A real penetration test of your network — automated, CREST-certified, and priced for businesses your size. The same answer the big consultancies give, without the £10,000 invoice or the six-week wait.
Three things have changed in the last twelve months, and they’re all pointing in the same direction.
Your cyber insurance renewal now asks the question. Look at the form. “When was your last penetration test?” is on there. So is “Do you have evidence of remediation?” If you can’t answer, expect a higher premium, a higher excess, or a flat refusal to renew. Insurers have been hit too hard in the last few years to keep underwriting blind.
Your bigger clients have started auditing their suppliers. If you sell into the NHS, local authorities, financial services, or any larger organisation, you’re getting supplier questionnaires that didn’t exist three years ago. They ask about pentesting because their auditors ask them. Lose that contract because you can’t tick the box, and the pentest you didn’t pay for becomes the most expensive thing you didn’t buy.
The law is changing. The Cyber Security and Resilience Bill is going through Parliament right now. It widens the existing 2018 regulations, brings managed service providers into direct regulatory scope, and pushes supply chain due diligence down into businesses that have never had to think about it before. Royal Assent is expected later in 2026. The businesses that get ahead of this won’t be scrambling in 2027.
43% of UK businesses reported a cyber breach or attack in the last twelve months, according to the Government’s 2025 Cyber Security Breaches Survey. For medium-sized businesses it was 67%. The average recovery cost for a small business hit by a serious breach is around £7,960 — and that’s before reputational damage, lost contracts, or ICO involvement.
The question isn’t whether to test your network. It’s whether you find the problems, or someone else does.
A pentest is not a vulnerability scan. A scan tells you what might be exploitable. A penetration test actively tries to exploit it — the way a real attacker would — so you find out what would genuinely happen, not what’s theoretically possible.
We deliver this through vPenTest, an automated platform from Vonahi Security that replicates the methodology of a human penetration tester. A typical assessment will:
Every action is logged. If your monitoring and alerting tools didn’t see any of it happen, that’s a finding in itself — and one that often surprises people more than the technical vulnerabilities.
Two assessment types, answering two different questions.
Run from the public internet against your firewalls, VPNs, mail servers, and any exposed services. This is the view from a stranger on the other side of the world looking for a way in.
A lightweight agent is deployed inside your network (around 30 minutes to set up) and tests what an attacker could do once they have a foothold — through a phished user, a compromised laptop, a stolen password, or an unpatched device. This is usually the more revealing of the two, because the perimeter is rarely the weakest part.
vPenTest is the first and only CREST-accredited automated penetration testing platform in Europe, the Middle East, and Africa. CREST is the standard the major consultancies are accredited to. It’s recognised by the NCSC, by cyber insurers, and by every serious compliance framework.
If your auditor, insurer, or framework — Cyber Essentials Plus, ISO 27001, SOC 2, PCI DSS — requires a CREST-certified report, vPenTest delivers one with the CREST logo on the cover. The report is issued under Vonahi Security’s CREST scope. ML Services is your local delivery partner: we scope the work, run the test, walk you through the findings in plain English, and handle the remediation work afterwards.
Within 48 hours of the test finishing, you get:
Findings are prioritised by what could actually be exploited, not just by CVSS score. You’ll know what to fix first because you’ll know what would have hurt you first.
The report is the start, not the finish. A pentest is only worth what you do with it.
If you’re not sure whether a full pentest is the right next step, start with the IT health check. Thirty minutes, no cost, no obligation. We’ll look at your current setup — your email security, your patching, your backups, your endpoint protection — and tell you honestly whether a pentest would tell you something you don’t already know.
Yes. vPenTest exercises the same caution a human pentester would — it has built-in conditions to avoid causing service disruption. It’s no riskier than a traditional manual penetration test, and far more controlled than an unannounced attack. We’ll agree the testing window with you upfront.
A scan finds things that might be exploitable. A pentest tries to exploit them. The two are complementary — most compliance frameworks expect both, but only a pentest tells you what an attacker would actually achieve.
vPenTest reports align with the penetration testing requirements in most UK cyber insurance policies, plus SOC 2, PCI DSS, HIPAA, ISO 27001, and Cyber Essentials Plus. We’ll check the specific wording in your policy during scoping — bring the questionnaire and we’ll match the report to it.
Annually is the minimum most frameworks require. In practice, the value comes from testing more often — quarterly or monthly — because your environment changes and the threat landscape changes faster. vPenTest is built for that cadence; there’s no extra cost to run it more frequently within your IP allocation.
Pricing depends on the size of your network and whether it’s a one-off or a recurring schedule. It’s a fraction of a traditional manual pentest — typically thousands rather than tens of thousands. Get in touch for a quote.