A scoping call defines targets, access, test windows and rules of engagement, which is what allows the work to be costed accurately. Tests typically run Monday to Friday, 09:00 to 17:30, and out-of-hours testing is agreed here where a production window will not tolerate a working-day test.
Penetration testing that tells you what to fix while the test is still running
Findings publish to our platform as our consultants find them, so your team can start remediating days before any report exists. High-severity fixes are then verified by a free re-test.
The problem
Most testing delivers its value weeks after the risk was found
A consultant finds something serious on day two, and you read about it on day fourteen in a document that then has to be transcribed into a spreadsheet before anyone can act on it.
-
The report arrives after the window closes
When findings are held back for a written deliverable, your exposure lasts as long as the writing does. The work of turning that document into tracked, assigned tasks then falls to your team. -
Building the capability in-house rarely pays
Credible testing needs specialist people, current tooling and constant practice, which is expensive to hold for work that happens a few times a year. Most teams end up with neither the depth nor the independence an auditor wants. -
Nobody knows whether the defences would notice
A technical test proves vulnerabilities exist. It does not tell you whether your people, processes and monitoring would spot someone exploiting one, which is the question a board actually asks.
How we run testing differently
Findings reach you during the test, not after it
Every vulnerability our consultants identify is published to the platform as it is found, with full client visibility. High-severity issues are raised with you immediately rather than saved for the deliverable, so remediation can begin while testing is still under way.
The same platform handles vulnerability management, scanning, asset management and remediation tracking, so findings are worked to closure in one place. You can export to PDF, Excel or CSV when someone needs a document, but the work does not have to live in one.
Engagements are threat-led, so the scenarios we run reflect the adversaries that plausibly target you rather than a generic checklist. Once you have remediated a high-severity finding, we re-test it at no further cost, which closes the loop with evidence rather than an assurance.
A finding you receive on day two is a finding you can fix on day two.
Business outcomes
What changes when testing stops being a document
-
Remediation starts during the engagement
Real-time reporting means your exposure window is measured from when a vulnerability is found rather than from when the report lands, which is usually a fortnight of difference. -
Audit and attestation evidence comes from the same work
Testing that supports compliance requirements produces the record auditors ask for as a by-product, so assurance stops being a separate exercise each year. -
Red teaming tests more than the technology
A red team exercise examines physical, technical, process and people security together, which is the only way to find out how your organisation behaves under a realistic attack.
-
Vulnerabilities are managed, not filed
Scanning, asset management and remediation tracking in one platform give you interactive management of findings rather than a version-controlled spreadsheet, with exports available when a document is genuinely needed. -
Third-party and insurance requirements get easier to answer
Independent testing supports the security requirements attached to customer contracts, and demonstrable remediation supports the cyber insurance conversation at renewal. -
You get the capability without building it
Access to experienced consultants year round, with a dedicated operations team running delivery, removes the cost and recruitment problem of holding specialist testing skills internally.
What's included
What a penetration testing engagement includes
-
A scoped technical security test
Tested against the scope you agreed at the scoping call, so the engagement matches your requirement rather than a packaged offer. -
Findings published live
Vulnerabilities appear on the platform as they are discovered, with high-severity issues raised immediately, so remediation does not wait for the report. -
Free re-test on high-severity findings
Once you have remediated, we verify the fix at no further cost, so the record shows a closed issue rather than an intention. -
Red, purple and wargame formats
From a full end-to-end adversary simulation to collaborative exercises that build internal capability while they run, chosen to match your maturity. -
Consultants available year round
Ongoing support and advice between engagements, so a question about a finding or a change does not wait for the next project.
-
Threat-led scenario design
Threat intelligence shapes each engagement, so the attacks we simulate are the ones that plausibly target an organisation like yours. -
Vulnerability management platform
Scanning, asset management and remediation tracking in one place, so findings are worked to closure interactively instead of through attachments. -
Technical and executive debrief workshops
Two audiences, two conversations: engineers get the reasoning and the detail, the board gets the decisions and the residual risk. -
A dedicated operations team
Scheduling, access and delivery coordination are owned by people whose job that is, so project management does not land back on you.
How it's delivered
A scoped project, then a working relationship
Scope and agree
Test
Consultants work the agreed scope with threat intelligence shaping the approach. Findings publish to the platform as they are identified, with high-severity issues raised straight away rather than held for the deliverable.
Debrief and re-test
Technical and executive debrief workshops turn findings into decisions, and we work with your internal teams to improve defensive controls and detection and response rather than handing over a report. High-severity findings are re-tested free of charge once remediated.
Get a sense of the size before you book the call
Six questions about what you need tested. You'll get an indicative engagement size, what drives it up or down, and exactly what the scoping call will confirm. It's an estimate to plan around, not a quote.
Why FluidOne
Four reasons security teams bring the testing to us
-
Assurance your auditors already recognise
Our cyber security practice, CSA Cyber, is a CREST member company and holds NCSC CHECK Green Light status, so the methodology behind your test is reviewed and approved externally rather than asserted by us. -
Collaborative by design
We do not break in and hand over a report. Our consultants work with your internal teams through debriefs and workshops to improve defensive controls and detection and response capability.
-
Threat-led rather than checklist-led
Threat intelligence informs each engagement, so the work reflects the adversaries relevant to your sector instead of a generic scan run against everyone. -
A team that has been doing this since 2006
Established testing experience across commercial and public sector work, with a dedicated red team used to organisations at very different levels of maturity.
Is it a fit?
We'd rather tell you now than three months in
This service is built for a particular shape of organisation. Here's how to tell quickly whether that's you.
A strong fit if
- ✓ An auditor, customer, insurer or regulator requires you to have independent testing.
- ✓ You ship software regularly and need testing that keeps pace with your releases.
- ✓ You want findings you can act on during the engagement rather than a report at the end.
- ✓ Somebody, internally or at a supplier, has the capacity to carry out remediation.
- ✓ You want to know whether your detection and response would notice a real adversary.
Worth knowing first
- • We provide prioritised recommendations. The remediation itself stays with your team or your supplier.
- • Nothing can be costed until a scoping call has defined targets, access and rules of engagement.
- • Tests typically run Monday to Friday, 09:00 to 17:30, with out-of-hours work agreed during scoping.
- • A test covers the scope agreed and the point in time it ran, so anything outside that scope is not assessed.
- • A full end-to-end red team assumes there is detection capability worth testing, otherwise a collaborative format gives you more.
FAQs
The questions we get asked first
Through a scoping call, always. It defines the targets, the access we need, the test windows and the rules of engagement, and cost follows from that rather than from a price list. Out-of-hours testing is agreed at the same point, where a production system cannot tolerate a working-day test.
A penetration test measures whether vulnerabilities exist in an agreed scope. A red team exercise simulates a real adversary to test physical, technical, process and people security together, including whether you would detect and respond. Purple team and wargame formats sit between the two and build internal capability as they run.
No. We provide prioritised recommendations, work through them with your engineers in the technical debrief, and re-test high-severity findings free of charge once you have remediated. The remediation itself stays with your team or the supplier that owns the system.
Next step
Ready to find out what an
attacker would find?
Tell us what needs testing, what is driving the deadline and who would act on the findings. The scoping call sets the targets, access and rules of engagement, and gives you an accurate cost for the work rather than an estimate.