Scotland

Penetration Testing in Scotland

Penetration testing for organisations anywhere in Scotland, delivered by Cyber Scheme and CREST qualified testers from a consultancy based in Edinburgh. We travel to any site in Scotland. Every engagement includes a free retest.

Overview

JAG Secure is a senior-led penetration testing consultancy headquartered in Edinburgh and working across the whole of Scotland. Testing is delivered by consultants holding Cyber Scheme and CREST qualifications, led by a Principal-registered (PriCSP) tester. We test web applications, APIs, external and internal infrastructure, cloud environments, mobile applications and wireless networks. The reports are written so that a board can read them and an engineer can act on them.

Where We Work

We travel anywhere in Scotland. Edinburgh, Glasgow, Stirling, Fife and the Lothians are on the doorstep for in-person scoping, on-site internal testing and debriefs. Aberdeen, Dundee, Inverness and the islands are all places we will come to; travel is built into the fixed price rather than added as a surprise. If you would rather not have a consultant on site, or you want the internal test to run between visits, we can also ship a pre-configured testing device that plugs into your network and gives the same coverage remotely. External, web application and API testing is delivered remotely wherever you are.

Why a Scottish Consultancy

Most penetration testing sold in Scotland is delivered from England. We are based here, which means the person who scopes your test is the person who turns up to do it and the person who presents the findings to your board. JAG Secure is a member of ScotlandIS and the Edinburgh Chamber of Commerce and was named a finalist for Cyber Start-up of the Year at the Scottish Cyber Awards 2026.

Who We Test For

Penetration Testing for Scottish Organisations

Universities and Colleges

Scottish universities run some of the most complex estates in the country: research networks, student systems, VPN and remote access for thousands of users and a long tail of departmental applications. We have delivered external, internal Active Directory and remote-access VPN testing for Scottish higher education. We understand Jisc, UCISA and the assurance questions that funders and partners ask.

Law Firms

Scottish law firms hold client funds, privileged correspondence and identity documents. Insurers and corporate clients increasingly ask them to evidence independent testing. We test case management platforms, client portals, Microsoft 365 tenancies and the internal networks that connect them. The report is written in language a managing partner can put in front of the Law Society or an insurer.

Oil, Gas and Energy

Aberdeen and the north east operate corporate IT alongside operational technology, with contractors, joint ventures and supply chains all needing access. We test the corporate side of that boundary: external perimeters, remote access, Active Directory and the applications that sit between the office and the field. Where operational networks are in scope, testing is planned around change windows and safety constraints rather than forced through them.

Schools and Local Authorities

Schools, independent schools and council education services hold data about children and are regularly targeted by phishing and ransomware. We test the systems that matter most in that setting, including management information systems, parent portals, Microsoft 365 and Google Workspace configurations, remote access and the internal network. Scoping is arranged to fit term times and tight budgets.

How It Is Carried Out

How an Engagement Works

Every engagement is scoped and delivered by a senior qualified consultant, not handed to a junior after the contract is signed. You receive a fixed-price proposal within 24 hours of scoping. Testing is mapped to standards such as ISO 27001, Cyber Essentials Plus and PCI DSS. The report is written for both technical teams and leadership. Once you have remediated, we verify your fixes at no extra cost.

At a Glance

01

Scoping & Quote

Tell us what needs testing. Fixed-price proposal within 24 hours, no hidden extras.

02

Scheduling

On-site anywhere in Scotland, or a shipped testing device if you prefer, arranged around your change windows.

03

Testing

Hands-on testing by qualified consultants, with any critical findings flagged to you immediately.

04

Reporting & Debrief

A clear report for technical teams and leadership alike, with an in-person debrief available across Scotland.

05

Free Retest

Once you have remediated, we verify your fixes at no extra cost.

You May Also Be Interested In

Penetration Testing Edinburgh →Penetration Testing Glasgow →Penetration Testing Aberdeen →Internal Infrastructure Testing →Web Application Testing →Cloud Security Assessments →

Frequently Asked Questions

Do you travel anywhere in Scotland?

Yes. We will come to any site in Scotland, from the Borders to the Northern Isles, with travel included in the fixed price. Any client who prefers it can have a pre-configured testing device shipped to plug into their network instead, which gives the same internal coverage without a consultant on site.

Can you test a university or college network?

Yes. We have delivered external infrastructure, internal Active Directory and remote-access VPN testing for Scottish higher education. Engagements are scoped around term dates and change freezes. Reports are written to satisfy Jisc, funder and audit questions as well as your own IT team.

Do you work with Aberdeen oil and gas companies?

We test the corporate IT side of energy companies: external perimeters, remote access, Active Directory, cloud tenancies and the applications between office and field. Where operational technology is in scope we plan testing around safety and change constraints and agree exactly what will and will not be touched.

Are you accredited?

JAG Secure delivers testing through consultants holding Cyber Scheme and CREST qualifications, led by a Principal Cyber Security Professional (PriCSP) registered with the UK Cyber Security Council. The company holds Cyber Essentials Plus.