Example design concept -- not a live client site. Built to demonstrate WebHostGB's tech & innovative style.
IRONVAULT

// services

Priced before we start, not after.

Every engagement is fixed price from the scoping call. If the scope changes we tell you before doing the work, not on the invoice.

01PENETRATION TESTING

Manual testing, by people

Automated scanning finds the findings everybody already knows about. The vulnerabilities that actually get organisations compromised are chained together by hand, which is how we test.

  • External infrastructure and perimeter
  • Internal network and Active Directory
  • Web and mobile application testing
  • Cloud configuration review (AWS, Azure, GCP)
  • Free retest of remediated findings within eight weeks
From£4,800

Typical two-week engagement for a mid-sized external and internal test, including report and readout.

02INCIDENT RESPONSE

When it has already happened

Containment first, forensics second, and a written timeline you can give to your insurer and the ICO. We work alongside your IT team rather than taking over from them.

  • Four-hour response SLA for retained clients
  • Containment and eradication support
  • Forensic imaging and timeline reconstruction
  • ICO notification support within the 72-hour window
  • Post-incident review and hardening plan
Retainer from£1,800/mo

Includes out-of-hours cover, a named responder and one annual test. Ad-hoc response charged at day rate.

03CYBER ESSENTIALS

Certification, including the fixing

Most providers send a questionnaire and mark it. We do the remediation work with you first, so the certificate reflects something that is actually true.

  • Cyber Essentials and Cyber Essentials Plus
  • Gap analysis before submission
  • Remediation support included in the fee
  • Annual renewal reminders and re-testing
From£1,400

Cyber Essentials Plus including gap analysis, remediation support and certification body fees.

A consultant working at a laptop in a focused workspace

// honest answer

Sometimes the answer is not to buy a test

If you have no asset inventory, no MFA and no backups you have tested restoring from, a penetration test will simply produce a long document confirming that. We will tell you to spend the money on those three things first and come back next year.

It costs us an engagement and saves you one, which over a decade has turned out to be a reasonable trade.

Book a scoping call