Vulnerability assessment and penetration testing.

A vulnerability assessment finds the weak points in your network and web applications and ranks them by severity. A penetration test actively tries to use them to show what an attacker could reach. Vulnerability assessments start at £800 a year and penetration tests at £1,200, excluding VAT.

From £800

a year for a vulnerability assessment, four tests with a report after each. Penetration tests from £1,200. Ex VAT.

What is the difference between the two?

Think of your IT as a house. A vulnerability assessment is like hiring an inspector to check your doors, windows and locks for weaknesses. It looks for missing patches, out-of-date systems and software, and open and exposed ports, and gives you a report ranked by severity with recommended fixes. It does not use the weaknesses it finds.

A penetration test is like hiring a professional to break into your house, as a burglar would. It uses the same tools and techniques as real attackers, in a controlled way, to see whether they could get in, what data they could reach and what they could compromise, then reports how they got in and how to stop it.

What does a vulnerability assessment cost?

An annual service with four quarterly tests and a report after each one.

Vulnerability assessment prices
ScopeCoversPrice a year, ex VAT
ExternalUp to 10 IP addresses: servers and firewalls£800
InternalUp to 100 IP addresses: systems, operating systems and servers£800
Web applicationUp to 5 URL addresses: websites and portals£1,200

There is also a one-off onboarding fee of £500 ex VAT: an initial consultation and setting up the access we need.

What does a penetration test cost?

A one-off project of around two months, including a retest and final report once you have fixed what we found.

Penetration testing prices
ScopeCoversPrice, ex VAT
ExternalUp to 10 IP addresses: servers and firewalls£1,200
Extra external addressesEach additional IP address£120 each
Web applicationUp to 5 URL addresses£2,200
Email social engineeringA simulated email campaign aimed at your people£1,200

There is also a one-off onboarding fee of £500 ex VAT.

How does a penetration test work?

The same sequence an attacker would follow, under your control.

  1. Step 1ScopingWe agree the IP addresses, hosts and web properties to test.
  2. Step 2Breach data and open-source researchWe check whether your company’s data is already exposed in breach databases and public sources.
  3. Step 3Reconnaissance and scanningAutomated and manual scans map what is reachable, including web applications.
  4. Step 4Manual verificationA person confirms each potential issue, for example a way around multi-factor authentication or credential spraying.
  5. Step 5Assumed breachWhere agreed, we start from low-privileged internal access to see how far an intruder could get.
  6. Step 6Report and retestYou get a report of the issues with ways to reduce them, and a retest after you have fixed them.

What you should know before you buy

These services find problems and explain them. Fixing them, such as patching or reconfiguring systems, is separate work that we can quote.

Lanmark works with trusted third-party companies to deliver this testing. Prices are for the scopes shown, and larger scopes are quoted. All prices exclude VAT.

Cyber security services

What do people ask about security testing?

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment looks for weak points and reports them by severity, like a house inspection. A penetration test goes a step further and actively tries to use those weaknesses to show what an attacker could reach, like a simulated break-in.

How often should we test?

Vulnerability assessments are not one-off. Ours run four times a year, with a report after each one. Penetration tests are periodic projects, usually after major changes or on a regular cycle.

Who carries out the testing?

Lanmark works with trusted third-party testing companies to deliver these services. We scope the work, manage it and explain the results.

Do you fix what you find?

The reports tell you what to fix and how. Fixing is separate work, which we can quote. For a penetration test, a retest checks the fixes and gives you a final report.

Is a vulnerability assessment included in Lanmark Total?

Lanmark Total includes vulnerability assessments every quarter, covering your firewalls, websites and devices, with a report after each one. The standalone services on this page are for businesses on other plans, or who want penetration testing.

Where to go next

Book a free IT review.

We look at what you have, what it costs and where the risks are, and tell you plainly if you do not need to change anything.

Book a free IT review