Web Application Penetration Testing
Manual, scenario-led security testing of web applications by CREST-certified testers to uncover access control flaws, injection issues, logic abuse and data exposure that automated scanners miss.
Features
- Manual testing by CREST testers using attacker techniques.
- Focus on business logic abuse, not automation.
- Review authentication, session handling, access control.
- Test injection, SSRF, RCE, data exposure.
- Validate role separation across user types.
- Cover OWASP Top 10 and app-specific abuse.
- Provide exploit evidence with screenshots and steps.
- Give developer-focused remediation guidance.
Benefits
- Learn how attackers could steal data or take control.
- Reduce ICO-reportable breach risk.
- Feed fixes straight into development pipeline.
- Prove secure development practice to clients, auditors.
- Stop one app becoming entry route to estate.
- Support confident rollout of new digital services.
- Show testing is embedded in delivery lifecycle.
- Ask: can normal users escalate to admin silently?
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 8 4 4 0 8 9 3 1 8 7 4 8 0 1
Contact
JUMPSEC LIMITED
Andy Roberts
Telephone: 0333 939 8080
Email: bids@jumpsec.com
About your service
- Service categories
-
Cloud Support Services
Security Services
- Security risk management
- Security design
- Security audit services
- Security quality assurance (QA) and testing
Service scope
- Service constraints
-
Scope is limited to the agreed application(s), environments and user roles.
Live production testing is agreed on a case-by-case basis to avoid disruption.
High-volume brute-force, fuzzing, or denial-of-service-style tests are excluded unless approved.
JUMPSEC does not implement code fixes as part of this service.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Typical Response time is less than 1 hour during Normal Business Hours.
Consultants are aligned on a project-by-project basis with direct access to the client.
Direct contact with the consultant can be made by phone or the preferred communication/messaging channel.
Delivery Management / Project Co-ordination reachable by email /phone/messaging - see Service Description. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
-
Typical Response time is less than 1 hour during Normal Business Hours.
Consultants are aligned on a project-by-project basis with direct access to the client.
Direct contact with the consultant can be made by phone or the preferred communication/messaging channel.
Delivery Management / Project Co-ordination reachable by email /phone/messaging - see Service Description.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Pricing
- Discount for educational organisations
- No
Architecture roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Security architect | £1,250.00 | |
| Lead security architect | £1,550.00 | |
| Principal security architect | £1,750.00 |
Cyber security roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Lead cyber security audit and assurance | £1,150.00 | |
| Principal cyber security audit and assurance | £1,650.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security governance and risk manager | £1,150.00 | |
| Lead cyber security governance and risk manager | £1,450.00 | |
| Principal cyber security governance and risk manager | £1,650.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber incident response | £1,400.00 | |
| Lead cyber security incident response | £1,500.00 | |
| Principal cyber security incident response | £2,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security vulnerability management | £1,150.00 | |
| Lead cyber security vulnerability management | £1,300.00 | |
| Principal cyber security vulnerability management | £1,650.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security digital forensics | £1,400.00 | |
| Lead cyber security digital forensics | £1,500.00 | |
| Principal cyber security digital forensics | £2,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security testing | £1,150.00 | |
| Lead cyber security penetration testing | £1,450.00 | |
| Principal cyber security testing | £1,750.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security secure systems architecture and design | £1,250.00 | |
| Lead cyber security secure systems architecture and design | £1,550.00 | |
| Principal cyber security secure systems architecture and design | £1,750.00 |
Product and delivery roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate delivery manager | £500.00 | |
| Delivery manager | £700.00 | |
| Senior delivery manager | £900.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Programme delivery manager | £800.00 |
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 11 June 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 11 June 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ff15ec0d-1d5e-4e13-8bbd-dc59148e1893
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 59682a3d-b7a2-486a-805a-26c964e7c1b6
- Other security certifications
- Yes
- Any other security certifications
- CREST Membership
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-