Managed Services

Security Testing Services

We validate your defence layers before an attack arrives.

Schedule a simulation review

Security Testing Services

Security testing validates, under controlled conditions, the vulnerabilities on your externally facing surface and the resilience of your defence layers. We run attack simulations within a defined scope and schedule, and report in measurable terms which layer engages and where.

What this service solves

Defence infrastructure is usually left running untested once it is in place. Whether the configuration behaves as intended is only observed during a genuine attack.

Controlled simulation removes that uncertainty. We measure the intensity at which the defence engages, the threshold at which it falls short, and how long detection and response actually take.

Our scope

Attack surface inventory

We map externally facing services and access points, and prioritise scope by criticality.

Controlled DDoS simulation

We run attack scenarios at different intensity levels and across protocols, measuring where each defence layer engages.

Resilience measurement

We assess system behaviour through performance metrics and identify the threshold at which service continuity degrades.

Response process validation

We check that alerting mechanisms and response steps work, and measure detection and response times.

Application layer checks

We test authentication, authorisation and session management controls, and report findings by risk level.

How do we work?

We plan around your release rhythm, manage the operation and improve it in every cycle.

01

Planning

We define scope, test levels and success criteria against your release calendar. Environment and test data requirements are resolved before the work begins.

02

Management

We take on team, tool and environment management. Progress is reported regularly against defined KPIs.

03

Execution

We run the tests and prioritise the findings. We track closure together with your development teams.

04

Improvement

At the end of every cycle we review scope, automation rate and escaped defect rate. The priorities for the next cycle are set from that review.

Virgosol

How technology supports the service

We run DDoS simulations with Ddosphere: five attack intensity levels and the TCP, UDP and ICMP protocols model real-world threats, with measurement taken through BPS, PPS and TPS metrics. Ddosphere can also be purchased on its own; in the service model, scenario design, execution and reporting sit with us.

What you receive

Deliverables

  • An attack surface inventory ranked by criticality
  • Simulation scenarios and execution records
  • A layer-by-layer resilience measurement report
  • Detection and response time indicators
  • A prioritised list of recommended improvements

What changes for the business

  • The effectiveness of the defence configuration is measured rather than assumed
  • Vulnerabilities are found without a real attack having to happen
  • Response processes are rehearsed
  • Evidence is ready for audit and regulatory requests

Frequently Asked Questions

Will the simulation damage our live systems?

Scope, intensity level and timing are agreed in advance. Tests run under controlled conditions with a stop mechanism in place, and no traffic is generated against systems outside scope.

When should the test be carried out?

Before a new system goes live, whenever the defence infrastructure changes and at regular intervals. Running it ahead of peak periods is also recommended.

Does security testing replace penetration testing?

It does not. This service focuses on resilience and defence layer validation. Penetration testing requires a different scope and method, and the two complement each other.

Can we present the results to regulators?

We prepare the reports with traceable records. Scope, method and results are documented in a form suited to audit presentation.

Let us assess your defence resilience together

Complete the form and we will discuss your externally facing services, your critical business flows and your current defence layers.

Cookie preferences