Security

Website penetration testing for UK small businesses: what it covers and costs

What a website penetration test actually checks, what UK businesses pay, how it differs from a scan and the cheaper security fixes to make before you book one.

By the WE-DEV teamUpdated 9 min read
Brass combination padlock resting on a white computer keyboard next to bank cards, representing website and payment security

A website penetration test is a time-boxed, authorised attack on your site by a qualified tester, who tries to break in the way a real attacker would and then writes up what they found and how to fix it. For a typical UK small business website or web app, expect a test to take two to five tester-days and cost roughly £1,500 to £6,000 plus VAT, depending on scope. Before you pay for one, though, most small businesses get more security per pound from fixing the basics first: updates, two-factor login, backups, a firewall and Cyber Essentials. This guide covers what a test checks, what it costs, how to prepare and what to fix yourself first.

We build and maintain websites, shops and custom software for businesses across the UK, and we spend a fair amount of time on the other side of these reports: fixing what testers find. So this is written from experience of what turns up, not from a sales brochure.

Do you actually need a pen test?

Not every business does. The UK Government’s annual Cyber Security Breaches Survey has found for several years running that roughly four in ten businesses report a breach or attack in a given year, most of it phishing rather than anyone hacking a website. A five-page brochure site on a well-maintained WordPress install with no logins and no customer data is a low-value target, and a pen test on it will mostly tell you things a good maintenance plan already covers.

A pen test starts to make sense when one or more of these apply:

  • Customers log in, upload files or see personal data (portals, booking accounts, member areas).
  • You run a custom web application or API that no off-the-shelf plugin vendor is patching for you.
  • You take payments in a way that brings your own systems into PCI DSS scope.
  • A client, insurer, investor or public-sector tender asks for an independent test report.
  • You are launching something new and significant, or you have just made major changes.
  • You have had an incident and want to know what else is exposed.

If none of those apply, start with the checklist further down and Cyber Essentials. If two or more apply, budget for a test at least once a year and after major releases.

Pen test, vulnerability scan or bug bounty?

These get mixed up constantly, partly because some providers sell an automated scan with a pen-test label on it.

ItemVulnerability scanPenetration testBug bounty
Who does itSoftware, sometimes reviewed by a personA qualified human tester using tools and judgementIndependent researchers, paid per valid finding
What it findsKnown issues: outdated software, missing headers, weak TLS, exposed filesKnown issues plus logic flaws, broken access control, chained attacksWhatever researchers find interesting
Typical UK costFree tools to roughly £50 to £300 a month for managed scanningRoughly £1,500 to £6,000+ for a small site or appPlatform fees plus rewards; rarely suitable for small firms
How oftenWeekly or monthlyAnnually and after major changesOngoing
Good forCatching the obvious between testsAssurance, compliance, custom appsMature organisations with a security team

A scan will tell you that your server reveals its PHP version. A tester will notice that changing the number in /account/invoice/1043 to 1042 shows another customer’s invoice. That second kind of flaw, broken access control, sits at the top of the OWASP Top 10 list of web risks, and no scanner reliably finds it.

What a website penetration test covers

Most UK testers work from the OWASP Testing Guide and the OWASP Top 10, adapted to your site. A typical web application test includes:

Reconnaissance

What can an outsider learn? Subdomains, old staging sites, exposed admin panels, software versions, email addresses, leaked files in public folders and anything sitting in search engine caches. We regularly see forgotten staging copies on subdomains with no password and an old database. That is often the easiest way in.

Authentication and sessions

Password rules, brute-force protection, account lockout, password reset flows, two-factor login, session cookies (Secure, HttpOnly, SameSite flags) and whether logging out actually ends the session.

Access control

Can a normal user reach admin functions? Can one customer see another customer’s orders, bookings or documents by changing an ID? Can a logged-out visitor call API endpoints that should need a login? This is where custom code most often fails.

Injection and input handling

SQL injection, cross-site scripting (XSS), file upload abuse, server-side request forgery and similar. Every form, search box, URL parameter and API field is a potential way in.

Business logic

Applying a discount code twice, changing a price in a hidden field, booking a slot without paying the deposit, skipping a step in a checkout. Only a person thinking about how your business works will find these.

Configuration and infrastructure

TLS settings, security headers, directory listing, error messages that leak details, outdated plugins and server software, open ports and exposed services. For WordPress sites, testers check plugin versions against known vulnerabilities, XML-RPC, user enumeration and the REST API.

The report and retest

You should receive a written report with an executive summary, each finding rated by severity (usually using CVSS scores), evidence, and specific remediation advice. A good provider includes a retest of fixed issues within a set period. Ask about this up front, because some charge extra for it.

What it costs in the UK

Pen testing is usually priced by tester-days. UK day rates vary widely, from around £700 at smaller independent firms to £1,500 or more at larger consultancies, and CREST-accredited or CHECK-approved firms tend to sit towards the upper end. Treat the figures below as typical market ranges rather than quotes.

ScopeTypical effortRough cost (excl. VAT)
Brochure WordPress site, no logins1 to 2 days£800 to £2,500
WooCommerce shop or booking site with customer accounts2 to 4 days£1,500 to £5,000
Custom web app or portal with roles and an API4 to 8 days£3,500 to £10,000
Retest after fixes0.5 to 1 dayOften included; otherwise £400 to £1,200

Then there is the cost of fixing what the test finds, which is the part people forget to budget for. A typical report on a small custom application might list one or two high-severity issues and a handful of medium and low ones. As a worked example, say the fixes need 12 hours of custom development. At our rate of £60 per hour that is £720, less our 10-hour volume discount of 5 % (£36), so £684 plus £136.80 VAT, or £820.80 in total. On a well-maintained WordPress site the remediation is usually much lighter, often a few hours of configuration at our WordPress rate of £50 per hour.

How to choose a tester

In the UK, look for one of these:

  • CREST accreditation for the company, with testers holding CREST certifications. This is the most widely recognised commercial standard.
  • CHECK, the NCSC scheme for testing public-sector and Critical National Infrastructure systems. You will need it if you are tested as part of certain government work.
  • Individual certifications such as OSCP or CREST CRT/CCT, if you are using a smaller independent firm.

Ask for a sample report, a named tester, a clear scope document and their insurance details. The NCSC publishes guidance on commissioning penetration tests that is worth reading before you buy. Be wary of anyone offering a “full pen test” for £299; that is almost always an automated scan.

To be clear about our role: we are not a penetration testing firm. Our cybersecurity services cover hardening before a test, working with the tester you appoint, and fixing what the report finds on sites and applications we build or take over.

Preparing for a test

A little preparation saves tester-days, which saves you money:

  1. Agree the scope in writing. Which domains, which environments, which user roles, what is out of bounds. Under the Computer Misuse Act 1990, testing without proper authorisation is a criminal offence, so the paperwork matters.
  2. Test a staging copy where you can. Ideally an up-to-date clone of live, so the tester can be aggressive without risking real orders or customer data.
  3. Create test accounts for each role (customer, staff, admin) so the tester spends time testing, not registering.
  4. Take a full backup and confirm you can restore it.
  5. Tell your host and Cloudflare, or whitelist the tester’s IP, so their traffic is not blocked halfway through.
  6. Fix the obvious first. Paying a tester £1,000 a day to report out-of-date plugins is poor value.

Fix these first: the free and cheap wins

Most small business website compromises we clean up come from the same handful of causes. Work through this list before you spend money on a test:

  • WordPress core, themes and plugins updated weekly; unused plugins deleted, not just deactivated.
  • No nulled (pirated) themes or plugins. They are a common source of backdoors.
  • Two-factor login for every admin account, and no shared logins.
  • Admin usernames that are not “admin” and passwords from a password manager.
  • Daily off-site backups with at least 30 days of history, and a tested restore.
  • Cloudflare (the free plan is fine for most) with the web application firewall rules enabled.
  • HTTPS everywhere, with HSTS and basic security headers (Content-Security-Policy where practical, X-Content-Type-Options, Referrer-Policy).
  • Staging and old sites deleted or password-protected.
  • File editing disabled in the WordPress dashboard; correct file permissions on the server.
  • Payments through a hosted or embedded provider such as Stripe, so card data never touches your server.

A proper WordPress maintenance plan covers most of this every month, and our DevOps services handle the server, backup and deployment side for custom applications.

Cyber Essentials: the sensible first step

Cyber Essentials is the UK Government-backed scheme, run through IASME, that certifies five basic controls: firewalls, secure configuration, user access control, malware protection and security update management. The basic self-assessed certificate costs from a little over £300 plus VAT for the smallest organisations, with fees rising by company size. Cyber Essentials Plus adds a hands-on technical audit and typically costs from around £1,500 upwards depending on the certification body and how many devices you have.

It is not a pen test, and it does not test your website application in depth. But it covers the controls behind most real-world incidents, and it is required for many government contracts. For a small firm in Bristol or Glasgow wondering where to start, Cyber Essentials first and a pen test later is usually the right order.

Where the law comes in

UK GDPR requires you to take “appropriate technical and organisational measures” to protect personal data, and it specifically mentions regularly testing and evaluating their effectiveness. It does not say you must commission a pen test, but if you hold sensitive data and suffer a breach, the ICO will ask what testing you did. If you take card payments, PCI DSS applies too: most small businesses that use Stripe Checkout or a similar hosted payment page qualify for the simplest self-assessment, while businesses whose own servers handle card data face much heavier requirements, including penetration testing.

For the bigger picture on testing before launch, see our software testing checklist.

Our recommendation

  • Brochure site, no logins: maintenance plan, Cloudflare, two-factor login, backups. Skip the pen test.
  • Shop or booking site: all of the above plus Cyber Essentials. Consider a short test after a major rebuild.
  • Custom portal, app or API with personal data: annual pen test by a CREST-accredited firm, plus a retest after fixes and a test before each major release.
  • Asked for a report by a client or tender: check exactly what standard they want (often CREST or Cyber Essentials Plus) before you buy.

If you have a report in hand and need the issues fixed, or you want your site hardened before a test, our team in St Albans works with businesses across the UK. Book hours through Hire us or get in touch with the scope and we will tell you honestly what is worth doing.

Frequently asked questions

How much does a website penetration test cost in the UK?

For a small business website or web application, typically £1,500 to £6,000 plus VAT, based on two to five tester-days at day rates of roughly £700 to £1,500. A simple brochure site can cost less; a custom portal with several user roles and an API can cost more.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated and finds known issues such as outdated software or weak TLS settings. A penetration test is carried out by a person who also looks for logic flaws and broken access control, such as one customer being able to see another's data, which scanners rarely catch.

How often should a small business have a pen test?

If you run a custom application or hold customer personal data, once a year and after major changes is a sensible rhythm. A simple brochure site with no logins usually gets better value from good maintenance and Cyber Essentials than from regular pen tests.

Is a penetration test a legal requirement in the UK?

Not in general. UK GDPR requires appropriate security measures and regular testing of their effectiveness, and PCI DSS requires penetration testing for some card-handling setups, but there is no blanket legal requirement for small businesses to commission one.

What does CREST accreditation mean?

CREST is a UK-founded body that accredits penetration testing companies and certifies individual testers against defined standards. Choosing a CREST-accredited firm gives you assurance about methodology, competence and how your data is handled during the test.

Will a penetration test take my website down?

It should not if it is scoped properly. Testers avoid denial-of-service attacks unless agreed, and testing a staging copy removes most of the risk to live orders and data. Always take a full backup before testing starts.

WE-DEVUK software and web development agency. We build websites, custom software, mobile apps and online shops, and write these guides from the projects we run every week.

Photo: Towfiqu barbhuiya via Unsplash

Read next

Tell us what the business needs.

A developer replies within one working day. Fixed price or hourly, your choice — and the code is yours.