SECFORCE logo

SECFORCE

Featured

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

Featured in: Best UK Penetration Testing Companies (2026)

Visit SECFORCE
Founded
2008
Team Size
11-50
Geography
Global
Last verified: Sept 2026

Key facts

  • Holds CREST, CBEST, STAR, ISO 27001, ISO 9001, and Cyber Essentials accreditations.
  • In business since 2008 (Companies House 06488355); CREST-accredited for penetration testing since 2011.
  • CBEST-accredited since 2015; first TIBER engagement in 2018.
  • CREST accreditations: penetration testing, vulnerability assessment and threat-led penetration testing (formerly STAR).
  • Certified to ISO 27001 and ISO 9001, with UK Cyber Essentials and the CREST AI Charter.
  • Offers regulated threat-led testing under CBEST, TBEST, TIBER-EU, iCAST, FEER and CORIE.
  • Back-to-back winners of the DEF CON Red Team CTF in 2021.
  • Published case studies with Cybereason, Nedbank, Gaming Innovation Group, EBA Clearing and Mortgagez.
  • CBEST-approved provider staffed by certified CCRTM and CCRTS consultants.
  • Has delivered over 15 CBEST engagements for UK high street banks, major financial institutions, and other regulated entities.
  • Works with a network of trusted, CBEST-approved threat intelligence partners, and can also work alongside any threat intelligence provider selected by the client or regulator.
  • Runs a manual-first methodology: findings are validated and exploited by hand, not reported from scanner output.
  • Team members speak at DEF CON, Black Hat, and 44CON.
  • Founded in 2008.
  • Headquartered in London, United Kingdom.
  • Team of 11-50 security professionals.
  • Delivers 16 penetration testing services.
  • Typical response time: Proposal within 24 hours of scoping.
  • Operates globally, with delivery across the UK, Europe, APAC, and the Middle East.
  • Specialises in Adversary Simulation, Thick Client Testing, and VDI Breakout.
  • Compliance expertise across ISO 27001, SOC 2, PCI DSS, GDPR, and NIS 2.

About

SECFORCE is a UK offensive security consultancy, in business since 2008, with offices in Richmond, London and Santa Venera, Malta. It specialises in penetration testing and adversary simulation, and calls its approach strategic offensive security: testing shaped by the client's business goals as well as by what attackers are after. Most of its clients are large and enterprise organisations, and financial services is the largest sector in its testing work.

SECFORCE has been CREST-accredited for penetration testing since 2011 and CBEST-accredited since 2015, and ran its first TIBER engagement in 2018. CREST lists its accreditations as penetration testing, vulnerability assessment and threat-led penetration testing (formerly STAR), and its certifications as ISO 27001, ISO 9001, UK Cyber Essentials and the CREST AI Charter. It offers regulated threat-led testing under CBEST, TBEST, TIBER-EU, iCAST, FEER and CORIE.

Its services run from application, infrastructure, cloud, IoT and AI/LLM testing to ransomware readiness, malware resilience and EDR testing, Gold Team crisis exercises, red and purple teaming, and advisory work such as virtual CISO, attack path mapping and compliance readiness for ISO 27001, DORA, NIS2 and the Cyber Resilience Act. The team were back-to-back winners of the DEF CON Red Team CTF in 2021, and it publishes open research, including the LLMGoat series on LLM application security.

Accreditations

CRESTCBESTSTARISO 27001ISO 9001Cyber Essentials

SECFORCE in Depth

Featured

Overview

SECFORCE is a UK offensive security consultancy, in business since 2008, with offices in Richmond, London and Santa Venera, Malta. It specialises in penetration testing and adversary simulation for large and enterprise organisations, and financial services is the largest sector in its testing work.

It has been CREST-accredited for penetration testing since 2011 and CBEST-accredited since 2015, and ran its first TIBER engagement in 2018. CREST lists its accreditations as penetration testing, vulnerability assessment and threat-led penetration testing, and its certifications as ISO 27001, ISO 9001, UK Cyber Essentials and the CREST AI Charter.

Since 2022 it has also run an offensive advisory practice, offering virtual CISO, cybersecurity strategy, attack path mapping and compliance readiness, so that what testing finds feeds into the client's security programme.

Approach

SECFORCE's testing is human-led. Scoping is done by former testers who suggest specific high-value attack scenarios, and assessments follow established methodologies, departing from them only where that gives the client equal or better coverage. Adversary simulation follows MITRE ATT&CK and starts from an assume-breach mindset, testing detection and response at the perimeter and once an attacker is inside the network. Reports carry executive and technical summaries with rated, categorised risks, and come as a PDF, an Excel remediation plan and online reporting, with findings pushed to Jira, GitHub or Bitbucket or through an API. SECFORCE aims to send a full proposal within 24 hours of validating the scope.

What They Test

Application security
Web application, mobile, API and thick-client penetration testing, and source code review.
Deployment security
AI/LLM application testing, IoT testing, cloud and host configuration review, Active Directory review and VDI breakout assessment.
Infrastructure security
External, internal and wireless infrastructure penetration testing.
Incident readiness
Ransomware readiness, malware resilience and EDR testing, Gold Team crisis exercises, stolen laptop review and physical breach simulation.
Adversary simulation
Red team, purple team and phishing exercises, run from an assume-breach mindset and mapped to MITRE ATT&CK.
Regulated threat-led testing
CBEST, TBEST, TIBER-EU, iCAST, FEER and CORIE engagements.
Advisory and compliance
Virtual CISO, cybersecurity strategy, remediation support, attack path mapping, gap analysis and audit readiness for SOC 2, ISO 27001 and 42001, GDPR, DORA, NIS2 and the Cyber Resilience Act.

Working with SECFORCE

What makes SECFORCE suited to financial services testing?
It has been CBEST-accredited since 2015 and has run TIBER engagements since 2018, and financial services is the largest sector in its testing work. Its published case studies include a TIBER-EU red team for EBA Clearing and threat-intelligence-led testing for Nedbank.
Does SECFORCE do conventional penetration testing as well as red teaming?
Yes. Alongside adversary simulation it delivers web application, mobile, API, infrastructure, wireless, cloud, IoT and AI/LLM testing, and source code review.
Where is SECFORCE based and where does it deliver?
Its UK office is in Richmond, London, and it has an EU office in Santa Venera, Malta. CREST lists its coverage as the UK and Europe, and it works on-site, remotely or in a hybrid model.
How quickly can SECFORCE start an engagement?
SECFORCE aims to send a full proposal within 24 hours of validating the scope. Threat-led programmes under CBEST or TIBER-EU need a longer scoping and threat-intelligence phase before testing starts.
What does a SECFORCE engagement typically cost?
Its CREST profile gives the spread: 70% of its penetration testing projects are under £25,000, while 60% of its red team projects fall between £100,000 and £500,000.

Methodologies

OWASPOSSTMMNISTCRESTCBESTTIBER-EUMITRE ATT&CK

Team Activity

Active in CTF competitions
Speaker: DEF CON
Speaker: Black Hat
Speaker: 44CON
Visit SECFORCE