Solusec Review: Penetration Testing
Cyber insurers now routinely ask smaller organisations for evidence of penetration testing before they'll even quote a premium. That single requirement has pushed a lot of businesses, charities and schools into a market they don't understand, full of firms whose "testing" amounts to running a vulnerability scanner and printing the results. Knowing who's actually doing manual, accredited work versus who's reselling automated output matters more than most buyers realise until they're staring at a report full of generic findings.
Solusec is a West Midlands-based provider offering CREST-accredited penetration testing, Cyber Essentials certification and incident response to businesses, charities and schools across the UK. Founded in 2021, the company has built its credentials around third-party accreditation rather than self-description, which is worth unpacking before deciding whether it fits your organisation.
What is Solusec?
Solusec is a cybersecurity services company, not a general IT consultancy that has bolted security onto its offering. Its three stated services, penetration testing, Cyber Essentials and incident response, cover the assessment, certification and crisis-response stages an organisation typically needs when it takes security seriously.
The accreditation angle matters here. CREST is the industry body that vets penetration testing firms in the UK and its accreditation is one of the few external checks a buyer can actually verify rather than take on faith. Solusec holds CREST-accredited penetration testing provider status alongside Cyber Essentials certification and IASME Cyber Assurance and Quality Principles certifications, which sit on top of the CREST badge rather than replacing it.
The consultant-direct model
Plenty of firms in this space route every client through account managers before you ever speak to someone technical. Solusec runs differently.
There's no sales layer sitting between the client and the person conducting the test and no scare tactics or upselling once an engagement is underway. That's a structural choice, not a marketing line and it changes what a conversation with the company actually looks like. Instead of a pitch, you get a scoping call with someone who will be doing the work.
The consultants behind the testing have published CVEs and a track record of responsible disclosure, which means their day job includes finding vulnerabilities in software used well beyond any single client's network. That's a different skillset from a technician running a preset scan and copying the output into a template. It also explains, at least in part, why the individual testers hold Synack Red Team recognitions including Acropolis 2022, Envoy, Hero, Olympian and Circle of Trust, badges awarded within Synack's crowdsourced testing programme rather than issued by Solusec itself.
How an engagement actually runs
A penetration test with a CREST-accredited provider generally follows a recognisable shape and Solusec's fits that pattern:
- Scoping. You define the systems, applications or networks in play and agree what's in and out of bounds.
- Testing. Consultants manually probe for exploitable weaknesses rather than relying solely on automated tooling, which is the part that separates real penetration testing from a scan with a report wrapped around it.
- Reporting. Findings come back ranked by severity and exploitability, with enough technical detail for your own IT team or developers to act on them.
- Retesting or follow-up. Once fixes are in place, a retest confirms the vulnerabilities were actually closed.
If a breach or suspected compromise happens outside that planned cycle, incident response is the separate service that kicks in, covering containment and recovery rather than scheduled assessment work. For a broader sense of where testing fits into a security programme, opsmatters has a longer explainer on understanding pentesting services and their role in cybersecurity.
Cyber Essentials as a separate track
Not every organisation needs a full penetration test straight away. Cyber Essentials is the UK government-backed scheme that checks basic technical controls, firewalls, secure configuration, access control, malware protection and patch management and Solusec offers certification against it alongside its testing work. For a charity or school with a smaller attack surface, Cyber Essentials is often the more proportionate starting point, with penetration testing following once the fundamentals are in place. Many organisations that later commission testing do so because a client or insurer specifically asked for it, a pattern covered in more detail in this piece on the benefits of managed cyber security services.
Strengths
CREST accreditation you can independently check. Rather than taking a claim of "expert testers" at face value, a buyer can verify CREST status through the accreditation body itself, which removes a lot of the guesswork common in this market.
Direct technical access throughout the engagement. Questions about a finding go to the person who found it, not a project manager relaying messages, which tends to speed up remediation.
A three-stage security offering. Testing, certification and incident response cover assessment, compliance and crisis response under one provider, which can simplify vendor management for smaller organisations that don't want three separate contracts.
Named individual recognition. The Synack Red Team badges held by Solusec's consultants are earned through invitation-only crowdsourced testing, a detail that says more about individual skill than a generic "expert team" claim would.
Where it may not fit
No provider suits every organisation and a few honest trade-offs are worth naming.
The West Midlands and UK focus means organisations outside the UK looking for a local presence elsewhere won't find that here, though the stated service area does cover the whole of the UK. Direct-to-consultant working suits businesses that already have some technical understanding of their own systems and want to talk shop. Organisations that prefer a heavily managed, account-manager-led relationship with regular check-in calls may find the leaner model less comfortable, even though it's the same trait that keeps conversations focused on findings rather than sales. And because the three services are distinct rather than bundled into a single flat package, an organisation needing all three—testing, certification and incident readiness—will be coordinating more than one scope of work, even if it's with a single provider.
Who Solusec Is Best For
The fit is clearest for businesses, charities and schools that need to demonstrate security due diligence, whether that's for a client requirement, an insurance renewal or a board-level compliance push and that want technical conversations rather than a sales cycle. It also suits organisations that value being able to check a provider's accreditation independently rather than relying on marketing copy. Organisations wanting a single all-in-one managed security contract with a dedicated account manager, or those outside the UK, are likely better served elsewhere.
The Verdict
Solusec's case rests on things a buyer can actually verify: CREST accreditation, Cyber Essentials and IASME certifications and consultants with a public track record in vulnerability disclosure and crowdsourced testing. That combination, paired with direct access to the people doing the work, is a genuine point of difference in a market where plenty of providers lean on vague claims of expertise. For a business, charity or school in the UK weighing up a first penetration test or a Cyber Essentials certification, it's a credible option worth putting on the shortlist alongside any other CREST-accredited firm you're considering.