
UK-based · penetration testing & red team operations
[email protected]Most organisations have an IT team. Few have a dedicated cyber security capability.
Forefront IT Security Services works alongside your internal IT team or MSP to provide specialist security expertise when you need it.
From penetration testing and offensive security through to vulnerability management, security architecture and long-term security improvement, we give organisations access to senior cyber specialists without having to build the capability internally.
Who we sit alongside
Your IT team or MSP
Microsoft 365, networking, endpoints, backups, cloud, helpdesk. They keep it running.
Forefront
Offensive security, assurance, architecture, vulnerability management, consultancy, certification and red/purple team capability. We keep it secure.
We are not trying to take over your IT. We are the specialist layer above it.
The Security Front Door
Every Virtual Security Team plan runs through one Security Front Door. Ask, and it gets done: scoped, scheduled, delivered and retested, all tracked in one place. Days are simply how we plan the work. What you are really buying is the outcome.
Got a question? Ask it. A quick check, a second opinion, "should we be worried about this?". Free, and never taken from your days.
Request it through the Security Front Door and consider it handled. No new quotes, no procurement cycle, no chasing emails.
Certification whenever you need it, through a licensed IASME Certification Body, with the assessment fees included. No extra invoice: it simply uses a day or two from your plan for a small business, a little more for larger estates.
Security awareness that beats the 30-minute video. Live, tailored sessions built around your people, your systems and the attacks that actually target you.
Through one front door
The "so what?"
Moving to Microsoft 365 moves the risk. It does not remove it. So we follow the "so what?" the way an attacker would:
Endpoint testing
What can somebody do from one compromised laptop?
Configuration reviews
Microsoft 365, Entra ID and device management, checked against how attackers actually abuse them.
Cloud testing
Somebody gets in through a phishing email or a stolen session. How far can they go, and would you notice?
One plan, one front door, and the peace of mind that your security is covered. No hidden costs, no surprises.
Same plan, same price, one big difference: spend your days on your own customers and bill them your way. Your client relationship stays yours.
Already a Forefront customer? Sign in to the Security Front Door
Penetration testing from one supplier. Cyber Essentials from another. Architecture advice from a contractor. Vulnerability scanning from a tool nobody properly reviews. Security advice from somebody else again.
The problem is not the number of suppliers. It is that nobody connects the findings, holds the complete security picture, or drives the improvement between one engagement and the next.
Forefront connects the picture.
A penetration test gives you a point-in-time view. We take it further: identify where you are exposed, prove what can actually be exploited, help you prioritise the improvement, then test whether that improvement held.
01 Understand
Establish the real security position before producing findings. What exists, what it is connected to, what it is worth and what is already known about it.
Attack Surface Assessment
Vulnerability Management
CTEM
Architecture Review
Cloud Security Review
Threat Context
Security Baseline
02 Test
Offensive security against the real environment. Weaknesses proven by hand and chained into the paths an attacker would actually take.
Penetration Testing
Red Teaming
Web Application Testing
API Testing
Infrastructure Testing
Cloud Testing
Social Engineering
03 Improve
Technical evidence turned into something your team can act on, sequenced by what actually reduces risk rather than by severity label.
Remediation Prioritisation
Security Architecture
Technical Security Advice
Hardening Guidance
Security Roadmaps
Supplier Assurance
Cyber Essentials / CE Plus
04 Validate
The improvements tested again, and the controls that should have caught the attack tested against the attack itself.
Retesting
Purple Teaming
Detection Validation
Continuous Validation
Control Validation
AETOS
Forefront was built from offensive security. Our advice is grounded in how systems are actually attacked, how controls actually fail and how weaknesses are actually exploited, rather than what a framework says should be in place.
That experience is what lets us turn technical evidence into practical security improvement, and then prove the improvement held.
A security programme with people who already know your environment, rather than a series of disconnected engagements that each start from nothing.
Your environment, architecture, exposure, existing controls, what has already been tested and what matters most to the business.
The baseline becomes a prioritised programme of improvement, sequenced by risk rather than by product cycle.
Specialist security capability your IT team or MSP can reach directly. The design question, the supplier review, the decision nobody wants to make alone.
Posture, vulnerabilities, live projects and emerging threats reviewed on a regular cycle rather than when something goes wrong.
When deeper work is needed, penetration testing, red teaming, CE Plus, architecture, the right Forefront specialists are brought in.
Changes are retested and validated, so you can show the risk genuinely went down rather than asserting it did.
Not every organisation needs the same relationship. Some have one system to test. Some test constantly. Some want specialists who already understand the estate before the question is asked.
Project
One assessment, one scope, one price. The right answer when you have a specific system to test or a certification deadline to hit.
Fixed scope and fixed price
CREST-aligned methodology
Board-ready report and technical evidence
Remediation guidance included
Call-off
Commit to a block of penetration testing days for the year and draw them down as you need them. No re-scoping, no re-procuring, every time.
An agreed block of pentest days, on request
Preferential day rate
Priority in the testing calendar
Penetration testing only. Want certification and advice too? That is the Virtual Security Team
Partnership
three tiers, from £1,500 / month
A whole security team on tap, not a series of projects. A pool of days for anything, plus the portal, FISS, advisory and a security roadmap, all through one front door.
An annual pool of days, usable on anything
Ask a security question any time, free
Security Front Door portal and FISS assistant
Baseline, roadmap and regular reviews
A monthly subscription that includes a set number of consultancy days a year, plus the ongoing Security Front Door service in the always-included column. Days are spent on any of the work listed below, scoped and agreed with you before anything starts. A pool day is a day, whatever the work: adversary simulation draws exactly like everything else.
Team
£1,500
per month
18 days a year
For organisations with no internal security capability who need one they can reach.
Days spent on any service, adversary simulation included
Top-up days available below your committed rate
Managed Exposure (CTEM) via AETOS available as an add-on
Unused days carry into the next year, up to 7
Partner
£3,000
per month
40 days a year
For organisations under real compliance or customer pressure, with an active roadmap.
Days spent on any service, adversary simulation included
A better effective day rate, and cheaper top-ups
Reviews every six weeks rather than quarterly
Unused days carry into the next year, up to 12
Embedded
£5,000
per month
72 days a year
For organisations where Forefront is effectively the security function.
Days spent on any service, adversary simulation included
Our best day rate, and the cheapest top-ups
Managed Exposure (CTEM) via AETOS included for a small estate
Priority response, and up to 18 days carried over
What the days buy
Testing
External and internal infrastructure testing
External attack surface review: what an attacker can see from the internet
Web application and API testing
Secure code review, AI-generated code included
AI and LLM application testing: prompt injection, data leakage and agent abuse
Cloud security assessment (M365 / Azure / AWS)
Microsoft 365 and Entra ID configuration review
Endpoint testing: what one compromised laptop can reach
Mobile application testing
Wireless network assessment
Build and configuration review
Red team and purple team exercises
Physical security assessment
Social engineering and phishing simulation
Detection validation: testing whether your EDR, SIEM or Microsoft Defender actually alerts
Retest of previously reported findings
Advisory and assurance
Virtual CISO (vCISO): security leadership without a full-time hire
Security architecture and design review
Security risk assessment and risk register
Active Directory hygiene review
Firewall and network segmentation review
Third-party and supply-chain risk assessment
M&A and due diligence security input
Cyber Essentials support, and CE Plus preparation and remediation
IASME Cyber Assurance readiness: policies, evidence and gap review
Vulnerability and exposure review and prioritisation
Security policy set review and update
Shadow AI discovery, AI data-leakage risk and AI acceptable-use policy
Incident response plans, playbooks and tabletop exercises
Security roadmap build and quarterly re-plan
Client and supplier security questionnaires
Board and executive security briefings
AI, builds and training
AI workflow automation for a manual process, with guardrails
AI assistants, chatbots and multi-step agents
Private, self-hosted AI, including AI over your own documents (RAG)
AI feasibility review: where to start, and what to leave alone
Custom apps, portals and dashboards built around how you work
Integrations between your systems and your security tools
Security hardening and secure baseline builds
Detection engineering: tuned rules for the gaps testing finds
Custom security awareness training, live and role-specific, including the safe use of AI tools
Hands-on technical workshops for IT and MSP teams
New-starter security induction
Mentoring for staff moving into security roles
No day count is printed against any of it, deliberately. The same cloud review is a different job at a 180-seat tenant and a 5,000-seat multi-geo estate, so we scope each one with you and agree the days before it starts rather than publishing a number that cannot be held.
Always included
Security Front Door: request it and it gets done, no chasing
First response within one business day
Free security chats: questions answered, never counted against your days
A named consultant who already knows your environment
A quarterly security review
Priority in the testing calendar
Work starts from your pool: no new quote, no procurement cycle
How the days work
Days are spent on any service in the list, scoped and agreed with you first
Cyber Essentials and CE Plus certification included, assessment fees and all. The assessment uses days from your plan: usually one or two for a micro or small business, more as size and effort grow
A pool day is a day: adversary simulation draws one day per delivery day, exactly like everything else
Adversary simulation does start big - red and purple team from 20 delivery days, physical from 15 - so it needs a Partner or Embedded pool, or top-up days on Team
Run low and you can top up mid-year, at a rate below your committed rate
Unused days carry into the next year, up to your tier limit, then expire
A one-off onboarding baseline of 1 to 2 days, waived when you commit to twelve months
Managed Exposure (CTEM) monitoring via AETOS is a separate monthly subscription, included at Embedded for a small estate (larger estates are quoted)
Incident response itself is separately engaged
Continuous visibility behind your Forefront security team.
A retained relationship is only as good as the context behind it. AETOS is the platform Forefront builds and runs, and it holds that context so the specialists working with you are not rebuilding their understanding of your estate at the start of every engagement.
It does not replace consultants. It is what gives them, and you, continuous context between individual pieces of work.
People + Platform + Process
Not software with a support contract attached.
What it brings together
Assets
Attack surface
Vulnerabilities
Threat intelligence
Testing activity
MITRE ATT&CK mapping
Security validation
Remediation tracking
Engagements
Security reporting
You manage the technology. Forefront provides the specialist cyber security capability around it: penetration testing, offensive security, Cyber Essentials and CE Plus, vulnerability management, CTEM, security architecture and technical consultancy.
We can work behind your existing client relationship. It stays yours.
It is a monthly subscription that gives you a virtual cyber security team through one point of contact. You get an agreed number of specialist days a year to spend across testing, certification, cloud and Microsoft 365 reviews, AI security, training and advice, and you raise everything through one Security Front Door.
Plans start at £1,500 a month, which includes eighteen specialist days a year plus the ongoing Security Front Door service. Larger Partner and Embedded plans add more days for organisations with more to cover. There are no hidden costs: the plan covers the work, scoped and agreed with you before anything starts.
Yes. Certification is included in every plan and the assessment fees are covered, so there is no separate certification invoice. The assessment itself uses days from your pool, usually one or two for a micro or small business and more as size and effort grow. Certificates are issued by a licensed IASME Certification Body, and a pass can never be guaranteed.
Any service in the plan: penetration testing, red and purple teaming, Cyber Essentials and CE Plus, cloud and Microsoft 365 reviews, endpoint and configuration reviews, AI workflows and AI security, custom apps, training, incident-response readiness and general advice. A pool day is a day whatever the work.
No. We work alongside your IT team or managed service provider as the specialist security layer above the technology they already run. MSPs can also subscribe at the same price and spend their days on their own customers, billing them their own way, with the client relationship staying theirs.
You can top up during the year at a rate below your plan day rate, or move to a larger plan. Big pieces of work such as a full red team start at twenty days, so we size those with you and agree them up front rather than letting them quietly drain your pool.