
SECFORCE
FeaturedUK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.
Featured in: Best UK Penetration Testing Companies (2026)
Visit SECFORCEKey facts
- Holds CREST, CBEST, STAR, ISO 27001, ISO 9001, and Cyber Essentials accreditations.
- In business since 2008 (Companies House 06488355); CREST-accredited for penetration testing since 2011.
- CBEST-accredited since 2015; first TIBER engagement in 2018.
- CREST accreditations: penetration testing, vulnerability assessment and threat-led penetration testing (formerly STAR).
- Certified to ISO 27001 and ISO 9001, with UK Cyber Essentials and the CREST AI Charter.
- Offers regulated threat-led testing under CBEST, TBEST, TIBER-EU, iCAST, FEER and CORIE.
- Back-to-back winners of the DEF CON Red Team CTF in 2021.
- Published case studies with Cybereason, Nedbank, Gaming Innovation Group, EBA Clearing and Mortgagez.
- CBEST-approved provider staffed by certified CCRTM and CCRTS consultants.
- Has delivered over 15 CBEST engagements for UK high street banks, major financial institutions, and other regulated entities.
- Works with a network of trusted, CBEST-approved threat intelligence partners, and can also work alongside any threat intelligence provider selected by the client or regulator.
- Runs a manual-first methodology: findings are validated and exploited by hand, not reported from scanner output.
- Team members speak at DEF CON, Black Hat, and 44CON.
- Founded in 2008.
- Headquartered in London, United Kingdom.
- Team of 11-50 security professionals.
- Delivers 16 penetration testing services.
- Typical response time: Proposal within 24 hours of scoping.
- Operates globally, with delivery across the UK, Europe, APAC, and the Middle East.
- Specialises in Adversary Simulation, Thick Client Testing, and VDI Breakout.
- Compliance expertise across ISO 27001, SOC 2, PCI DSS, GDPR, and NIS 2.
About
SECFORCE is a UK offensive security consultancy, in business since 2008, with offices in Richmond, London and Santa Venera, Malta. It specialises in penetration testing and adversary simulation, and calls its approach strategic offensive security: testing shaped by the client's business goals as well as by what attackers are after. Most of its clients are large and enterprise organisations, and financial services is the largest sector in its testing work.
SECFORCE has been CREST-accredited for penetration testing since 2011 and CBEST-accredited since 2015, and ran its first TIBER engagement in 2018. CREST lists its accreditations as penetration testing, vulnerability assessment and threat-led penetration testing (formerly STAR), and its certifications as ISO 27001, ISO 9001, UK Cyber Essentials and the CREST AI Charter. It offers regulated threat-led testing under CBEST, TBEST, TIBER-EU, iCAST, FEER and CORIE.
Its services run from application, infrastructure, cloud, IoT and AI/LLM testing to ransomware readiness, malware resilience and EDR testing, Gold Team crisis exercises, red and purple teaming, and advisory work such as virtual CISO, attack path mapping and compliance readiness for ISO 27001, DORA, NIS2 and the Cyber Resilience Act. The team were back-to-back winners of the DEF CON Red Team CTF in 2021, and it publishes open research, including the LLMGoat series on LLM application security.
Accreditations
SECFORCE in Depth
FeaturedOverview
SECFORCE is a UK offensive security consultancy, in business since 2008, with offices in Richmond, London and Santa Venera, Malta. It specialises in penetration testing and adversary simulation for large and enterprise organisations, and financial services is the largest sector in its testing work.
It has been CREST-accredited for penetration testing since 2011 and CBEST-accredited since 2015, and ran its first TIBER engagement in 2018. CREST lists its accreditations as penetration testing, vulnerability assessment and threat-led penetration testing, and its certifications as ISO 27001, ISO 9001, UK Cyber Essentials and the CREST AI Charter.
Since 2022 it has also run an offensive advisory practice, offering virtual CISO, cybersecurity strategy, attack path mapping and compliance readiness, so that what testing finds feeds into the client's security programme.
Approach
SECFORCE's testing is human-led. Scoping is done by former testers who suggest specific high-value attack scenarios, and assessments follow established methodologies, departing from them only where that gives the client equal or better coverage. Adversary simulation follows MITRE ATT&CK and starts from an assume-breach mindset, testing detection and response at the perimeter and once an attacker is inside the network. Reports carry executive and technical summaries with rated, categorised risks, and come as a PDF, an Excel remediation plan and online reporting, with findings pushed to Jira, GitHub or Bitbucket or through an API. SECFORCE aims to send a full proposal within 24 hours of validating the scope.