Penetration Testing for UK Managed Service Providers and Technology Suppliers
CREST-accredited penetration testing for UK managed service providers, MSSPs, cloud service resellers and IT outsourcing firms. We test the tooling that gives your staff privileged access into every customer you support: the PSA and customer management console, the RMM and remote-access platform, the help desk and ticketing system, and the backup platform. Privileged-access focused.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
customer environments, each with a distinct privileged role in your console, RMM or ticketing platform, is the minimum test setup we ask for to test customer separation properly.
What Your Customers & Their Auditors Expect
Why buyers ask. An MSP’s tooling gives staff privileged, remote access into every customer environment it supports: the PSA console, the RMM platform, the help desk and the backup platform. A single compromised console can reach many customers at once, which is exactly the separation boundary NCSC’s Cloud Security Principle 3 addresses: buyers assessing a cloud or managed service should look for externally audited evidence of regular penetration tests, including red-team and blue-team exercises. Guidance for buyers, not a mandate. NCSC: Cloud Security Principle 3.
Supply-chain due diligence. Customers who hold Cyber Essentials or Cyber Essentials Plus themselves often ask their suppliers, including MSPs, to hold the same certification, and sometimes ask what independent security testing the MSP commissions on its own tooling. Cyber Essentials Plus is an assessor-led technical audit, not a penetration test; the two answer different questions. We are an IASME Cyber Essentials certification body and hold Cyber Essentials Plus ourselves.
UK GDPR Article 32. Where an MSP processes customer data as part of a managed service, Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. It does not name penetration testing as the method, but a test of the systems holding that data is the most direct evidence that your controls work. UK GDPR Article 32.
Who we test for. Managed service providers, MSSPs, cloud and IT outsourcing providers, and technology suppliers whose staff or tooling reach into customer environments. If you run your own SOC or NOC and want a collaborative test where your analysts try to detect us in real time, see our purple teaming page.
SCOPE
What We Test for UK Managed Service Providers
Customer Management Console & PSA
Professional services automation and customer management consoles holding contracts, credentials, tickets and asset inventories for every client you support. Customer-to-customer separation, staff permission boundaries, and what a compromised console account can see or change across your client base.
Remote Monitoring & Management
Remote monitoring and management platforms and the agents installed on customer endpoints. Console authentication, session recording, agent and update integrity, and whether a compromised session or agent can pivot from one customer’s endpoints into another’s network.
Help Desk & Ticketing
Service desk and ticketing platforms handling customer requests, credentials and attachments. Cross-customer ticket visibility, attachment access, staff impersonation resistance, and secrets left in ticket notes or attachments.
Multi-Tenant Microsoft 365 Administration
Delegated administration across client Microsoft 365 tenants. GDAP and partner-centre permissions, mailbox and SharePoint access boundaries between clients, and what a compromised MSP account can reach inside a customer’s tenant.
Entra ID & Conditional Access
Entra ID tenants you administer on behalf of clients. Global Admin and role assignment across tenants, conditional access policy gaps, break-glass account handling, and token or session paths that skip MFA.
Intune-Managed Endpoints
Device management platforms deploying policy, scripts and applications to client fleets. Script and package integrity, device compliance bypass, and whether one client’s device policies or data are reachable from another’s.
Backup & Recovery Platforms
Backup and recovery consoles managing restore points for every customer they protect. Cross-customer restore access, immutability and retention settings, and console authentication that stops a compromised account reaching another client’s backups.
Client Networks & Active Directory
On-site and hosted Active Directory environments you administer for clients. Privileged access paths, service account permissions, and segregation between your management tooling and the client’s own network.
Red Team
Multi-week assume-breach engagements modelled on ransomware actors who target MSPs specifically to reach many downstream customers through one compromise. Spear phishing, persistent access, privileged pivoting across your management tooling.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute technical scoping call. Map your customer environments, privileged consoles and remote-access tooling in scope, plus rules of engagement and timeline. Fixed-price quote within 24 hours.
Test Environment
You provide access to a designated test tenant, staging console, or a small number of representative customer environments. We agree in writing what stays out of scope before testing starts.
Active Testing
3-15 days of hands-on testing by CREST-certified pen testers, crossing customer, role and console boundaries. Daily status updates and live findings in your client portal.
Report & Retest
CVSS-scored report with reproduction steps and remediation guidance, a 60-minute walkthrough call, free retest, and a letter of attestation for customers and auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST MSP pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.
Cyber Essentials Plus
An assessor-led technical audit, not a penetration test. Certified directly by us as an IASME certification body, and often asked for as supply-chain evidence by customers who hold it themselves.
ISO 27001
Annex A 8.8 technical vulnerability management, once you declare that control applicable.
UK GDPR
Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures over the customer data you process.
SOC 2
Evidence for the evaluations your auditor reviews under CC4.1, where your MSSP or cloud services contract asks for one.
NCSC Cloud Security Principles
Externally audited evidence customers look for under Principle 3 when assessing a managed or cloud service.
Customer Questionnaires
An independent report you can attach to customer and prospect security questionnaires and supplier due-diligence reviews.
PRICING
Indicative Engagement Pricing
Fixed-price quotes confirmed during scoping. Free retest, executive summary, walkthrough call, and letter of attestation included.
Depends on service + scope
External / web / API / mobile single-target engagement. CREST-certified delivery. Around 3 to 5 working days from kickoff to report.
Get a fixed quoteDepends on service + scope
Multi-target combined engagement (web + API + external + AD), or single complex target. Typically 7-10 days.
Get a fixed quoteDepends on service + scope
Full-stack engagement (multiple cloud accounts, hybrid AD, complex web + API + mobile). Typically 12-15+ days.
Get a fixed quoteWHY EJN LABS
What You Get From MSP Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What does a penetration test check on an MSP that our own monitoring wouldn’t catch?
Manual, adversarial testing of the paths an attacker would actually use: whether one customer’s console session can reach another customer’s data, whether a support script or impersonation attempt can trick your help desk, and whether a compromised endpoint agent can pivot into a client network. Monitoring tells you what happened; testing tells you what is possible before it does.
Do you test our RMM and remote-access tooling, or only the networks our engineers reach through it?
Both. We test the RMM or remote-access platform itself, including authentication, session recording and customer separation, and what a compromised session or agent can reach inside a client network, using a test tenant or a client-supplied lab environment.
Can you test delegated admin (GDAP) access across our Microsoft 365 client tenants?
Yes. We test how Global Admin and other delegated roles are granted and revoked across client tenants, conditional access and break-glass account configuration, and whether a compromised staff account in your tenant can reach a client’s mailboxes, SharePoint or Teams data.
Can you test whether someone impersonating a customer can get our service desk to reset a password or share access?
Yes. Help desk and ticketing tests include social-engineering attempts against your support staff: impersonating a customer’s employee to request a password reset, MFA re-enrolment or remote-access session, and checking whether tickets, attachments or notes from one customer are visible to another.
We manage Microsoft 365 for several clients under delegated admin and need Cyber Essentials Plus supply-chain evidence for one of them. Can one engagement cover both?
Often, yes. We scope one engagement across your M365 delegated admin relationships and the specific systems your client’s Cyber Essentials Plus assessor wants evidenced, and write the report so the technical findings and the supply-chain evidence are both clear. Cyber Essentials Plus itself is a separate assessor-led audit, which we can also arrange as an IASME certification body, but it’s scoped and delivered apart from the penetration test.
Do you test our backup platform, or just production systems?
Yes, when it’s in scope. Backup and recovery consoles such as Veeam hold restore access across every customer they protect, so we test console authentication, cross-customer restore boundaries and the immutability settings that stop ransomware reaching your backups too.
Can our own SOC or NOC team try to detect you in real time during testing?
Yes. Our red team and purple teaming engagements can run collaboratively with your analysts watching for detection and response, rather than as a blind assume-breach test. Useful if you run a NOC or SOC for your customers and want to test your own detection capability at the same time.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my MSP pen test scope
A CREST-certified pen tester will contact you within one business day with a fixed price aligned to what your customers and their auditors expect from an MSP with privileged access into their environment.



