Forefront IT Security Services

UK-based · penetration testing & red team operations

[email protected]
Forefront IT Security ServicesForefront IT Security Services
The proposition

Your Virtual Cyber Security Team

Most organisations have an IT team. Few have a dedicated cyber security capability.

Forefront IT Security Services works alongside your internal IT team or MSP to provide specialist security expertise when you need it.

From penetration testing and offensive security through to vulnerability management, security architecture and long-term security improvement, we give organisations access to senior cyber specialists without having to build the capability internally.

Who we sit alongside

Your IT team or MSP

Microsoft 365, networking, endpoints, backups, cloud, helpdesk. They keep it running.

Forefront

Offensive security, assurance, architecture, vulnerability management, consultancy, certification and red/purple team capability. We keep it secure.

We are not trying to take over your IT. We are the specialist layer above it.

The Security Front Door

You're not buying days. You're buying a secure company.

Every Virtual Security Team plan runs through one Security Front Door. Ask, and it gets done: scoped, scheduled, delivered and retested, all tracked in one place. Days are simply how we plan the work. What you are really buying is the outcome.

Free security chats

Got a question? Ask it. A quick check, a second opinion, "should we be worried about this?". Free, and never taken from your days.

No fuss, no chasing

Request it through the Security Front Door and consider it handled. No new quotes, no procurement cycle, no chasing emails.

Cyber Essentials and CE Plus, sorted

Certification whenever you need it, through a licensed IASME Certification Body, with the assessment fees included. No extra invoice: it simply uses a day or two from your plan for a small business, a little more for larger estates.

Training people remember

Security awareness that beats the 30-minute video. Live, tailored sessions built around your people, your systems and the attacks that actually target you.

Through one front door

Certification and compliance

Cyber Essentials
Cyber Essentials Plus
IASME Cyber Assurance readiness
Security and AI policies
Security questionnaires

Test and assess

Penetration testing
Red and purple teaming
Endpoint testing
Configuration reviews
Microsoft 365 reviews
Cloud testing
Secure code reviews

Find and fix

Attack surface reviews
Detection testing and tuning
System hardening
Retests
Exposure monitoring add-on

Lead and prepare

Virtual CISO
Risk assessments
Architecture reviews
Supplier risk reviews
Incident readiness
Tabletop exercises

AI and apps

AI workflows
AI assistants and agents
Private self-hosted AI
Shadow AI discovery
Security testing for AI apps
Custom web apps and portals

Train and develop

Custom security training
Phishing simulation
IT and MSP team workshops
Security mentoring

The "so what?"

Cloud first does not mean secure

Moving to Microsoft 365 moves the risk. It does not remove it. So we follow the "so what?" the way an attacker would:

1

Endpoint testing

What can somebody do from one compromised laptop?

2

Configuration reviews

Microsoft 365, Entra ID and device management, checked against how attackers actually abuse them.

3

Cloud testing

Somebody gets in through a phishing email or a stolen session. How far can they go, and would you notice?

Buying direct

One plan, one front door, and the peace of mind that your security is covered. No hidden costs, no surprises.

MSPs and IT providers

Same plan, same price, one big difference: spend your days on your own customers and bill them your way. Your client relationship stays yours.

Already a Forefront customer? Sign in to the Security Front Door

The problem

Cyber security shouldn't be a collection of disconnected suppliers

Penetration testing from one supplier. Cyber Essentials from another. Architecture advice from a contractor. Vulnerability scanning from a tool nobody properly reviews. Security advice from somebody else again.

The problem is not the number of suppliers. It is that nobody connects the findings, holds the complete security picture, or drives the improvement between one engagement and the next.

Forefront connects the picture.

How we approach security

Security shouldn't end with a penetration test

A penetration test gives you a point-in-time view. We take it further: identify where you are exposed, prove what can actually be exploited, help you prioritise the improvement, then test whether that improvement held.

UnderstandTestImproveValidateUnderstand

01  Understand

Where are we exposed?

Establish the real security position before producing findings. What exists, what it is connected to, what it is worth and what is already known about it.

Attack Surface Assessment

Vulnerability Management

CTEM

Architecture Review

Cloud Security Review

Threat Context

Security Baseline

02  Test

What can actually be exploited?

Offensive security against the real environment. Weaknesses proven by hand and chained into the paths an attacker would actually take.

Penetration Testing

Red Teaming

Web Application Testing

API Testing

Infrastructure Testing

Cloud Testing

Social Engineering

03  Improve

What should we fix first?

Technical evidence turned into something your team can act on, sequenced by what actually reduces risk rather than by severity label.

Remediation Prioritisation

Security Architecture

Technical Security Advice

Hardening Guidance

Security Roadmaps

Supplier Assurance

Cyber Essentials / CE Plus

04  Validate

Did it actually work?

The improvements tested again, and the controls that should have caught the attack tested against the attack itself.

Retesting

Purple Teaming

Detection Validation

Continuous Validation

Control Validation

AETOS

Why Forefront

We don't just tell you what good security should look like. We test whether it actually works.

Forefront was built from offensive security. Our advice is grounded in how systems are actually attacked, how controls actually fail and how weaknesses are actually exploited, rather than what a framework says should be in place.

That experience is what lets us turn technical evidence into practical security improvement, and then prove the improvement held.

The retained relationship

Cyber expertise without building an internal security team

A security programme with people who already know your environment, rather than a series of disconnected engagements that each start from nothing.

1

Establish the baseline

Your environment, architecture, exposure, existing controls, what has already been tested and what matters most to the business.

2

Build the security roadmap

The baseline becomes a prioritised programme of improvement, sequenced by risk rather than by product cycle.

3

Work alongside your team

Specialist security capability your IT team or MSP can reach directly. The design question, the supplier review, the decision nobody wants to make alone.

4

Review continuously

Posture, vulnerabilities, live projects and emerging threats reviewed on a regular cycle rather than when something goes wrong.

5

Bring in specialist capability

When deeper work is needed, penetration testing, red teaming, CE Plus, architecture, the right Forefront specialists are brought in.

6

Validate the improvement

Changes are retested and validated, so you can show the risk genuinely went down rather than asserting it did.

Ways to work with us

Work with Forefront your way

Not every organisation needs the same relationship. Some have one system to test. Some test constantly. Some want specialists who already understand the estate before the question is asked.

Project

Penetration Test

One assessment, one scope, one price. The right answer when you have a specific system to test or a certification deadline to hit.

  • Fixed scope and fixed price

  • CREST-aligned methodology

  • Board-ready report and technical evidence

  • Remediation guidance included

Call-off

Testing Agreement

Commit to a block of penetration testing days for the year and draw them down as you need them. No re-scoping, no re-procuring, every time.

  • An agreed block of pentest days, on request

  • Preferential day rate

  • Priority in the testing calendar

  • Penetration testing only. Want certification and advice too? That is the Virtual Security Team

Strategic

Partnership

Virtual Security Team

three tiers, from £1,500 / month

A whole security team on tap, not a series of projects. A pool of days for anything, plus the portal, FISS, advisory and a security roadmap, all through one front door.

  • An annual pool of days, usable on anything

  • Ask a security question any time, free

  • Security Front Door portal and FISS assistant

  • Baseline, roadmap and regular reviews

What it costs

A security team, on a monthly agreement

A monthly subscription that includes a set number of consultancy days a year, plus the ongoing Security Front Door service in the always-included column. Days are spent on any of the work listed below, scoped and agreed with you before anything starts. A pool day is a day, whatever the work: adversary simulation draws exactly like everything else.

Team

Virtual Security Team

£1,500

per month

18 days a year

For organisations with no internal security capability who need one they can reach.

  • Days spent on any service, adversary simulation included

  • Top-up days available below your committed rate

  • Managed Exposure (CTEM) via AETOS available as an add-on

  • Unused days carry into the next year, up to 7

Most chosen

Partner

Security Partner

£3,000

per month

40 days a year

For organisations under real compliance or customer pressure, with an active roadmap.

  • Days spent on any service, adversary simulation included

  • A better effective day rate, and cheaper top-ups

  • Reviews every six weeks rather than quarterly

  • Unused days carry into the next year, up to 12

Embedded

Embedded Security Team

£5,000

per month

72 days a year

For organisations where Forefront is effectively the security function.

  • Days spent on any service, adversary simulation included

  • Our best day rate, and the cheapest top-ups

  • Managed Exposure (CTEM) via AETOS included for a small estate

  • Priority response, and up to 18 days carried over

What the days buy

Spend them on work like this

Testing

External and internal infrastructure testing

External attack surface review: what an attacker can see from the internet

Web application and API testing

Secure code review, AI-generated code included

AI and LLM application testing: prompt injection, data leakage and agent abuse

Cloud security assessment (M365 / Azure / AWS)

Microsoft 365 and Entra ID configuration review

Endpoint testing: what one compromised laptop can reach

Mobile application testing

Wireless network assessment

Build and configuration review

Red team and purple team exercises

Physical security assessment

Social engineering and phishing simulation

Detection validation: testing whether your EDR, SIEM or Microsoft Defender actually alerts

Retest of previously reported findings

Advisory and assurance

Virtual CISO (vCISO): security leadership without a full-time hire

Security architecture and design review

Security risk assessment and risk register

Active Directory hygiene review

Firewall and network segmentation review

Third-party and supply-chain risk assessment

M&A and due diligence security input

Cyber Essentials support, and CE Plus preparation and remediation

IASME Cyber Assurance readiness: policies, evidence and gap review

Vulnerability and exposure review and prioritisation

Security policy set review and update

Shadow AI discovery, AI data-leakage risk and AI acceptable-use policy

Incident response plans, playbooks and tabletop exercises

Security roadmap build and quarterly re-plan

Client and supplier security questionnaires

Board and executive security briefings

AI, builds and training

AI workflow automation for a manual process, with guardrails

AI assistants, chatbots and multi-step agents

Private, self-hosted AI, including AI over your own documents (RAG)

AI feasibility review: where to start, and what to leave alone

Custom apps, portals and dashboards built around how you work

Integrations between your systems and your security tools

Security hardening and secure baseline builds

Detection engineering: tuned rules for the gaps testing finds

Custom security awareness training, live and role-specific, including the safe use of AI tools

Hands-on technical workshops for IT and MSP teams

New-starter security induction

Mentoring for staff moving into security roles

No day count is printed against any of it, deliberately. The same cloud review is a different job at a 180-seat tenant and a 5,000-seat multi-geo estate, so we scope each one with you and agree the days before it starts rather than publishing a number that cannot be held.

Always included

Never counted against your days

Security Front Door: request it and it gets done, no chasing

First response within one business day

Free security chats: questions answered, never counted against your days

A named consultant who already knows your environment

A quarterly security review

Priority in the testing calendar

Work starts from your pool: no new quote, no procurement cycle

How the days work

Days are spent on any service in the list, scoped and agreed with you first

Cyber Essentials and CE Plus certification included, assessment fees and all. The assessment uses days from your plan: usually one or two for a micro or small business, more as size and effort grow

A pool day is a day: adversary simulation draws one day per delivery day, exactly like everything else

Adversary simulation does start big - red and purple team from 20 delivery days, physical from 15 - so it needs a Partner or Embedded pool, or top-up days on Team

Run low and you can top up mid-year, at a rate below your committed rate

Unused days carry into the next year, up to your tier limit, then expire

A one-off onboarding baseline of 1 to 2 days, waived when you commit to twelve months

Managed Exposure (CTEM) monitoring via AETOS is a separate monthly subscription, included at Embedded for a small estate (larger estates are quoted)

Incident response itself is separately engaged

The technology layer

Powered by AETOS

Continuous visibility behind your Forefront security team.

A retained relationship is only as good as the context behind it. AETOS is the platform Forefront builds and runs, and it holds that context so the specialists working with you are not rebuilding their understanding of your estate at the start of every engagement.

It does not replace consultants. It is what gives them, and you, continuous context between individual pieces of work.

People + Platform + Process

Not software with a support contract attached.

What it brings together

Assets

Attack surface

Vulnerabilities

Threat intelligence

Testing activity

MITRE ATT&CK mapping

Security validation

Remediation tracking

Engagements

Security reporting

For MSPs and IT providers

Extend your cyber capability without building it internally

You manage the technology. Forefront provides the specialist cyber security capability around it: penetration testing, offensive security, Cyber Essentials and CE Plus, vulnerability management, CTEM, security architecture and technical consultancy.

We can work behind your existing client relationship. It stays yours.

Common questions

Security Front Door, answered

What is the Security Front Door?

It is a monthly subscription that gives you a virtual cyber security team through one point of contact. You get an agreed number of specialist days a year to spend across testing, certification, cloud and Microsoft 365 reviews, AI security, training and advice, and you raise everything through one Security Front Door.

How much does it cost?

Plans start at £1,500 a month, which includes eighteen specialist days a year plus the ongoing Security Front Door service. Larger Partner and Embedded plans add more days for organisations with more to cover. There are no hidden costs: the plan covers the work, scoped and agreed with you before anything starts.

Are Cyber Essentials and Cyber Essentials Plus included?

Yes. Certification is included in every plan and the assessment fees are covered, so there is no separate certification invoice. The assessment itself uses days from your pool, usually one or two for a micro or small business and more as size and effort grow. Certificates are issued by a licensed IASME Certification Body, and a pass can never be guaranteed.

What can the days be used for?

Any service in the plan: penetration testing, red and purple teaming, Cyber Essentials and CE Plus, cloud and Microsoft 365 reviews, endpoint and configuration reviews, AI workflows and AI security, custom apps, training, incident-response readiness and general advice. A pool day is a day whatever the work.

Do you replace our IT team or MSP?

No. We work alongside your IT team or managed service provider as the specialist security layer above the technology they already run. MSPs can also subscribe at the same price and spend their days on their own customers, billing them their own way, with the client relationship staying theirs.

What if we need more days than the plan includes?

You can top up during the year at a rate below your plan day rate, or move to a larger plan. Big pieces of work such as a full red team start at twenty days, so we size those with you and agree them up front rather than letting them quietly drain your pool.

Forefront
UK Penetration Testing & Red Team Operations
Loading...