Incursion Cyber Security:
penetration testing and IASME certification,
UK-wide.
Certified, accredited and registered
An offer so good we did it twice
Free retests
Four ways to work with us
Penetration testing and
IASME certification
Ten penetration testing services and three certifications. Every engagement is scoped and delivered by a named consultant with a UK Cyber Security Council professional title.
Web application penetration testing
Authenticated and unauthenticated testing against the OWASP Top 10 and beyond, on the application you actually run.
Learn more about web application penetration testingAPI penetration testing
REST, GraphQL and SOAP services: authentication, authorisation, object-level access and business logic.
Learn more about API penetration testingMobile application penetration testing
iOS and Android, black box or source-assisted: the app, device storage and the back-end API behind it.
Learn more about mobile application penetration testingExternal infrastructure penetration testing
Everything you expose to the internet: perimeter, remote access, mail, DNS and exposed services.
Learn more about external infrastructure penetration testingInternal infrastructure penetration testing
What an attacker or insider could do once inside your network: Active Directory, segmentation, privilege escalation.
Learn more about internal infrastructure penetration testingCloud penetration testing
Configuration review against the CIS Benchmarks plus hands-on testing of identity, permissions and workloads in AWS, Azure and Google Cloud.
Learn more about cloud penetration testingWireless penetration testing
Configuration review of controllers and access points plus active testing of corporate, guest and rogue Wi-Fi, on site.
Learn more about wireless penetration testingPhysical penetration testing
Covert and overt testing of your premises: entry controls, reception, badges, tailgating and on-site staff interaction.
Learn more about physical penetration testingBuild and configuration review
Windows, Unix and macOS builds reviewed against the CIS Benchmarks and your own standard.
Learn more about build and configuration reviewCyber Essentials
The UK government baseline certification, assessed and issued by us as an IASME-licensed certification body.
Learn more about Cyber EssentialsCyber Essentials Plus
Independent technical verification of the five controls by our assessors, with the certificate issued by us.
Learn more about Cyber Essentials PlusIASME Cyber Assurance
Level 1 and Level 2 certification of your security governance, beyond the Cyber Essentials baseline. We hold both levels ourselves.
Learn more about IASME Cyber AssuranceOne consultant,
from scope to retest
Our sales team will set up the calls, handle the proposal, talk through the commercials and drink as much of your coffee as you will let them. But the scope is agreed only by an active penetration tester. That is how we guarantee the scope is accurate and nothing is oversold. No more inaccurate scopes.
We do not advertise qualified testers and send you the new intern.
Scoping
Your account manager and an active penetration tester work with you to agree the scope of your test on a scoping call. The quote is fixed to it.
Testing
A named, suitably qualified consultant does the work, and you get a direct line to them before, during and after the engagement. Critical and high-risk issues are verified and reported immediately.
Reporting
Easily digestible summaries sum up the whole engagement and support detailed technical findings, written so your team can replicate and fix them. Delivered within 5 working days.
Free retesting
One day of free retesting for every five days of consultancy, taken within 90 days of report delivery, so you can be sure the fixes worked.
Founded by a tester who still tests
Incursion Cyber Security was founded in 2022 by Lewis Lockwood, a former British Army Intelligence Analyst who holds the Chartered Cyber Security Professional title in Security Testing and still tests. We are a Cyber Scheme Accredited Company, and the people who do the work hold UK Cyber Security Council professional titles. We are fully remote, with consultants in Somerset, Greater London, West Yorkshire and Renfrewshire, working with organisations across the UK.
Every consultant on an engagement is named on our team page, and every accreditation we claim is linked to its register on our accreditations page.
Named consultants,
plain-English reports
“We were extremely happy with the work carried out by Lewis and Incursion Cyber Security, with the project being completed well ahead of schedule. Lewis went above and beyond to help us.”
“We feel very good about the way we were guided through the process and the support we were given; and of course the result.”
“Working with Incursion was straightforward from start to finish. Communication was clear, everything was well-organised, and the assessment was completed efficiently.”
Guides from our testers
and assessors
- Cyber Essentials Plus vs penetration testing: what each covers and which to do firstCyber Essentials Plus audits five baseline controls on sampled devices; a penetration test tries to get in. What each covers, where they overlap, which to do first, and how to run both without paying twice.
- The five Cyber Essentials controls: what they are and what assessors checkThe five Cyber Essentials technical controls (firewalls, secure configuration, security update management, user access control and malware protection) explained by a certification body: what each requires, what the assessor checks, and where applicants fall short.
- How to build a defensible cyber security budgetIn short. A defensible cyber security budget starts with a risk assessment, not last year’s figures or a vendor’s shopping list. Identify your most…
Ready to scope a test?
Book a call. Our Senior Business Development Manager will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.



