Aberdeen & the North East

Penetration Testing in Aberdeen

Penetration testing for organisations in Aberdeen and across the north east of Scotland, delivered on site by Cyber Scheme and CREST qualified testers. Travel is included in the fixed price. Every engagement includes a free retest.

Overview

JAG Secure is a senior-led penetration testing consultancy headquartered in Edinburgh. We come to Aberdeen as standard: scoping in person where you want it, internal testing on your premises with our own equipment and a debrief in the room with the people who need to hear it. Testing is delivered by consultants holding Cyber Scheme and CREST qualifications, led by a Principal-registered (PriCSP) tester. We test web applications, APIs, external and internal infrastructure, cloud environments, mobile applications and wireless networks.

Working in Aberdeen

Aberdeen is a two and a half hour drive or a short flight from Edinburgh. Either way the cost is ours and the timing is arranged around your change windows. We work across the city, Dyce, Westhill, the Energy Park and the business parks along the A90, as well as Aberdeenshire towns such as Inverurie, Stonehaven and Peterhead. If you would rather not have a consultant on site, or you want an internal test to run between visits, a pre-configured testing device can be shipped to plug into your network instead. External, web application and API testing is delivered remotely.

Why a Scottish Consultancy

Most penetration testing bought in Aberdeen is delivered from England or from the Glasgow offices of national groups. We are a Scottish consultancy. The person who scopes your test is the person who turns up to do it and the person who presents the findings to your board. JAG Secure is a member of ScotlandIS and the Edinburgh Chamber of Commerce and was named a finalist for Cyber Start-up of the Year at the Scottish Cyber Awards 2026.

Who We Test For

Penetration Testing for North East Organisations

Oil, Gas and Energy

Operators, service companies and the supply chain around them run corporate IT alongside operational technology, with contractors, joint ventures and offshore connectivity all needing access. We test the corporate side of that boundary: external perimeters, remote access and VPN, Active Directory, cloud tenancies and the applications that sit between office and field. Where operational networks are in scope, testing is planned around safety cases and change constraints. We agree in writing exactly what will and will not be touched before anything starts.

Universities and Colleges

The University of Aberdeen, Robert Gordon University and North East Scotland College run research networks, student systems and remote access for tens of thousands of users. We have delivered external, internal Active Directory and remote-access VPN testing for Scottish higher education. Engagements are scoped around term dates. Reports are written to satisfy Jisc, funder and audit questions as well as the IT team.

Healthcare and NHS Suppliers

NHS Grampian’s supplier base and the health technology companies serving it hold patient data and must evidence assurance to sell into the NHS. We have tested patient-facing web and mobile applications and the APIs behind them for health technology providers. Testing is scoped to respect clinical safety and patient data handling, with reports written to the assurance questions suppliers actually get asked.

Professional Services

The law firms, accountants, recruiters and consultancies that serve the energy sector hold client funds, contracts and identity documents for a demanding client base. Insurers and corporate clients increasingly ask them to evidence independent testing. We test case management platforms, client portals, Microsoft 365 tenancies and the internal networks behind them. The report is written in language a managing partner can put in front of an insurer or a client’s procurement team.

How It Is Carried Out

How an Engagement Works

Every engagement is scoped and delivered by a senior qualified consultant, not handed to a junior after the contract is signed. You receive a fixed-price proposal within 24 hours of scoping, with Aberdeen travel already included. Testing is mapped to standards such as ISO 27001, Cyber Essentials Plus and PCI DSS. The report is written for both technical teams and leadership. Once you have remediated, we verify your fixes at no extra cost.

At a Glance

01

Scoping & Quote

Tell us what needs testing. Fixed-price proposal within 24 hours, travel included, no hidden extras.

02

Scheduling

On-site anywhere in Aberdeen or the north east, or a shipped testing device if you prefer, arranged around your change windows.

03

Testing

Hands-on testing by qualified consultants, with any critical findings flagged to you immediately.

04

Reporting & Debrief

A clear report for technical teams and leadership alike, with an in-person debrief in Aberdeen.

05

Free Retest

Once you have remediated, we verify your fixes at no extra cost.

You May Also Be Interested In

Penetration Testing Scotland →Penetration Testing Edinburgh →External Infrastructure Testing →Internal Infrastructure Testing →

Frequently Asked Questions

Do you have an office in Aberdeen?

No. JAG Secure is headquartered in Edinburgh and delivers Aberdeen work on site from there. Travel is included in the fixed price, so an Aberdeen engagement costs the same as one in Edinburgh.

Can you test operational technology?

We test the corporate IT side of energy companies as standard: perimeters, remote access, Active Directory, cloud tenancies and the applications between office and field. Where operational technology is in scope we plan around safety cases and change constraints and agree in writing exactly what will and will not be touched.

Can you test offshore or remote sites?

Yes, through a pre-configured testing device that plugs into the site network and reports back to us. It gives the same internal coverage as a consultant on site and avoids the cost of getting one there.

Are you accredited?

JAG Secure delivers testing through consultants holding Cyber Scheme and CREST qualifications, led by a Principal Cyber Security Professional (PriCSP) registered with the UK Cyber Security Council. The company holds Cyber Essentials Plus.