Skip to content

Incursion Cyber Security:
penetration testing and IASME certification,
UK-wide.

Veteran-founded
Cyber Scheme Accredited Company
Est 2022

Certified, accredited and registered

The Cyber Scheme Accredited CompanyJOSCAR registered supplier
G-Cloud 15 supplier, Government Commercial AgencyArmed Forces Covenant Employer Recognition Scheme Bronze awardFederation of Small Businesses member

An offer so good we did it twice

Free retests

On all penetration tests
On all Cyber Essentials Plus assessments
WHAT WE DO

Penetration testing and
IASME certification

Ten penetration testing services and three certifications. Every engagement is scoped and delivered by a named consultant with a UK Cyber Security Council professional title.

Web application penetration testing

Authenticated and unauthenticated testing against the OWASP Top 10 and beyond, on the application you actually run.

Learn more about web application penetration testing

API penetration testing

REST, GraphQL and SOAP services: authentication, authorisation, object-level access and business logic.

Learn more about API penetration testing

Mobile application penetration testing

iOS and Android, black box or source-assisted: the app, device storage and the back-end API behind it.

Learn more about mobile application penetration testing

External infrastructure penetration testing

Everything you expose to the internet: perimeter, remote access, mail, DNS and exposed services.

Learn more about external infrastructure penetration testing

Internal infrastructure penetration testing

What an attacker or insider could do once inside your network: Active Directory, segmentation, privilege escalation.

Learn more about internal infrastructure penetration testing

Cloud penetration testing

Configuration review against the CIS Benchmarks plus hands-on testing of identity, permissions and workloads in AWS, Azure and Google Cloud.

Learn more about cloud penetration testing

Wireless penetration testing

Configuration review of controllers and access points plus active testing of corporate, guest and rogue Wi-Fi, on site.

Learn more about wireless penetration testing

Physical penetration testing

Covert and overt testing of your premises: entry controls, reception, badges, tailgating and on-site staff interaction.

Learn more about physical penetration testing

Build and configuration review

Windows, Unix and macOS builds reviewed against the CIS Benchmarks and your own standard.

Learn more about build and configuration review

Cyber Essentials

The UK government baseline certification, assessed and issued by us as an IASME-licensed certification body.

Learn more about Cyber Essentials

Cyber Essentials Plus

Independent technical verification of the five controls by our assessors, with the certificate issued by us.

Learn more about Cyber Essentials Plus

IASME Cyber Assurance

Level 1 and Level 2 certification of your security governance, beyond the Cyber Essentials baseline. We hold both levels ourselves.

Learn more about IASME Cyber Assurance
HOW WE TEST

One consultant,
from scope to retest

Our sales team will set up the calls, handle the proposal, talk through the commercials and drink as much of your coffee as you will let them. But the scope is agreed only by an active penetration tester. That is how we guarantee the scope is accurate and nothing is oversold. No more inaccurate scopes.

We do not advertise qualified testers and send you the new intern.

01

Scoping

Your account manager and an active penetration tester work with you to agree the scope of your test on a scoping call. The quote is fixed to it.

02

Testing

A named, suitably qualified consultant does the work, and you get a direct line to them before, during and after the engagement. Critical and high-risk issues are verified and reported immediately.

03

Reporting

Easily digestible summaries sum up the whole engagement and support detailed technical findings, written so your team can replicate and fix them. Delivered within 5 working days.

04

Free retesting

One day of free retesting for every five days of consultancy, taken within 90 days of report delivery, so you can be sure the fixes worked.

WHO WE ARE

Founded by a tester who still tests

Incursion Cyber Security was founded in 2022 by Lewis Lockwood, a former British Army Intelligence Analyst who holds the Chartered Cyber Security Professional title in Security Testing and still tests. We are a Cyber Scheme Accredited Company, and the people who do the work hold UK Cyber Security Council professional titles. We are fully remote, with consultants in Somerset, Greater London, West Yorkshire and Renfrewshire, working with organisations across the UK.

Every consultant on an engagement is named on our team page, and every accreditation we claim is linked to its register on our accreditations page.

WHAT CLIENTS SAY

Named consultants,
plain-English reports

“We were extremely happy with the work carried out by Lewis and Incursion Cyber Security, with the project being completed well ahead of schedule. Lewis went above and beyond to help us.”

E
ElevenLabs AI audio company

“We feel very good about the way we were guided through the process and the support we were given; and of course the result.”

R
Royal Free London NHS Foundation Trust NHS

“Working with Incursion was straightforward from start to finish. Communication was clear, everything was well-organised, and the assessment was completed efficiently.”

H
Homerun Software company
INSIGHTS

Guides from our testers
and assessors

Ready to scope a test?

Book a call. Our Senior Business Development Manager will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.