Frequently asked questions

Scoping, pricing, delivery and reporting — answered plainly.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and prioritises known weaknesses across your estate, largely through authenticated and unauthenticated scanning, validated by a consultant to remove false positives. It answers what is exposed.

A penetration test goes further: a consultant actively attempts to exploit weaknesses, chain them together, and demonstrate real business impact. It answers what an attacker could actually achieve.

Most organisations benefit from regular vulnerability assessment for coverage, and periodic penetration testing for depth. We will tell you honestly which one your situation calls for.

How much does a penetration test cost?

Cost is driven by scope and complexity rather than a fixed price list — the number of hosts, applications, user roles, and the depth of testing required. A small external infrastructure test is a very different exercise to a multi-role web application assessment.

We scope every engagement before quoting, so the figure you receive reflects the work actually required. There are no per-seat licences or tooling surcharges. Fees are set out in the Quote and are exclusive of VAT.

Tell us what you need scoped and we will come back with a written quote.

How long does an engagement take, from scoping to report?

Scoping is typically a single conversation. Testing duration depends on the agreed scope. Reports are delivered after testing completes, following internal quality assurance.

Findings are not held back until the report: anything materially serious is escalated to you during testing, in line with the agreed escalation procedure, so you can begin remediating immediately.

Will testing break our production systems?

Testing is performed using controlled techniques intended to minimise risk, strictly within the agreed scope and rules of engagement. As with any technical assessment, there is an inherent possibility of unintended system behaviour, and we are explicit about that rather than pretending otherwise.

We agree testing windows, escalation contacts, and any excluded techniques before work begins, and we ask that you maintain appropriate backups. Any material issue arising during testing is communicated immediately.

What access and information do you need from us?

That depends on the assessment type. Typically we need an accurate list of in-scope targets, any credentials or test accounts required for authenticated testing, relevant documentation, and named points of contact.

We also need written confirmation that you have authority over the in-scope systems and that any third-party permissions — from hosting providers, for example — have been obtained. This is what makes the testing lawful under the Computer Misuse Act 1990.

What qualifications do your consultants hold?

Nanorisk is a CREST accredited company for penetration testing — an assessment of the organisation itself, covering methodology, data handling, and quality assurance, not just individual qualifications. Engagements are delivered by experienced consultants holding recognised industry certifications from bodies including CREST, Offensive Security, and INE.

Nanorisk also holds Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance Level One and IASME Quality Principles, and is a Crown Commercial Service supplier. Every one of those credentials is independently verifiable — see our accreditations page.

Is a retest included?

Post-assessment support, including retesting where applicable, is part of how we deliver. The specific retest provision for your engagement is defined in the Statement of Work.

Retests can also be requested through the Nanorisk Security Portal against individual findings, so you can verify a fix as soon as it is deployed rather than waiting for a scheduled cycle.

Who owns the report, and how is it delivered?

Reports and deliverables are provided for your internal use unless otherwise agreed. Nanorisk retains ownership of its methodologies, tools, and intellectual property.

Reports are delivered through the Nanorisk Security Portal, where findings are tracked individually with evidence, severity, and remediation guidance, rather than arriving as a static PDF attachment and nothing else.

Do you sign NDAs, and how is our data handled?

Yes. Nanorisk treats all client information accessed or generated during engagements as confidential, and confidentiality obligations survive termination of the contract.

Client data is hosted within the UK and/or European Economic Area, protected by access controls, encryption, and audit logging. Full detail is in our Privacy Notice.

Do you sell security products or certification?

No. Nanorisk does not sell security products, automated tooling outcomes, or certification services. We are an independent assessment consultancy, which means our findings carry no commercial incentive to recommend a particular vendor.

We do provide assessment and preparation support for organisations pursuing Cyber Essentials and Cyber Essentials Plus, but the certification itself is issued by the relevant certification body, not by us.

How do we get started?

Get in touch with an outline of what you need assessed — even a rough one. We will follow up with the scoping questions that matter, then issue a written Quote and Statement of Work.

Once you accept, testing is scheduled around your operational constraints. You can send us the details here or call 0191 369 2434.