Skip to main content
Precursor Security
2026 Comparison Guide

Best Penetration Testing for Law Firms

The best penetration testing for UK law firms in 2026 comes from CREST-accredited providers with UK-based, vetted testers for confidentiality of privileged matter data, a retest included for remediation evidence, and reporting that satisfies client security questionnaires and professional-indemnity insurers. This guide compares 7 providers: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof.

Seven penetration testing companies compared for UK law firm buyers, on the criteria that actually matter for a practice holding privileged matter data: confidentiality and UK-based testers, verifiable CREST accreditation, a retest for remediation evidence, and reporting that satisfies client security questionnaires and PI insurers.

Updated August 2026
Every claim verifiable
Confidentiality marked
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Read This First

We are Precursor Security, and we have ranked ourselves first on this list.

Rather than pretend otherwise, we publish the selection criteria in full and describe every provider fairly, including where a rival is the better fit. The firms below are genuinely good at what they do; the differences are in confidentiality, transparency, accreditation, and who each serves best for a practice holding privileged client data. Confirm any CREST claim in the independent CREST member directory.

At a Glance

Seven firms, side by side

ProviderCREST statusPricing publishedFrom
1. Precursor SecurityPen Test + VA + SOCYesFrom £2,500
2. NCC GroupMember firmNoOn application
3. Pen Test PartnersMember firmNoOn application
4. Redscan (Kroll)Member firmNoOn application
5. JUMPSECMember firm + NCSC CHECKNoOn application
6. OnSecurityMember firmNoInstant quote via platform
7. BulletproofMember firmNoOn application

Verified against each provider's public website, August 2026. "No" under pricing means a rate was not published at the time of writing, not that a provider is more expensive. Redscan is part of Kroll (US-headquartered).

The 7 best for UK law
firms in 2026

1. Precursor Security

Best for: UK law firms that need confidentiality of privileged data, fixed pricing, and evidence their client due-diligence teams and insurers will accept

Precursor holds triple CREST accreditation across Penetration Testing, Vulnerability Assessment, and Security Operations Centre. Every tester is a UK-based, DBS-checked employee, which matters when a firm needs privileged matter data and client records handled in-jurisdiction with no offshoring. Testing starts from £2,500 at approximately £1,200 per consultant day, published on the website, with a retest included in every engagement and a written quote within 24 hours, useful when a client-mandated deadline is fixed. Reports are built to satisfy the security questionnaires corporate clients and insurers send, and social engineering testing is available for firms exposed to business-email-compromise attempts around client funds. Findings feed detection rules through the closed-loop model, which suits a firm expected to demonstrate ongoing assurance, not a once-a-year exercise.

Trade-off: A UK mid-market specialist rather than a global enterprise brand, and it does not hold NCSC CHECK, which only a small number of providers offer.

2. NCC Group

Best for: Large national and international firms needing global delivery at scale

NCC Group is one of the largest security consultancies in the world, headquartered in Manchester, with a deep research pedigree and the capacity to staff very large, multi-office assessment programmes. For a top-tier or international firm running a global rollout across multiple jurisdictions, few firms match its bench depth.

Trade-off: Engagement model and pricing are built for enterprise procurement. Costs are on application.

3. Pen Test Partners

Best for: Embedded and operational technology, less common in a typical law firm estate

Pen Test Partners are the UK's best-known specialists in embedded and operational technology, and their public research is consistently cited. Most law firms run standard web, network, and cloud estates rather than embedded systems, so this specialism is a narrower fit for the sector, though their standard testing practice is well regarded.

Trade-off: A specialist focus built around embedded and OT work; standard web and network testing is not their distinctive strength. Pricing on application.

4. Redscan (Kroll)

Best for: Firms wanting testing inside a wider Kroll incident response and forensics relationship

Redscan, now part of Kroll, pairs a large practitioner organisation with the backing of a global incident response and forensics business. For a firm that wants its tester, its IR retainer, and its forensics provider under one roof, particularly useful if the firm ever needs breach forensics for a client matter, the Kroll relationship is the draw.

Trade-off: Kroll is US-headquartered, which is worth weighing against confidentiality obligations for privileged data, and the engagement model leans enterprise. Pricing on application.

5. JUMPSEC

Best for: Firms with public-sector-adjacent instructions or an NCSC CHECK requirement

JUMPSEC holds NCSC CHECK status alongside CREST membership, with a strong red teaming and adversary-simulation practice. For a firm acting on PSN-connected or government-adjacent matters that mandate CHECK delivery, that combination is the differentiator.

Trade-off: Pricing on application.

6. OnSecurity

Best for: Smaller firms and legal-tech startups wanting fast, platform-led testing

OnSecurity runs a platform-first, pentest-as-a-service model with instant online quoting and quick scheduling. For a smaller practice or a legal-tech provider that needs a test booked this week with minimal procurement friction ahead of a client due-diligence deadline, the platform model works well.

Trade-off: Quotes are generated through the platform rather than published as a rate card, and the model suits smaller, repeatable scopes.

7. Bulletproof

Best for: Smaller firms wanting testing and compliance certification on one contract

Bulletproof combines penetration testing with a broad compliance practice, including Cyber Essentials support, which suits a smaller firm that wants testing and certification handled by a single supplier ahead of insurer or client renewal.

Trade-off: A generalist breadth play rather than a testing specialist. Pricing on application.

Methodology

How we ranked them for law firms

Six criteria that matter specifically to a practice holding privileged matter data, each something you can verify without taking anyone's word for it. Weighting is ours; the facts are checkable.

UK-based testers and confidentiality

Where the testers physically sit, whether any work is offshored, and whether individuals are vetted. A test against a case management system or client portal can expose privileged matter data, so the engagement needs confidentiality obligations equivalent to those you owe your own clients.

Verifiable CREST accreditation

Company and individual CREST accreditation, checkable in the public directory. It is the accreditation most corporate clients, insurers, and the Law Society's guidance point firms towards.

Retest included

Whether verification of your fixes is included or sold back as a second engagement. A firm needs remediation evidence for the SRA, insurers, and client due-diligence, and paying twice for it is avoidable.

Reporting that satisfies client questionnaires and insurers

Whether the report has an executive summary, business impact, and prioritised remediation that a client's security team and a professional-indemnity insurer will accept, not raw scanner output.

Social engineering and phishing testing

Law firms are high-value phishing and business-email-compromise targets, particularly around client funds and conveyancing. Whether the provider can test social engineering and phishing resilience, not just infrastructure, matters for this sector specifically.

Continuous assurance

Whether findings feed ongoing detection rather than sitting in a PDF until next year. A firm expected to demonstrate continuous protection of client data benefits from the closed-loop model.

Buyer Beware

Red flags for a law
firm buyer

Whichever firm you choose, including us, walk away if you see these.

Offshore testers on privileged matter data

Ask where the testers on your engagement physically sit and whether any work is subcontracted overseas. For a firm holding privileged client data, confidentiality and vetting are not paperwork, they are the answers you give clients and insurers.

A scan dressed up as a penetration test

Engagements priced under £500 a day are automated scans with a human cover sheet. Ask how many days of manual testing, by whom, with what certifications. A client or insurer wants evidence of real testing, not a tool report.

POA-only pricing under a client-mandated deadline

A firm that cannot indicate a day rate before a discovery call adds procurement drag when you are working to a client due-diligence or panel-review deadline. UK CREST day rates run £1,000 to £1,500.

No retest, so no evidence for insurers or clients

A test without verification of your fixes is half a service. If the retest is a separate paid engagement, your remediation evidence for the SRA, insurers, and client due-diligence teams costs double.

Accreditation that does not check out

Verify every CREST and CHECK claim in the official directories. A supplier that implies a capability it does not hold is a compliance risk you inherit.

Reports clients' security teams and insurers will not accept

Ask for a redacted sample. If it reads like raw scanner output with no executive summary, business impact, or prioritised remediation, your clients' security questionnaires and your PI insurer will get nothing from it.

What It Costs

Law firm penetration testing prices

CREST-accredited testing runs £1,000 to £1,500 per consultant day. At Precursor's published rate of approximately £1,200 per day: external network from £2,500, web application from £3,750, internal network from £6,250, and full multi-scope assessments from £10,000. Full pricing with worked examples is on the cost guide below.

Full cost guide with worked examples
External networkFrom £2,500
Web applicationFrom £3,750
Internal networkFrom £6,250
Full assessmentFrom £10,000
Make It a Fair Fight

Compare us against anyone on this list.

UK-based, DBS-checked testers for confidentiality of privileged data. Fixed pricing published before you call. A written quote within 24 hours of scoping. Retest included.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team
FAQs

Penetration testing for law firms

The questions law firms ask most when comparing UK providers.

UK penetration testing runs from £2,500 for a small external network test to £25,000+ for a full multi-scope assessment, at roughly £1,000 to £1,500 per consultant day from a CREST-accredited provider. For a law firm specifically, a smaller practice typically budgets an annual external network and web application test; a larger firm with a case management system, client portal, and remote-access estate usually runs a wider scope covering internal network and cloud. Most firms price on application; Precursor publishes its rates. Full pricing with worked examples is on our penetration testing cost guide.

The SRA does not mandate a specific penetration test. What it expects is that firms take reasonable, proportionate measures to protect client data and money under the SRA Standards and Regulations, including the obligation to keep client affairs confidential. In practice, that expectation is increasingly evidenced through annual CREST-accredited penetration testing: it is what corporate clients ask for in due-diligence questionnaires, what the Law Society's Lexcel and cyber-related guidance points firms towards, and what professional-indemnity insurers now expect to see at renewal. A firm without a recent test is exposed on all three fronts even without a specific regulatory mandate.

Corporate clients running vendor due diligence on their instructed firms typically ask whether penetration testing is performed at least annually, whether the provider holds CREST accreditation, whether findings were remediated and retested, where the testers are based, and whether the firm can produce a redacted report or attestation letter as evidence. A firm that cannot answer these quickly, with evidence rather than assurances, adds friction to a panel review or a new-client onboarding.

Ask any provider where the testers on your engagement physically sit, whether any work is subcontracted or offshored, and whether individual testers are vetted, ideally DBS-checked. A test against a case management system, client portal, or document management system can expose privileged matter data, so the engagement should be scoped and contracted with confidentiality obligations equivalent to those you owe your own clients. Precursor uses only UK-based, DBS-checked employees, with no offshoring.

UK law firms commonly shortlist a mix of specialists and larger consultancies. This guide compares seven: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof. The right choice depends on where the testers sit, whether pricing is published, whether a retest is included for your remediation evidence, and whether the firm can produce reports that satisfy client due-diligence teams and PI insurers. Confirm any CREST accreditation in the public directory at crest-approved.org.