Pen Test Partners
Pen Test Partners is a UK-headquartered cybersecurity consulting firm delivering penetration testing, red teaming, incident response, OT/ICS, AI security testing, and compliance services. The NCSC CHECK, CREST, and PCI QSA accredited firm serves finance, healthcare, retail, and transport sectors from offices in the UK and US.
- Company typePrivate
- Founded2010
- HeadquartersBuckingham, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Pen Test Partners does
Pen Test Partners (PTP) is a UK-headquartered cybersecurity consulting firm founded in 2010 and structured as a limited liability partnership, with operating offices in Buckingham, UK and New York, US. The firm delivers professional security testing and advisory services across approximately thirty distinct offerings organised into four categories: Test and Simulate (penetration testing under NCSC CHECK, red teaming under CBEST/GBEST/STAR-FS/TIBER, purple teaming, attack surface management, PTaaS, AI testing, cloud, physical, OT/ICS/IIoT, and transport systems testing); Detect and Respond (incident response, DFIR, expert witness, dark web OSINT, MDR, compromise assessments); Improve and Protect (security architecture, SDLC, gap and maturity assessments, security training, virtual CISO, password auditing); and Comply (Cyber Essentials, PCI ROC Level 1, PCI SAQ, ISO/SOC 2 preparation).
The firm's core technology is human-delivered expert security testing supported by a content and tooling platform: a free technical blog, YouTube hack demonstrations, open-source tooling on GitHub (Rust extractors, Ghidra plugins), and an annual PTP Cyber Fest event. Revenue is generated through professional services billed on project or retainer basis, with PTaaS and ASM representing newer recurring-delivery formats. PTP holds a deep regulatory moat including NCSC CHECK, NCSC IR Standard, CREST accreditations (penetration testing, mobile, STAR-FS, intelligence-led, incident response, ASSURE), PCI QSA status, ISO 27001:2022, Cyber Essentials Plus, CSA STAR Level 1, and Crown Commercial Service supplier status.
Go-to-market is sales-led and content-led: direct enterprise engagement via website forms, phone lines in the UK and US, a 24/7 breach response hotline, supplemented by conference speaking at DEF CON, BSides, Steelcon, and Infosecurity Europe. The firm serves customers across four regulated verticals — finance, healthcare, retail/consumer, and transport/aviation — with sector partnerships through Aviation ISAC and Retail & Hospitality ISAC. The company has been carbon neutral since 2020 and operates a 30kW solar array at its UK headquarters.
Pen Test Partners firmographics
Firmographics- Name
- Pen Test Partners
- Legal name
- Pen Test Partners LLP
- Website
- https://pentestpartners.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Pen Test Partners is a UK-headquartered cybersecurity consulting firm delivering penetration testing, red teaming, incident response, OT/ICS, AI security testing, and compliance services. The NCSC CHECK, CREST, and PCI QSA accredited firm serves finance, healthcare, retail, and transport sectors from offices in the UK and US.
- Ownership category
- akta.pro rank
Pen Test Partners industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Other Scientific and Technical Consulting Services (541690), Computer Systems Design and Related Services (54151), Testing Laboratories and Services (54138)
- SIC
- Services-Engineering Services (8711), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where Pen Test Partners is headquartered
LocationHeadquarters
- HQ city
- Buckingham
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Pen Test Partners business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Professional Cybersecurity Services: Revenue generated from cybersecurity consulting, penetration testing, incident response, red teaming, security assessments, and related professional services. Services are delivered by certified consultants and billed on project or retainer basis.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Pen Test Partners product offering
Product offeringCore offering
Pen Test Partners is a UK-based cybersecurity consulting and testing firm that delivers professional services to enterprise clients across four areas: Test and Simulate (penetration testing, red/purple teaming, AI testing, cloud, physical, OT/ICS, transport security testing), Detect and Respond (incident response, digital forensics, expert witness, managed detection and response, compromise assessments), Improve and Protect (security architecture, secure SDLC, virtual CISO, security training, gap and maturity assessments), and Comply (PCI DSS, Cyber Essentials, ISO 27001 preparation). Services are delivered by CHECK-, CREST-, and PCI QSA-accredited consultants on a per-project or retainer basis, with a 24/7 Rapid Breach Response service for active incidents.
Product overview
Pen Test Partners is a cybersecurity consulting firm offering professional security testing and advisory services organized into four main categories: Test and Simulate (offensive security testing including penetration testing, red teaming, and attack surface management), Detect and Respond (incident response, digital forensics, and threat detection services), Improve and Protect (security architecture, secure development, and training), and Comply (regulatory compliance assessments for PCI DSS, Cyber Essentials, and other standards). The portfolio includes specialized services for AI security testing, OT/ICS environments, cloud platforms, and physical security. The company does not offer a software product but provides consulting-based services delivered by security professionals, with offerings such as PTaaS providing continuous testing and ASM providing ongoing attack surface monitoring as closest approximations to managed services.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing (CHECK) Ethical hacking and vulnerability assessment services delivered by NCSC CHECK-approved specialists to identify security weaknesses in systems, networks, and applications for regulated UK and enterprise clients.
- Pen Testing as a Service (PTaaS) On-demand penetration testing platform providing continuous security testing and real-time reporting for organizations requiring ongoing vulnerability assessment.
- Artificial Intelligence Testing Specialized security testing services focused on identifying vulnerabilities and weaknesses in AI systems, machine learning models, and AI-powered applications.
- Red Teaming (CBEST, GBEST, STAR-FS, TIBER) Intelligence-led cyber attack simulation services following CBEST, GBEST, STAR-FS, and TIBER regulatory frameworks to assess an organization's ability to detect and respond to sophisticated adversaries.
- Purple Teaming Combined offensive and defensive security testing that bridges red team attackers and blue team defenders to improve overall security posture.
- Attack Surface Assessment Comprehensive point-in-time analysis of an organization's external digital footprint to identify exposed assets, services, and potential entry points for attackers.
- Attack Surface Management (ASM) Ongoing monitoring and management of an organization's external attack surface to discover, prioritize, and remediate security exposures.
- Cloud Testing Services Security assessment services for AWS, Azure, and Google Cloud environments covering configuration review, identity management, and cloud-native vulnerabilities.
- Physical Security Testing Assessment of physical security controls including access systems, barriers, surveillance, and badge/cloning vulnerabilities to identify weaknesses in physical defenses.
- OT, ICS, IIoT Security Testing Security testing for operational technology, industrial control systems, and industrial IoT devices, covering protocols such as Modbus/TCP and addressing the patching and operational constraints of OT environments.
- Transport Systems Testing Specialized security testing for aviation, maritime, automotive, and rail transport systems to identify vulnerabilities in connected vehicles and transportation infrastructure.
- Incident Response Rapid breach response and incident management services including containment, investigation, evidence preservation, and recovery support for organizations experiencing cyber attacks.
- Incident Response Maturity Assessment Evaluation of an organization's incident response capabilities to identify gaps, improve processes, and enhance readiness for future security incidents.
- Digital Forensic Investigations Forensic analysis of digital evidence including thumbcache forensics, shellbags analysis, and artifact examination to reconstruct events and support legal proceedings.
- Digital Forensics Expert Witness Expert witness services providing forensic analysis and testimony for legal cases involving cybercrime, intellectual property theft, and regulatory investigations.
- Dark Web Annual OSINT Assessment Open-source intelligence gathering from dark web sources to identify exposed credentials, stolen data, and threats specific to the organization.
- Exposure and Identity Risk Assessment Assessment to identify exposed corporate identities, credentials, and personal information across the internet and dark web to mitigate identity-based risks.
- Managed Detection & Response Ongoing security monitoring, threat detection, and incident response services to identify and respond to cyber threats in real-time.
- Compromise Assessments and Forensic Sweep Proactive assessments to determine if an organization has been compromised, including comprehensive forensic sweeps of systems and networks.
- Rapid Breach Response 24/7 emergency incident response service providing immediate assistance for organizations experiencing active cyber breaches, with dedicated UK and US hotlines and email intake.
- Security Architecture Consulting services to design and review security architectures, ensuring networks, applications, and systems are built with security best practices.
- Secure Software Development (SDLC) Integration of security practices throughout the software development lifecycle, including threat modeling, code review, and security testing.
- Cloud Configuration and Best Practice Review and remediation of cloud infrastructure configurations to ensure compliance with security best practices and reduce cloud-specific risks.
- Cyber Security Gap Analysis Assessment comparing current security controls against frameworks and standards to identify gaps and prioritize remediation efforts.
- Cyber Security Maturity Assessment (CSMA) Comprehensive evaluation of an organization's security program maturity across people, processes, and technology dimensions.
- Security Training Security awareness and technical training programs including phishing awareness, secure coding, and incident response training for staff.
- Third-party Vendors Selection and Assurance Security assessment and due diligence services for evaluating third-party vendors and suppliers to manage supply chain security risks.
- Virtual CISO Fractional CISO services providing senior security leadership, strategy development, and board-level communication for organizations lacking full-time security leadership.
- Proactive Advanced Password Auditor (PAPA) Password security assessment service to evaluate password policies, detect weak credentials, and identify compromised passwords.
- Cyber Essentials and Cyber Essentials Plus UK government-backed certification scheme assessment and guidance for Cyber Essentials and Cyber Essentials Plus compliance.
- Formal Certification Preparation Preparation services for organizations pursuing formal security certifications including ISO 27001, SOC 2, and other industry standards.
- PCI ROC Level 1 Assessment Payment Card Industry Data Security Standard (PCI DSS) Report on Compliance assessments for Level 1 merchants and service providers, delivered by PCI QSA-accredited consultants.
- PCI SAQ Assessment Self-Assessment Questionnaire support for organizations pursuing PCI DSS compliance at lower transaction volumes.
- PCI Scoping Workshop Workshop to help organizations understand and define their PCI DSS scope, identifying all system components that handle cardholder data.
Quantifiable outcome
- Carbon neutral since 2020 with independently audited carbon footprint
- +1 more outcomes
Companies that use Pen Test Partners
Customer profileSegments5 records
Ideal customer profiles3 records
Pen Test Partners technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Pen Test Partners partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered minor and core.
- ShoosmithsminorShoosmiths, a law firm, sponsored PTP Cyber Fest 2026 and participated in the DFIR panel discussion on ransomware and breach crisis management alongside PTP and RANT Community.
- Harmonic AIminorHarmonic AI sponsored PTP Cyber Fest 2026 as part of the event's sponsor and partner lineup.
- Aviation ISACcoreAviation ISAC (Information Sharing and Analysis Center) partnered with PTP Cyber Fest 2026 and PTP actively participates in Aviation ISAC events including Q2 AvTech workshops. PTP provides cybersecurity expertise to the aviation sector.
- Retail and Hospitality ISACcoreRetail & Hospitality ISAC partnered with PTP Cyber Fest 2026. PTP provides security testing services to retail and hospitality organizations.
- RANT CommunitycoreRANT Community co-hosted the DFIR panel at PTP Cyber Fest 2026 and organizes RANT sessions and the Cyber House Party event during Infosecurity Europe week.
- University of BristolminorUniversity of Bristol was listed as a sponsor/partner for PTP Cyber Fest 2026.
- Carbon Footprint LtdminorCarbon Footprint Ltd conducts annual carbon footprint analysis for PTP and provides carbon neutral certification. PTP has been working with them for several years to measure and reduce carbon emissions.
- Verra (Verified Carbon Standard)minorPTP invests in carbon offsetting projects certified under Verra's Verified Carbon Standard, including UK tree planting initiatives.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Pen Test Partners competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant is a leading global incident response and threat intelligence firm with a substantial offensive security practice. Competes with PTP for high-end DFIR, intelligence-led red teaming (TIBER/CBEST), and post-breach engagements, with materially greater scale and brand recognition.
- F-Secure (WithSecure): European-headquartered cybersecurity vendor providing managed detection, incident response, and offensive security services alongside its consumer security products. A broader incumbent that competes for enterprise security testing and DFIR budgets but with a much wider product portfolio than PTP.
- Trustwave: Global cybersecurity firm offering managed security, penetration testing, DFIR, and PCI DSS QSA services. A broad incumbent competing for the same mid-market and enterprise testing and compliance engagements that PTP targets.
- CrowdStrike Services: CrowdStrike's services arm delivers incident response, proactive services, and red team assessments on top of the Falcon platform. A broad incumbent competitor for incident response and intelligence-led testing, leveraging platform data advantages that pure-play consultancies cannot match.
Direct peers
- Bishop Fox: US-based offensive security consultancy specializing in penetration testing, red teaming, and attack surface management for enterprise clients. Closest US-headquartered specialist pen testing peer to PTP, with overlapping service lines including continuous testing, cloud assessments, and IoT/OT work.
- NCC Group: UK-headquartered cybersecurity consulting and pen testing firm offering CHECK-accredited penetration testing, red teaming, DFIR, and managed detection services to financial services and critical infrastructure clients. The closest large-scale UK peer to Pen Test Partners, competing for the same regulated-industry testing budgets.
- Pentest People: UK-based penetration testing specialist delivering CREST-accredited testing, PTaaS, and managed security services. Direct UK competitor focused on a similar enterprise customer base with comparable service catalog and GTM motion.
- Secarma: UK-based cybersecurity consultancy providing CREST-accredited penetration testing, red teaming, and incident response. Operates in the same boutique UK segment as Pen Test Partners with overlapping service portfolio and enterprise client base.
- Coalfire: US-headquartered cybersecurity advisory firm delivering penetration testing, red teaming, and PCI DSS QSA assessments alongside cloud and compliance services. Direct competitor for PTP's PCI QSA and compliance-led pen testing work, especially with North American financial and retail clients.
Emerging players
- HackerOne: Bug bounty and vulnerability disclosure platform increasingly offering pen testing as a service and attack surface management. An emerging player with partial overlap to PTP's penetration testing and ASM service lines, but delivering through a crowdsourced platform model rather than a boutique consultancy.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks1 record
Key highlights6 records
Customer concentration
Pen Test Partners social profiles
Digital presencePen Test Partners compliance and trust
Trust signalCompliance7 records
Pen Test Partners financial estimates
Financial estimateRevenue estimate
Valuation estimate
Pen Test Partners leadership team
Management profileNumber of profiles
Profiles17 records
Pen Test Partners funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Pen Test Partners M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Pen Test Partners
What does Pen Test Partners do?
Pen Test Partners is a UK-based cybersecurity consulting and testing firm that delivers professional services to enterprise clients across four areas: Test and Simulate (penetration testing, red/purple teaming, AI testing, cloud, physical, OT/ICS, transport security testing), Detect and Respond (incident response, digital forensics, expert witness, managed detection and response, compromise assessments), Improve and Protect (security architecture, secure SDLC, virtual CISO, security training, gap and maturity assessments), and Comply (PCI DSS, Cyber Essentials, ISO 27001 preparation). Services are delivered by CHECK-, CREST-, and PCI QSA-accredited consultants on a per-project or retainer basis, with a 24/7 Rapid Breach Response service for active incidents.
Is Pen Test Partners a public or private company?
Pen Test Partners is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Pen Test Partners founded?
Pen Test Partners was founded in 2010. It employs 11 to 50 people.
Where is Pen Test Partners based?
Pen Test Partners is headquartered in Buckingham, United Kingdom, in the Europe region.
How does Pen Test Partners make money?
One revenue line is on record: professional Cybersecurity Services.
Who are Pen Test Partners's main competitors?
Broad incumbents on record are Mandiant (Google Cloud), F-Secure (WithSecure), Trustwave and CrowdStrike Services. Direct peers are Bishop Fox, NCC Group, Pentest People, Secarma and Coalfire. HackerOne is listed as an emerging player.
Does Pen Test Partners have an API?
No public API is recorded for Pen Test Partners.
What industry is Pen Test Partners in?
Pen Test Partners's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541690 and its SIC code is 8711.