HackingForge Get in touch

Your pentest takes weeks. Attackers strike in hours.

HackingForge is a security partner for companies that want to know where they're exposed and prove they're in control. We test like attackers and build governance that auditors trust.

01Who we are

Most companies buy testing from one firm and compliance from another, then spend months reconciling the two. We do both, so a weakness we find becomes a managed risk instead of a line in a forgotten report.

Our testers are experienced offensive security practitioners. They use AI tooling to cover more ground more often and spend their own time on the problems that need a person: business logic, access control and the gaps between systems.

Our governance team builds management systems that reflect how your company actually works. Policies people follow, risks tied to real assets and evidence that's ready when the auditor asks.

02Services
  1. 01

    Penetration testing

    Human-led testing of your applications and infrastructure, supported by automated verification during the engagement.

    Web · API · Mobile · Cloud · Network
  2. 02

    Tabletop Exercises

    Objective-based exercises that test people, process and technology together and show whether your detection and response hold up.

    Threat-led scenarios · Purple teaming
  3. 03

    Governance, risk & compliance

    Risk assessments, policy frameworks and control design, built to be run by your team rather than kept in a drawer.

    ISMS · Risk register · Vendor risk
  4. 04

    Frameworks & certifications

    From first gap assessment to certification audit and the surveillance audits after.

    ISO/IEC 27001 · 27701 · SOC 2 · Cyber Essentials · NIS2 · PCI DSS
  5. 05

    Virtual CISO

    Senior security leadership, part-time. Strategy, roadmaps, board reporting and a steady hand when something goes wrong.

    Security strategy · Board reporting · Incident readiness
03Platform

The HackingForge Platform

Your security testing in one place. See what's exposed, what's been tested and what still needs fixing, without waiting for next year's report.

Continuous testing

The platform re-tests your applications and infrastructure as they change. New hosts, new releases and configuration drift get looked at in days.

Findings checked by people

Every significant finding is verified by one of our testers before it reaches you. You get fewer, better findings with clear steps to fix them.

Fixes tracked to the end

Assign findings to owners, follow progress and have fixes re-tested automatically. Reports and evidence are ready to share with auditors and your board.

04Governance

Compliance should leave you with a security programme that works, not a folder of documents written for the auditor.

  1. 1

    Gap assessment

    An honest view of where you stand against the standard and what it will take to close the gaps.

  2. 2

    Scope and design

    We agree the boundary of the management system and your statement of applicability.

  3. 3

    Risk assessment

    Risks identified against real assets and owners, with a treatment plan people can act on.

  4. 4

    Controls and policies

    We put the controls in place and fix the technical gaps. Our own testing feeds directly into the evidence.

  5. 5

    Internal audit and review

    We run the internal audit and management review the certification body will expect to see.

  6. 6

    Certification and beyond

    We support you through the Stage 1 and Stage 2 audits with your chosen certification body, then keep things current for surveillance audits.

Frameworks we work with: ISO 27001/SOC 2/ISO 27701/Cyber Essentials/GDPR/NIS2/PCI DSS

05How we work

Evidence over opinion

We report what we can demonstrate. If we can't reproduce it, we don't put it in front of your engineers.

Your scope, strictly

You decide what we touch and when. Every action is logged and nothing destructive is ever part of the plan.

Start small

Plenty of clients begin with one test or one gap assessment. The rest can follow when it makes sense.

06Contact

Tell us what's keeping you up at night.

A test before a launch, an ISO 27001 deadline, or a security programme that needs an owner. Write to us and a specialist will reply within two business days.