Independent UK Cyber Security Consultancy

Penetration Testing & Attack Path Simulation

We test your defences the way an attacker would, identifying exploitable weaknesses before they are found by others. Every engagement is formally scoped, contracted, and delivered with clear findings that technical and executive audiences can act on.

6+
Certifications
100%
Authorised
UK
Based
CMA
Compliant

About

Secured By Offense

Secured By Offense is an independent cyber security consultancy based in the United Kingdom. We provide penetration testing, cyber security audits, attack path simulation, and Cyber Essentials certification support to organisations across the private and public sectors.

Our work is grounded in current offensive security techniques and aligned to NCSC guidance and recognised industry frameworks. All findings are documented with risk ratings and practical recommendations, structured to be understood at board level and acted upon by technical teams.

Every engagement is governed by a formal written contract, signed Rules of Engagement, and a Non-Disclosure Agreement, providing legal certainty for both parties from the outset.

Get in Touch

Services

What We Do

We work across the full spectrum of offensive security, from government-backed certification through to complex adversary simulation.

01

Web Application & API

Manual penetration testing of web applications and APIs conducted in accordance with OWASP methodology. The assessment identifies authentication weaknesses, injection vulnerabilities, business logic flaws, and access control failures beyond the reach of automated scanning. Findings are delivered with full technical detail, risk ratings, and prioritised remediation steps.

02

Internal Infrastructure Assessment

Assessment of services and software running within a specified network range. Domain credentials are not required but can be provided to assess from both an authenticated and unauthenticated perspective. Covers vulnerability identification, service misconfiguration, and exposure across the internal network, delivering a risk-rated findings report.

03

Attack Path Simulation

A fully comprehensive infrastructure assessment with all systems within scope. Conducted from a position of provided credentials or a provisioned corporate device, the engagement tests every viable attack path across on-premise and cloud environments, including Azure, AWS, and GCP. Each path leading to a defined objective, typically administrative access to a system, is documented in full, producing a structured record of exploitable routes through your environment.

04

Cyber Essentials Certification

Structured preparation for Cyber Essentials and Cyber Essentials Plus certification. The NCSC-backed scheme is a requirement across many public sector and supply chain contracts. We conduct a gap assessment against the five technical control areas, provide remediation guidance for identified weaknesses, and carry out a pre-submission review to support first-time certification.

Certified

Our Credentials

PortSwigger
Zero-Point Security
HackTheBox
The Cyber Scheme
INE Security
CompTIA
PortSwigger
Zero-Point Security
HackTheBox
The Cyber Scheme
INE Security
CompTIA

Fees

Engagement Fees

All engagements are priced at a fixed day rate. Indicative fees based on typical engagement duration. A fixed-price quotation follows every scoping discussion.

NCSC Scheme
Cyber Essentials
£800 – £2,500
Per engagement · 1 – 2 weeks

Gap assessment against the five NCSC technical controls, remediation guidance for identified weaknesses, and a pre-submission review for both CE and CE Plus pathways.

Web & API
Web Application & API
£3,300 – £5,500
3 – 5 days · from £1,100 per day

Manual OWASP-aligned testing of web applications and APIs, with a full technical report, executive summary, and risk-rated remediation guidance.

Internal Network
Internal Infrastructure Assessment
£6,000 – £8,400
5 – 7 days · from £1,200 per day

Assessment of services and software within a specified network range, conducted from an unauthenticated or authenticated perspective, with a risk-rated technical report.

Attack Simulation
Attack Path Simulation
£21,000 – £42,000
15 – 30 days · from £1,400 per day

Fully comprehensive assessment of on-premise and cloud infrastructure with all systems in scope. Every attack path leading to administrator-level access is enumerated and documented, covering Azure, AWS, and GCP. Includes post-engagement debrief.

Client Accreditation

Recognised on Completion

Secured By OFFENSE

Clients who complete an engagement receive the official Secured By Offense accreditation badge, confirming that their organisation has undergone independent security assessment. The badge can be displayed publicly and unlocks ongoing client benefits.

Contact

Get in Touch

We offer a no-obligation scoping call for all enquiries. Fill in the details below and we will be in touch shortly.

01 Enquiry Type
02 Scoping Request
03 Engagement Request