulation engagements that test detection and response capabilities across people, process, and technology. Conducted over an extended period using realistic threat actor TTPs mapped to MITRE ATT&CK. Recommended for organisations with an established security function and SOC capability.
On-site assessment of Wi-Fi infrastructure, rogue access point detection, and wireless client-side attacks. Covers corporate, guest, and IoT segments. Aligned to ISO 27001 Annex A physical and network security controls.
Select a service to compare Essentials, Professional, and Advanced side by side. All tiers include the full universal deliverable stack.
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 3�5 days | 5�8 days | 8�12 days |
| Testing approach | Black box | Grey box | Grey / white box |
| User roles in scope | Up to 5 | Up to 10 | Unlimited |
| OWASP Top 10 coverage | Full | Full | Full |
| Business logic testing | � | Included | Included |
| OAuth / SSO / MFA bypass | � | Included | Included |
| Source code�assisted review | � | � | Included |
| Chained attack scenarios | � | � | Included |
| Architecture & threat model review | � | � | Included |
| Indicative price range | �3,600 � �6,000 | �7,500 � �12,000 | �16,000 � �24,000 |
| Ideal for | Cyber Essentials Plus | ISO 27001 audit | Pre-launch / regulated |
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 3�5 days | 8�12 days | 12�20 days |
| Scope | External only | Internal + external | Full estate |
| IP range | Up to /24 | Up to /16 | Unlimited |
| CVE exploitation | Included | Included | Included |
| Active Directory attacks | � | Included | Included |
| Lateral movement simulation | � | Included | Included |
| Domain compromise simulation | � | � | Included |
| OT / SCADA boundary testing | � | � | Optional |
| Indicative price range | �3,600 � �6,000 | �12,800 � �19,200 | �24,000 � �40,000 |
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 3�5 days | 5�8 days | 8�12 days |
| Platforms | Single (AWS/Azure/GCP) | Single + active testing | Multi-cloud |
| CIS Benchmark scan | Included | Included | Included |
| IAM privilege escalation | Review only | Active exploitation | Active exploitation |
| Kubernetes / container testing | � | Basic | Full K8s assessment |
| CI/CD pipeline review | � | � | Included |
| Indicative price range | �3,600 � �6,000 | �7,500 � �12,000 | �16,000 � �24,000 |
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 3�5 days | 5�8 days | 7�10 days |
| Platforms | iOS or Android | iOS + Android | Both + API backend |
| Static analysis | Included | Included | Included |
| Frida instrumentation | � | Included | Included |
| SSL pinning bypass | � | Included | Included |
| Binary reverse engineering | � | � | Included |
| Indicative price range | �3,600 � �6,000 | �7,500 � �12,000 | �12,600 � �18,000 |
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 2�4 days | 4�6 days | 6�10 days |
| Endpoint volume | Up to 50 | Up to 150 | Unlimited |
| OWASP API Top 10 | Full | Full | Full |
| GraphQL deep testing | Basic | Full injection + introspection | Full |
| gRPC / Protobuf | � | � | Included |
| Indicative price range | �2,400 � �4,800 | �6,000 � �9,000 | �10,800 � �18,000 |
| Feature / capability | Professional | Advanced | |
|---|---|---|---|
| Duration | 10�15 days | 20�30 days | |
| Initial access method | Assumed breach | Full kill chain | |
| MITRE ATT&CK mapping | Included | Included | |
| C2 infrastructure | Standard | Custom built | |
| Physical access testing | � | Optional | |
| CBEST / TIBER-EU | � | Optional alignment | |
| Indicative price range | �22,000 � �33,000 | �44,000 � �72,000 | |
| Feature / capability | Essentials | Professional | Advanced |
|---|---|---|---|
| Duration | 1�2 days | 2�3 days | 3�5 days |
| Sites | Single site | Multi-segment | Multi-site + IoT |
| Rogue AP detection | Included | Included | Included |
| EAP / 802.1X attacks | � | Included | Included |
| IoT / Bluetooth / Zigbee | � | � | Included |
| Indicative price range | �1,200 � �2,400 | �3,000 � �4,500 | �5,400 � �9,000 |
A specialist offensive security practice delivering penetration testing, red team operations, and security assurance across the UK. Our consultants hold industry-leading certifications and operate under a rigorous delivery framework aligned to CHECK, CREST, and internationally recognised security standards.
Every engagement is delivered by CREST-certified or CHECK-qualified testers. No juniors running scans unsupervised � you get senior practitioners with direct accountability for every finding.
Our reports are written for two audiences simultaneously: a technical finding for your engineers and a risk-rated executive summary that board members can act on without translation.
Every engagement includes a free retest of all Critical and High severity findings within 30 days. We don't close an engagement until your most serious vulnerabilities are confirmed remediated.
Standard report turnaround is 72 hours from test completion. Draft findings are shared within 24 hours for time-sensitive engagements and compliance deadlines.
Every report maps findings to CHECK, ISO 27001 Annex A, and Cyber Essentials controls � reducing your audit preparation burden significantly and satisfying most certification body requirements.
We operate under a formal responsible disclosure policy. All findings are treated as confidential. We hold �5M professional indemnity and �5M public liability insurance on every engagement.
No obligation. We'll discuss your requirements, recommend the right service and tier, and provide a formal proposal within 24 hours.
Online booking coming soon. In the meantime, email us at contact@strategicedgeconsulting.co.uk to request a call.
Answers to the questions we receive most from first-time buyers, compliance teams, and procurement departments evaluating security suppliers.
Answer a few targeted questions about your environment and requirements. We'll recommend the right tier and provide an indicative investment range � in under two minutes.
Select one or more. Multi-service engagements receive a bundled discount (7% for two services, 12% for three or more).