Pentest
Pentest Limited is a CREST-accredited UK offensive cybersecurity firm delivering manual penetration testing and adversary simulation — web, mobile, infrastructure, cloud, IoT, red teaming, and PCI/ISO-aligned compliance testing — to enterprise and public sector clients across eight verticals.
- Company typePrivate
- Founded2019
- HeadquartersAltrincham, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Pentest does
Pentest Limited is a UK-based, CREST-accredited offensive cybersecurity firm that delivers manual penetration testing and adversary simulation services to organisations that require assurance beyond automated scanning. The firm's core technology is human-led assessment by directly employed, certified consultants (OSCP, CRTO) using proprietary methodologies combined with commercial tooling. The service portfolio spans five penetration testing lines — web application, mobile application, infrastructure, cloud, and embedded device/IoT — plus an adversary simulation suite covering red team assessments, purple team exercises, continuous adversary simulation, and social engineering/phishing. Compliance-aligned offerings for PCI DSS, ISO 27001, and M&A security due diligence extend the proposition into regulated and transactional workflows, supported by a research arm (Pentest Labs) that publishes original CVE advisories and competing Pwn2Own track records.
Pentest operates a project-based professional services revenue model. Engagements are individually scoped against target complexity, scope, duration, and testing approach (black box, grey box, white box), with pricing not publicly disclosed and competitive tender processes used for larger clients, notably through the G-Cloud procurement framework for the UK public sector. An initial fee of 10% of estimated fees is charged upon order acceptance; balance invoicing is tied to delivery of the Test Report with 30-day payment terms. Go-to-market is enterprise field sales: all engagements originate from direct contact (website form, phone, email), are scoped via consultation, and are delivered by in-house consultants. The customer base spans eight verticals — software/SaaS, technology and telecoms, higher education, fintech and financial services as primary segments, plus food and drink manufacturing, retail/e-commerce, healthcare, and media — with named engagements including a UK government-owned renewable energy organisation.
Pentest is a subsidiary of Shearwater Group plc, an information security conglomerate whose portfolio includes Xcina Consulting, Geolang, Brookcourt Solutions, and SecurEnvoy. The group structure produces reciprocal referral channels: Xcina delivers ISO 27001/PCI DSS QSA services, Brookcourt drives G-Cloud channel referrals, and Pentest provides the underlying penetration testing. Headcount sits in the 11–50 band, with UK offices in London (registered address), Altrincham, Redhill, Basingstoke, and Cardiff, and group-level operating geographies across the UK, USA, and Germany. Certification set includes CREST, ISO 9001, ISO 27001, and Cyber Essentials Plus. Leadership comprises CEO Phil Higgins (who also serves as Shearwater Group's Slavery Compliance Officer) and Managing Director Paul Harris.
Pentest firmographics
Firmographics- Name
- Pentest
- Legal name
- Pentest Limited
- Website
- https://pentest.co.uk
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Pentest Limited is a CREST-accredited UK offensive cybersecurity firm delivering manual penetration testing and adversary simulation — web, mobile, infrastructure, cloud, IoT, red teaming, and PCI/ISO-aligned compliance testing — to enterprise and public sector clients across eight verticals.
- Ownership category
- akta.pro rank
Pentest industry classification
Industry- Product category
- Cybersecurity Penetration Testing Services
- NAICS
- Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKADAE), Vulnerability Management & Penetration Testing Services (BPAEADAD), IoT Vulnerability Assessment, Penetration Testing & Risk Audits (HSAHAJAC)
Keywords
Where Pentest is headquartered
LocationHeadquarters
- HQ city
- Altrincham
- HQ country
- United Kingdom
- HQ region
- Europe
Offices5 records
Markets served
Pentest business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel
Revenue model
- Penetration Testing Services: Project-based professional services delivering security assessments across web applications, infrastructure, cloud, mobile, and IoT/embedded devices. Fees are scoped per engagement based on complexity, scope, and duration. Invoices are issued upon delivery of the Test Report, with payment due within 30 days. An Initial Fee of 10% of estimated Fees may be charged upon order acceptance to cover initiation and preparation costs.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Pentest product offering
Product offeringCore offering
Pentest Limited delivers human-led, CREST-accredited penetration testing and adversary simulation services to enterprise and public-sector clients. Engagements span web application, mobile, infrastructure, cloud, and IoT/embedded device testing, complemented by red/purple team exercises, continuous adversary simulation, social engineering, and compliance-aligned testing for PCI DSS and ISO 27001. All work is delivered by directly employed certified consultants using manual expertise combined with advanced tooling.
Product overview
Pentest Limited is a CREST-accredited offensive cybersecurity firm with over 25 years of experience offering human-led penetration testing and adversary simulation services. The core portfolio spans five penetration testing service lines — Web Application, Mobile Application, Infrastructure, Cloud, and Embedded Device/IoT testing — complemented by adversary simulation offerings including Red Team Assessments, Purple Team Exercises, Continuous Adversary Simulation, and Social Engineering & Phishing. Compliance and risk assurance services cover PCI DSS, ISO 27001, and M&A due diligence. Supporting the service delivery, Pentest Labs produces original vulnerability research and CVE disclosures, with all engagements delivered by directly employed, certified consultants using a methodology combining manual expertise with advanced tooling. The company is a Shearwater Group plc company.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Application Penetration Testing In-depth security testing of websites, APIs, and web-based platforms covering the OWASP Top 10 and beyond, including business logic flaws, authentication weaknesses, and session management vulnerabilities. Delivered remotely using black box, grey box, or white box approaches for enterprise clients.
- Mobile Application Penetration Testing Security testing for iOS and Android applications using static and dynamic analysis, assessing insecure data storage, weak authentication, unprotected API backends, and inter-app communication vulnerabilities.
- Infrastructure Penetration Testing Testing of external perimeter and internal networks identifying misconfigurations, unpatched vulnerabilities, privilege escalation paths, and network architecture weaknesses across routers, switches, firewalls, operating systems, and Active Directory environments.
- Cloud Penetration Testing Security assessment of AWS, Azure, Oracle, and GCP cloud environments identifying misconfigured services, over-privileged accounts, and exposed cloud-native resources that could be exploited by attackers.
- Embedded Device / IoT Penetration Testing Security testing for connected devices and embedded systems covering hardware analysis, firmware review, communication protocol testing, and device-level vulnerability assessment, particularly where sensitive data is processed or compromise could have operational consequences.
- Red Team Assessments Full-scope adversary simulation exercises that test an organisation's people, processes, and technology under realistic attack conditions, assessing whether defences can detect, contain, and respond to intrusions.
- Purple Team Exercises Joint exercises combining red team offensive tactics with blue team defensive detection capabilities to improve an organisation's ability to identify and respond to threats in real time.
- Continuous Adversary Simulation Ongoing adversary simulation programme providing continuous testing rather than point-in-time assessments, maintaining persistent visibility of an organisation's exposure over time.
- Social Engineering & Phishing Assessment of an organisation's human attack surface through phishing campaigns, impersonation exercises, and other social engineering techniques to test employee awareness and response.
- PCI DSS Penetration Testing Penetration testing aligned to PCI DSS v4.0 Requirements 11.3.1 and 11.3.2, covering external and internal network infrastructure, application testing, network segmentation verification, and wireless assessments within the cardholder data environment, with reporting designed for QSA use.
- ISO 27001 Security Testing Penetration testing and vulnerability analysis aligned to ISO 27001 control objective A12.6.1, supporting risk assessment, risk treatment planning, and ongoing internal auditing requirements for ISMS certification.
- M&A Security Due Diligence Security assurance assessments conducted as part of mergers and acquisitions to evaluate the cybersecurity posture, vulnerability exposure, and risk profile of target organisations.
Quantifiable outcome
- Identification of vulnerabilities that automated tools cannot find, including business logic flaws, chained attack paths, and real-world exploitation scenarios
- +1 more outcomes
Companies that use Pentest
Customer profileNamed customers1 record
Segments8 records
Ideal customer profiles6 records
Pentest technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Pentest partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Brookcourt SolutionscoreBrookcourt Solutions, a sister company within Shearwater Group plc, identified the renewable energy sector engagement opportunity and passed it to Pentest for consideration. Brookcourt operates as a channel partner through the G-Cloud 14 procurement framework, generating referral opportunities for Pentest's penetration testing services.
- Xcina ConsultingcoreXcina Consulting is a sister company within Shearwater Group plc and a BSI Platinum Member offering full ISO 27001 consulting services. Pentest refers clients requiring ISO 27001 certification support to Xcina. Conversely, Xcina recommends Pentest for penetration testing requirements. For PCI DSS, Xcina acts as a Qualified Security Assessor (QSA) while Pentest provides the required penetration testing, creating a complementary service offering.
- Shearwater Group plccoreShearwater Group plc is the parent company of Pentest Limited. Shearwater Group's stated aim is to acquire and develop information security, cyber and cyber security companies with leading capabilities, whose full potential can be unlocked through active management and capital investment. SWG is comprised of Xcina Consulting Limited, Geolang Limited, Pentest Limited, Brookcourt Solutions Limited, and SecurEnvoy Limited.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
Pentest competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike Services: Endpoint security leader with a substantial professional services arm offering adversary simulation, red team, and penetration testing. Comparable on adversary simulation methodology and enterprise buyer overlap, though bundled into a much larger platform company.
- NCC Group: Large UK-listed cybersecurity and resilience firm with a sizeable penetration testing practice spanning web, infrastructure, cloud, and red team. Comparable to Pentest in service breadth and CREST accreditation, but materially larger in headcount and geographic reach, positioning it as a tier-1 incumbent in the same segment.
- Coalfire: US-based cybersecurity advisory and assessment firm with strong penetration testing and compliance testing (PCI DSS, ISO 27001) practices. Comparable on regulated-industry testing mandates and adjacent to Pentest via shared PCI DSS QSA-adjacent positioning.
- WithSecure (formerly F-Secure Cyber Security Consulting): European-headquartered cybersecurity firm with a cyber security consulting arm offering penetration testing and red team services (formerly MWR InfoSecurity). Comparable service line with deeper geographic spread and broader product portfolio, competing for similar enterprise accounts.
- Schellman: US-based IT attestation and cybersecurity firm with penetration testing and ISO 27001 assessment services. Comparable in delivering compliance-aligned testing to enterprise clients, particularly in financial services, although structured more around attestation than red team.
Direct peers
- Secarma: UK penetration testing and cybersecurity consultancy with CREST and CHECK accreditations. Directly comparable as a UK mid-market pen testing firm targeting regulated industries, with similar PCI DSS and ISO 27001 testing capabilities.
- Bishop Fox: US-based offensive security firm offering penetration testing, red teaming, and adversary simulation services. Comparable on human-led methodology, research-led brand (CVE disclosures), and enterprise / financial services client base, albeit serving primarily North America.
- Context Information Security: UK-based technical cybersecurity consultancy (now part of Accenture) with penetration testing, red team, and IoT security practices. Comparable on CREST-accredited UK delivery, embedded / IoT focus, and regulated-industry client base.
- Cyberis: UK-based information security consultancy specialising in penetration testing and incident response. Comparable as a CREST-accredited boutique with similar enterprise and public-sector focus and an emphasis on manual, intelligence-led testing.
- Pentest Partners: UK-based CREST-accredited penetration testing consultancy with a similar service mix across web, mobile, infrastructure, cloud, IoT, and red team. Most directly comparable competitor given overlapping verticals, accreditation footprint, and comparable scale.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Pentest social profiles
Digital presencePentest compliance and trust
Trust signalCompliance4 records
Pentest financial estimates
Financial estimateRevenue estimate
Valuation estimate
Pentest leadership team
Management profileNumber of profiles
Profiles4 records
Pentest funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Pentest M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Pentest
What does Pentest do?
Pentest Limited delivers human-led, CREST-accredited penetration testing and adversary simulation services to enterprise and public-sector clients. Engagements span web application, mobile, infrastructure, cloud, and IoT/embedded device testing, complemented by red/purple team exercises, continuous adversary simulation, social engineering, and compliance-aligned testing for PCI DSS and ISO 27001. All work is delivered by directly employed certified consultants using manual expertise combined with advanced tooling.
Is Pentest a public or private company?
Pentest is a private company. It is classified as corporate owned and is currently operating.
When was Pentest founded?
Pentest was founded in 2019. It employs 11 to 50 people.
Where is Pentest based?
Pentest is headquartered in Altrincham, United Kingdom, in the Europe region.
How does Pentest make money?
One revenue line is on record: penetration Testing Services.
Who are Pentest's main competitors?
Broad incumbents on record are CrowdStrike Services, NCC Group, Coalfire, WithSecure (formerly F-Secure Cyber Security Consulting) and Schellman. Direct peers are Secarma, Bishop Fox, Context Information Security, Cyberis and Pentest Partners.
Does Pentest have an API?
No public API is recorded for Pentest.
What industry is Pentest in?
Pentest's product category is Cybersecurity Penetration Testing Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 54138 and its SIC code is 8734.