THRESHOLDSecurity

Penetration testing services

Testing focused on the paths that matter.

Every engagement is manually led, proportionately scoped and designed around your systems, threat profile and reasons for testing.

01

Web application testing

Manual testing of web applications and their supporting services, focused on exploitable weaknesses and meaningful business impact.

  • Authentication and session management
  • Access control and business logic
  • Input handling and server-side vulnerabilities
  • Browser-side security and sensitive data exposure
02

Infrastructure testing

Internal or external assessment of networks, systems and exposed services to understand the paths an attacker could use.

  • External attack surface and perimeter services
  • Internal network and Active Directory
  • Configuration weaknesses and privilege escalation
  • Segmentation and lateral movement
03

API security testing

Focused assessment of REST, GraphQL and other application interfaces, including authorisation and business-logic abuse.

  • Object and function-level authorisation
  • Authentication and token handling
  • Input validation and injection
  • Rate limiting and workflow abuse
04

Wireless security testing

Assessment of corporate and guest wireless networks, client isolation and the controls separating radio access from sensitive systems.

  • Wireless configuration and encryption
  • Corporate and guest segregation
  • Authentication and credential exposure
  • Rogue access point resilience
05

Physical security assessment

A controlled, authorised attempt to access premises, restricted areas or assets using realistic attacker techniques.

  • Perimeter and entry controls
  • Reception and visitor procedures
  • Tailgating and agreed pretexts
  • Post-entry movement and asset exposure
06

Bespoke security assessment

A tightly scoped engagement for environments or objectives that do not fit a standard testing category.

  • Combined cyber and physical scenarios
  • Assumed-breach exercises
  • Security control validation
  • Remediation verification

What you receive

A report built to be used.

Findings are communicated during the engagement where urgency demands it, then brought together in a clear technical and executive report.

Executive context

A concise view of the material risks, written for decision-makers.

Technical evidence

Reproducible findings with supporting evidence and affected assets.

Prioritised remediation

Clear, proportionate actions based on exploitability and business impact.

Debrief and retest

A walkthrough with your team and an agreed route to validate fixes.

Not sure what to scope?

Start with the outcome you need.

A short initial conversation is usually enough to identify the right test boundary, access level and evidence requirements.