Penetration testing, threat intelligence, SOC operations, and security awareness — real-world capability backed by active research and MSc-level expertise.
Our Cybersecurity division delivers offensive and defensive security services grounded in active research, MSc-level academic training, and hands-on lab experience across Kali Linux, Metasploitable, and custom-built tooling. We help SMEs and enterprises understand their risk and reduce it.
Web, network, and infrastructure penetration testing using industry-standard methodology and tooling.
View serviceSystematic scanning and analysis using Nmap, Nikto, and OpenVAS to enumerate and prioritise vulnerabilities.
View serviceIP reputation, geolocation, and threat context powered by our Netra platform integrating AbuseIPDB and live threat feeds.
View serviceSecurity monitoring and detection for SMEs, plus staff awareness training and phishing simulation programmes.
View serviceSelf-assessment tools built to NCSC, ICO, CSRB, and NCSC supply-chain frameworks. Free to use — built and maintained by Quatech.
31-question self-assessment covering all 5 NCSC Cyber Essentials controls. Returns PASS / AT_RISK / FAIL with a downloadable branded report.
Try live ↗27-question breach severity assessment. Returns LOW–CRITICAL severity with ICO 72-hour notification recommendation and a pre-filled Article 33 letter.
Try live ↗UK Cyber Security & Resilience Bill classification tool. 17 questions across 9 regulated sectors — classifies to REPORT_24H, REPORT_72H, MONITOR, or NEAR_MISS.
Try live ↗Offline TOTP authenticator. PIN-encrypted vault, QR code scanning, 30-second countdown. No account, no tracking — installs to your phone home screen.
Try live ↗Authorised, methodical attacks on your systems to find what real attackers would — before they do. Web, network, and infrastructure scopes available.
Quatech's penetration testers apply a structured, PTES-aligned methodology to simulate the tactics, techniques, and procedures of real-world attackers. Our testing spans web application, external network, internal network, and wireless infrastructure scopes.
Our capability is grounded in active MSc Cybersecurity study including CO7042 penetration testing, hands-on Kali Linux and Metasploitable labs, and the 23-project CyberLab GitHub portfolio. We use industry-standard tooling: Nmap, Metasploit, Burp Suite, Hydra, and Nikto.
Every engagement concludes with a plain-English report: an executive summary for leadership, a full technical finding set for your IT team, and a prioritised remediation plan with CVSS-rated risk scores.
Web application penetration testing (OWASP Top 10 coverage)
External and internal network penetration testing
Wireless network security testing
CVSS-rated findings with executive and technical reports
Remediation guidance and re-test included
Written Rules of Engagement before every engagement
We define authorised targets, test windows, emergency contacts, and exclusions in a signed Rules of Engagement document. No testing begins without written authorisation.
Passive and active information gathering: OSINT, DNS enumeration, WHOIS, port scanning, service fingerprinting, and technology stack identification.
Systematic identification of vulnerabilities through automated scanning (Nmap, Nikto, OpenVAS) and manual verification to eliminate false positives.
Safe, controlled exploitation of confirmed vulnerabilities to demonstrate real-world impact. Metasploit, custom scripts, and manual techniques are applied as appropriate.
Where scope permits, we demonstrate lateral movement, privilege escalation, and data access to show the full chain of compromise an attacker could achieve.
A full report is delivered: executive summary, technical findings with evidence, CVSS scores, and a prioritised remediation plan. A debrief call is included.
Penetration testing methodology grounded in CO7042 coursework at the University of Liverpool (Russell Group).
IN PROGRESSCertified Ethical Hacker and eLearnSecurity Junior Penetration Tester certifications targeted for all pentest team members.
TARGETEDAll engagements follow the Penetration Testing Execution Standard for consistency and completeness.
STANDARDWeb application testing covers the full OWASP Top 10 and OWASP Testing Guide methodology.
STANDARDDescribe your target environment and the scope you need tested. We'll come back with a scoped proposal and written Rules of Engagement within one business day.
Submit your target details and preferred test scope
We issue a scoped proposal and Rules of Engagement for sign-off
Testing is conducted and a full report delivered within the agreed timeline
Our penetration testing team will review your scope and respond within one business day.
Systematic discovery and prioritisation of security weaknesses across your infrastructure — giving you a clear, actionable risk picture.
A vulnerability assessment is the essential first step in any security programme. Quatech uses a combination of automated scanning and manual verification to identify, catalogue, and prioritise vulnerabilities across your web applications, servers, network devices, and endpoints.
We use industry-standard tooling including Nmap for network discovery and service fingerprinting, Nikto for web server analysis, OpenVAS/Greenbone for comprehensive host vulnerability scanning, and custom scripts from our CyberLab toolset.
Results are correlated against the National Vulnerability Database (NVD) and CVSS v3.1 scoring, then presented in a clear risk register with remediation priorities aligned to business impact.
Network discovery and port/service enumeration (Nmap)
Web server and application scanning (Nikto, custom tools)
Host vulnerability scanning (OpenVAS / Greenbone)
CVE cross-referencing and CVSS v3.1 severity rating
Risk register with prioritised remediation plan
Quarterly re-scan option for continuous assurance
Target IP ranges, URLs, and exclusions are agreed in writing. Scanning windows are set to minimise impact on production systems.
Nmap scans enumerate live hosts, open ports, running services, and OS fingerprints. UDP scanning is included where agreed.
OpenVAS performs authenticated and unauthenticated host scans. Nikto analyses web servers for misconfigurations, outdated software, and common vulnerabilities.
Automated findings are manually verified to eliminate false positives before reporting. Context and exploitability are assessed for each finding.
Each vulnerability is rated by CVSS v3.1 score and re-prioritised against your business context: asset criticality, exposure, and ease of exploitation.
A risk register and technical report are delivered covering all findings, evidence, CVE references, and a prioritised remediation plan.
Vulnerability assessment skills developed through MSc practical modules and active CyberLab tooling.
IN PROGRESSSecurity+ covers threat and vulnerability management aligned with our assessment methodology.
TARGETEDAll findings rated using CVSS v3.1 from the National Vulnerability Database for consistent, comparable risk scoring.
STANDARD23 active security tooling repositories demonstrating practical vulnerability research and tool development capability.
IN PROGRESSTell us what you need scanned and we'll respond with a scoped proposal within one business day.
Submit your target details and preferred assessment scope
We agree scope, scanning windows, and issue a formal quote
Assessment is conducted and a risk register report delivered
Our assessment team will review your scope and respond within one business day.
Know who is targeting you and why. IP reputation, threat context, and geolocation intelligence powered by our Netra platform and live threat feeds.
Quatech's threat intelligence services are powered by Netra — our internally developed threat analysis platform that aggregates data from AbuseIPDB, IP geolocation services, and curated threat feeds to give you actionable intelligence on the IPs and domains interacting with your environment.
We deliver intelligence in three forms: on-demand IP and domain reputation lookup, continuous monitoring of your exposed assets against threat feeds, and contextual threat reporting that maps observed indicators to known attack campaigns and threat actor profiles.
Whether you're investigating a suspicious login, triaging a firewall alert, or building a threat-informed defence strategy, our intelligence services give your team the context to act quickly and confidently.
IP reputation and abuse scoring via AbuseIPDB integration
Geolocation and ASN context for suspicious sources
Domain and URL threat classification
Indicator of Compromise (IOC) matching against live feeds
Threat actor profiling and campaign mapping
Custom threat intelligence reports for your sector
We work with you to define your priority intelligence requirements (PIRs): what threats matter most to your organisation, sector, and asset profile.
Relevant threat feeds, OSINT sources, and our Netra platform are configured to collect indicators relevant to your environment and industry.
Raw indicators (IPs, domains, hashes) are enriched with geolocation, ASN, abuse history, WHOIS, and passive DNS data to build complete context.
Enriched indicators are matched against your firewall logs, SIEM data, or access logs to identify whether known bad actors have interacted with your environment.
Findings are packaged into a clear threat intelligence report: what we found, the likely threat actors, their techniques, and recommended defensive actions.
For retainer clients, continuous monitoring detects new indicators as they emerge, with weekly or monthly briefings keeping your team informed.
Internally built threat intelligence platform integrating AbuseIPDB, geolocation APIs, and curated threat feeds.
IN PROGRESSThreat actor profiling and campaign mapping aligned to the MITRE ATT&CK knowledge base.
STANDARDThreat intelligence practices grounded in MSc academic study in threat analysis and digital forensics.
IN PROGRESSIntegrated with AbuseIPDB, Shodan, VirusTotal, and open-source threat intelligence feeds for comprehensive coverage.
IN PROGRESSNetra is Quatech's own threat intelligence platform: real-time network traffic analysis, IP geolocation mapping, AbuseIPDB integration, and SOC alert triage in one dashboard. It powers the threat intelligence services we deliver to clients — and will be available at netra.com.
Tell us what you're investigating or what ongoing intelligence coverage you need. We'll respond with a proposal within one business day.
Submit your intelligence requirements and any indicators to investigate
We scope the engagement and agree deliverables and timelines
Intelligence is delivered as a report or integrated into your security workflow
Our threat intelligence team will review your requirements and respond within one business day.
Continuous security monitoring for SMEs who can't afford a full in-house SOC — plus staff awareness training to reduce the human-layer risk.
Quatech's SOC-as-a-Service gives SMEs access to professional security monitoring without the cost of an in-house team. We monitor your endpoints, firewall logs, and cloud activity for signs of compromise, alerting your team and investigating incidents as they arise.
Our Security Awareness Training programme addresses the most common entry point for attackers: your people. We deliver tailored training sessions, phishing simulation campaigns, and a measurable awareness improvement programme aligned to the NCSC Cyber Essentials framework.
Both services are designed to be practical and affordable for growing businesses that take security seriously.
Log aggregation, correlation, and threat detection
24/7 alert monitoring with defined escalation paths
Incident response support and containment guidance
Phishing simulation campaigns (click-rate tracking)
Staff cybersecurity awareness training (online and in-person)
Cyber Essentials alignment and preparation support
Log sources are connected (firewall, endpoint, cloud), parsing rules configured, and a baseline of normal activity established over the first two weeks.
Detection rules are tuned to your environment, reducing false positives while ensuring high-fidelity alerts for genuine threat behaviours.
24/7 monitoring of your log streams. Alerts are triaged by our SOC team and escalated to you with clear context and recommended action.
When a confirmed incident is detected, we support your team through containment, evidence preservation, and recovery — and document the incident for post-mortem review.
Simulated phishing campaigns are sent to your staff. Click rates are tracked and reported, and targeted follow-up training deployed to users who clicked.
Training modules covering phishing, password hygiene, social engineering, and safe browsing are delivered. Completion and assessment scores are reported to management.
SOC and awareness services aligned to NCSC Cyber Essentials and Cyber Essentials Plus frameworks.
STANDARDInternal SOC simulation tool built and published as part of the 23-project CyberLab GitHub portfolio.
IN PROGRESSSecurity monitoring and awareness training aligned to ISO 27001 controls for human resource and incident management.
STANDARDCybersecurity Analyst certification targeted for all SOC team members, covering threat detection and response.
TARGETEDTell us about your environment and what security outcomes matter most. We'll propose a monitoring and training package matched to your size and budget.
Submit your environment details and security objectives
We scope a monitoring and/or training package and provide pricing
Onboarding is completed within 10 working days of sign-off
Our SOC team will review your requirements and be in touch within one business day.