Security Testing

We identify vulnerabilities before cybercriminals can exploit them

We conduct authorised penetration testing of applications, systems and network infrastructure. We work based on a contract, written consent from the system owner and an agreed scope. Every engagement ends with a report detailing vulnerabilities, risk assessment and practical remediation recommendations.

What we test

Testing scope

We test the application, system and network layers — individually or as a single, joined-up engagement.

Test areas

application layer

Web applications & APIs

We test web applications, B2B and B2C platforms, and APIs. We examine authentication and access control, business logic, injection vulnerabilities, configuration and the handling of sensitive data.

system layer

Linux systems

We test Linux servers and environments: service configuration, permissions management, privilege escalation paths, patch levels of components and the effectiveness of hardening.

network layer

Networks & network devices

We test network infrastructure and edge devices, including MikroTik, FortiGate and pfSense. We review configuration, network segmentation, firewall rules, remote access and VPNs, and whether firmware is up to date.

How we deliver

Internal & external testing

We test from the perspective of an attacker on the internet as well as that of a user inside the network. The scenario is chosen to fit the threat model agreed with the client.

Configuration review & audit

Where active testing would pose too great a risk to a production environment, we carry out a configuration and architecture review instead. The outcome is the same: a list of findings with risk ratings and recommendations.

Retesting

Once fixes have been deployed, we verify that the vulnerabilities have genuinely been remediated and update the report accordingly.

How we work

Security testing, always with the owner's consent

Nothing starts without a signed contract and written authorisation. We hold ourselves to the same standard we apply to our clients.

1

Scoping

We define which systems, addresses and applications are in scope — and which are explicitly out of scope.

2

Contract & authorisation

We sign a contract and an NDA, and obtain the system owner's written consent to carry out the testing.

3

Rules of engagement

We agree the testing window, permitted techniques, points of contact on both sides and an escalation path for reporting critical findings immediately.

4

Testing

We identify vulnerabilities and verify whether they can realistically be exploited — with no destructive actions and no disruption to your systems' operation.

5

Reporting

We deliver a report setting out our findings, risk ratings and remediation recommendations, then walk the client's team through it.

What you get

A report that turns findings into action

We write every report so your technical team knows exactly what to fix, and your board understands which risks have been taken off the table.

Penetration test report Confidential
  • Executive summary

    The key facts about the security of the tested scope, together with an assessment of the business risk.

  • Risk-rated vulnerability list

    Every vulnerability is described with its impact and remediation priority.

  • Vulnerability verification

    We check whether the weaknesses we find can actually be exploited in an attack, and assess their real-world impact.

  • Remediation recommendations

    Clear, practical steps tailored to your technology stack.

Once you have the report

  1. Results walkthrough

    A session with your technical team to go through the findings in detail.

  2. Retest

    We confirm that the fixes you have put in place actually work.

We treat reports and all data obtained during testing as confidential, and share them only with the people you nominate.

Our team and methodologies

Who carries out the testing

Every test is conducted by our in-house engineers, never by subcontractors. We work to recognised industry methodologies and back them up with hands-on manual testing.

15 years in business
200+ systems delivered
60+ specialists in the team

Methodologies

  • Web applications and APIs
    WSTGOWASP Web Security Testing Guide ASVSOWASP Application Security Verification Standard API Top 10OWASP API Security Top 10
  • Linux systems
    CIS Benchmarks Hardening guidance from distribution vendors
  • Networks and network devices
    CIS Benchmarks Vendor hardening guidelines: MikroTik, Fortinet, Netgate
  • Testing process
    NIST SP 800-115 PTESPenetration Testing Execution Standard
  • Classification and risk scoring
    CWECommon Weakness Enumeration CVSS v4.0

Organisational standards

ISO/IEC 27001:2022

Certified by the certification body SGS.

Tools

We combine commercial and open-source tools with manual testing and custom scripts written for each specific engagement.

We practise what we preach

We test our own systems every month

We treat security as an ongoing process, not a one-off audit. Omega Code's infrastructure and products are tested on a monthly cycle, following exactly the same procedure we use for our clients. That's how we know what keeping systems secure looks like over time — not just on the day of the test.

We recommend the same approach to our clients

A test after every major system change

A review at least once a year

Make your test results last

Putting the fixes in place is only the beginning. We can help you keep your environment secure day to day and plan future IT investment with confidence.

FAQ

Could testing disrupt our systems?
We work within an agreed time window and never carry out destructive actions. Higher-risk scenarios are only run with your explicit consent and, where necessary, in a test environment.
Do we need a test environment?
It isn't required. If you do have one, though, it often lets us test a wider range of scenarios without any risk to production.
How long does a test take?
A typical engagement takes anywhere from a few days to two weeks, depending on the scope. We'll give you a detailed schedule once the scope has been agreed.
How often should testing be repeated?
We recommend testing after every major change to your system, and a review at least once a year.
What about data confidentiality?
We work under an NDA. The report and all test data are shared only with the people you nominate.
Do you test systems you didn't build?
Yes. We test both systems we have built ourselves and solutions delivered by other suppliers.

Find the right approach
to security testing

We’ll discuss your systems and potential risks to determine the testing approach that best meets your needs.