// Penetration Testing

Test your systems and know what to fix next

Some security gaps are hard to spot during the normal working day.

Rated 4.9 on Google Reviews   |   Testing, findings and remediation
A Chrome Telecom tester works through security assessment findings on screen alongside a printed report
Sarah from the Chrome Telecom team

Why use Chrome Penetration Testing?

A firewall rule may have been left in place after a supplier change. A web application may have a weakness. Remote access may not be set up as carefully as it should be. A system may also have changed since the last review, without anyone testing what that means.

Penetration testing helps your business check agreed systems by using approved testing methods to look for weaknesses.

Chrome can help you plan the right test, agree the scope, coordinate penetration testing services through approved providers and understand the findings after the report is complete.

The aim is simple: give your business a clearer view of where security needs attention and what should happen next.

Test agreed systems

Penetration testing can look at agreed networks, applications, websites, remote access or other systems within a clear scope.

Understand practical risk

A test can help show whether a weakness could affect the business, not only whether it exists.

Support customer and compliance questions

Some customers, insurers, regulators or frameworks may ask whether testing has been carried out.

Plan useful fixes

A good test should lead to clear findings, priorities and next steps, not just a long technical report.

Sarah from the Chrome Telecom team, supporting penetration testing

What is penetration testing?

Penetration testing, often called pen testing, is an authorised security test of agreed systems.

Testers use tools and techniques that an attacker might use, but they do so with permission, a defined scope and clear rules. The purpose is to find weaknesses so your business can understand and fix them.

A penetration test may look at areas such as external networks, internal networks, firewalls and remote access, web applications, cloud services, wireless networks, specific systems or applications, new services before launch, and systems after a major change.

The exact test depends on your business, the systems involved and why the test is needed.

Penetration testing does not mean trying anything, anywhere, at any time. The scope should be agreed carefully before work begins, so everyone knows what is being tested, when it will happen and what is out of scope.

That planning matters because testing can involve live systems.

Chrome can help you ask the right questions before the work starts and make sense of the results afterwards.

An agreed scope

Everyone knows what is being tested before anything starts.

Real techniques

Testers use the methods an attacker would, but with permission.

Findings you can act on

Weaknesses explained clearly enough to actually fix.

A retest where needed

Confirming the fix worked rather than assuming it did.

Chloe from the Chrome Telecom team, supporting penetration testing

When penetration testing makes sense

Penetration testing can be useful when your business needs more assurance about a system, change or security control.

It may be worth considering when a new website, application or portal is going live, or when remote access has been changed or added. It can also help after major network or firewall changes, or when a customer, insurer or tender asks for evidence of testing.

Some businesses use penetration testing after security improvements have been made, to check agreed areas again. Others need it because they handle sensitive information or want to understand the risk linked to a specific system.

A penetration test should not be treated as a general health check for everything. It works best when the question is clear: what are we testing, what do we need to learn, who needs the report, and what happens if issues are found?

Chrome can help shape the test around those questions, so the work has a useful purpose from the start.

Different questions need different types of test.

External penetration testing looks at systems facing the internet, the view an outside attacker would have. Internal penetration testing looks at what could happen if someone already had a foothold inside your network. Cloud penetration testing focuses on cloud-hosted services and configuration, and web application penetration testing looks specifically at how a website or application handles requests, data and user access.

Many businesses need more than one type, depending on what they are trying to learn.

Chrome can help you work out which combination makes sense for your systems, rather than defaulting to whichever test is easiest to sell.

Penetration testing and vulnerability scanning are related, but they are not the same thing.

A vulnerability scan uses tools to look for known weaknesses, missing updates, exposed services or configuration issues. It can be useful for regular checks and ongoing visibility.

A penetration test goes further by using human judgement to explore whether weaknesses can be used in practice, within the agreed scope and rules.

For example, a scan may show that a service is exposed or a setting looks weak. A penetration tester may then look at whether that issue can be used to gain access, move further or affect the system in a meaningful way.

Both can be useful, but they answer different questions. Chrome can help you understand whether your business needs a vulnerability assessment, a penetration test or both as part of a wider cyber security plan.

A good penetration test starts with a clear scope.

This means agreeing what will be tested, what will not be tested, who needs to know and what limits apply.

The scope may include IP addresses, websites, applications, user accounts, test windows, contact details, the systems your business depends on most and supplier responsibilities. It should also cover practical points such as testing times, expected disruption, emergency contacts, reporting format and how high-risk findings will be handled during the test.

This is especially important when systems are managed by more than one provider.

Your website may be managed by one supplier, Microsoft 365 by another, the firewall by Chrome and a line-of-business application by a software vendor.

Chrome can help coordinate the conversation, so testing does not start with missing information or unclear permissions.

Clear scope keeps the test useful and helps avoid testing systems that should not be touched.

A penetration test report should be useful to more than one person.

Technical teams need enough detail to fix the findings; business owners and managers need a clear summary of the risks, priorities and next steps.

A good report should answer practical questions: what was tested, what was found, how serious are the findings, what could they mean for the business, what should be fixed first, which supplier or team owns each action, and is re-testing needed after fixes are made?

Chrome can help you review the penetration test report and turn the findings into a practical action plan.

Some fixes may be straightforward, such as changing a setting, removing old access or applying an update. Others may need planning, supplier input or a separate project.

The report is not the finish line. It is the point where the work becomes clearer.

Penetration testing is most useful when findings are acted on.

That may mean patching systems, changing firewall rules, updating code, reviewing user access, improving logging, changing supplier settings or replacing unsupported technology.

Chrome can help work through the findings and identify what can be handled through existing support, what needs another supplier and what should become a separate project.

Where re-testing is needed, we can help plan the next step after fixes have been completed.

This is important because a finding is not resolved just because it has been written down. Someone needs to own the action, complete the work and confirm the result.

Chrome can help keep that process clearer, especially when findings touch managed IT, network security, patch management, Microsoft 365, email security or supplier-managed systems.

Penetration testing and wider cyber security

Penetration testing is one part of a wider cyber security setup.

 

It should sit alongside patch management, network security, email security, managed DMARC, password management, cyber security awareness training, backups and user access reviews.

 

For example, a test may find an exposed service that needs a firewall change. It may identify missing updates that link to patch management, or weak access controls that need password management and multi-factor authentication.

 

It may also show where monitoring, logging or supplier ownership needs to be clearer.

 

Chrome can help bring these services together through one team, so your business has a clearer place to start when findings need action.

// Scope to retest

How a test comes together

Here’s how we approach penetration testing, step by step.

1

Understand why you need testing

We'll discuss whether testing is linked to a customer request, tender, compliance question, system change, internal review or wider cyber security plan.
2

Agree the right scope

We'll help define what should be tested, what should stay out of scope and who needs to be involved.
3

Coordinate the testing route

Where agreed, Chrome can help coordinate testing through the right internal team, partner or approved testing provider.
4

Explain the findings

We'll help you understand the report, priorities and practical impact of the findings.
5

Support the next steps

Where the work fits Chrome's services, we can help with fixes, supplier coordination, re-testing plans and wider cyber security improvements.
// Google Reviews

Testing that leads to clearer action

Penetration testing works best when the findings are understood, prioritised and acted on.

Read what customers say about Chrome’s communication, support and the people behind the service in our reviews.

Jake was extremely helpful and even gave good advice through clear communication when the issue was a manual fix on my end. His quick reply’s helped to resolve this matter swiftly. Many thanks to him.

elliott

Thank you so much to Jake at Chrome Telecom Limited for his excellent training and great product.

Claire Bryson

Kallum came today to install and set up our new phone system. He was excellent, talked through everything in laymans terms (which was needed) and went out of his way to leave us with a system that works for us.
We have been with Chrome for 3 years and have always found the service very good with desperate tech calls answered quickly and efficiently. I would highly recommend them

Kriss Morrison Cooper

Mark and Callum installed out new phone and cctv systems at Hilltop Garage Services in Horndean, they were really professional and left our premisies clean and tidy. Excellent job – thank you…

Graham Parish

We can’t thank Jake enough for his outstanding service! As a care home, reliable phone lines and Wi-Fi are absolutely critical for our daily operations. When we were unexpectedly faced with outages, Jake went above and beyond to resolve the issues swiftly and efficiently. His dedication and professionalism ensured that everything was back up and running smoothly, and we couldn’t be more grateful for his help. Highly recommended!

Caroline H

Jake was a massive help after our phone stopped working we could not take any bookings jake was on hand and quickly dialed in from his office and was able to get us back on line in no time at all
fantasitc service

Aaron Ludford

// Penetration Testing FAQ

What to expect from a security test

Common questions we hear from businesses planning a penetration test.

Penetration testing is an authorised security test of agreed systems. Testers use approved methods to look for weaknesses and show how they could affect the business within a defined scope.

No. Vulnerability scanning looks for known weaknesses using tools. Penetration testing usually goes further by using human judgement to test whether weaknesses can be used in practice.

This depends on your business and the agreed scope. Testing may cover external networks, internal networks, web applications, remote access, wireless networks, cloud services or specific systems.

A well-planned test should aim to reduce unnecessary disruption, but testing live systems can carry some risk. That is why the scope, timings, contacts and rules need to be agreed before work starts.

Penetration testing cost depends on the scope, the systems being tested and the type of test needed. We’ll confirm pricing once the scope is agreed.

No. A penetration test gives useful assurance about the systems tested at that point in time. It should sit alongside wider cyber security controls, monitoring, patching, awareness training and regular review.

// Get in touch

Need a clearer view of your security gaps?

Your business may need penetration testing for a customer request, tender, system change or wider cyber security review.

Chrome can help you decide what to test, agree the scope and understand the findings once the report is complete.

You’ll get clear advice on what needs attention and how the results fit into your wider cyber security plan.