Get a quote

Platform Capability · Admin-Gated · Consent-Based

Active Security Testing & Validation

Active web scanning, plus DNS, IP and application-layer validation tools — run by your team, on your schedule, fully logged, never a surprise.

What it is

Most security tools only tell you what looks wrong. Testing & Validation tells you what's actually exploitable.

It's two things, side by side, inside the platform you already use for posture, compliance and asset tracking. Active web scanning sends real attack payloads at a web application to confirm whether a vulnerability is genuinely present and exploitable — the same class of testing a manual web-application penetration test performs. It keeps its own approval flow: anyone can request a scan, an administrator authorises it after confirming they're entitled to test that target, and it runs when it suits the business. Validation tools are a growing set of DNS, IP and application-layer reconnaissance tools that share one session-based consent flow — tick the tools, start the session, an administrator confirms entitlement to test the target.

Both are deliberately gated. Nothing in Testing & Validation ever runs without someone accountable choosing to run it, and every run is logged — who authorised it, which target, and when.

Why it matters

Passive monitoring tells you what looks wrong. It can't tell you whether an attacker could actually get in through it — and "we scan for it" and "we've proven it's exploitable" are different claims. Only one of them is unambiguous evidence, to a board, an auditor, or a customer's due-diligence questionnaire.

Active testing closes that gap, but only if it's done safely and with authority. Run without control, active testing can — rightly — alarm a firewall, disrupt a system, or test something nobody agreed to test. So the platform makes active testing as safe to turn on as anything else in it: gated by explicit, logged authorisation, never scheduled behind your back, and never blended into your automatic posture score, because a result you chose to generate today shouldn't make your score depend on how recently you happened to test.

That's not friction. It's the reason the result can be trusted at all.

How it works

Active web scanning — Request → Authorise → Start

Anyone on the team can request a scan for a domain that already has web scanning enabled. An administrator reads the authorisation, confirms they're entitled to permit testing of that target, and approves it — every approval recorded. An administrator then starts the scan when it suits them, typically inside a maintenance window; a scan takes roughly 30–90 minutes. One authorisation covers exactly one scan of exactly that target.

Validation tools — one shared session consent

DNS, IP and application-layer reconnaissance tools are ticked for a session rather than authorised one at a time; starting the session authorises everything ticked, after an administrator confirms entitlement to test the target. New tools join this same list over time — no new approval flow to learn each time one ships.

Both flows are logged in full, both surface raw findings to administrators (with only 786 Cyber's own internal secrets redacted — nothing about your own environment is ever hidden from you), and a scan that doesn't complete is always recorded as failed, never as a false "clean."

Who needs it

Regulated and financial organisations Where frameworks name active or penetration testing directly — PCI-DSS (Requirement 11.3), SAMA CSF, NCA ECC, DORA.
ISO 27001 and Cyber Essentials Plus organisations Where confirmed, exploitable findings strengthen evidence of an active vulnerability-management process, not just a scanning schedule.
Security and IT teams Who want the confidence of a penetration test without commissioning a separate engagement every time they need to check something.
MSPs Delivering active testing as part of a managed compliance or security service, with a branded report to hand each client.

How 786 Cyber helps

Two tools, one place. Active web scanning and DNS/IP/application-layer validation live together, so active testing is not a separate product, a separate login, or a separate vendor relationship.
Gated by design. Every action is logged — who authorised it, which target, when. Nothing runs without someone accountable choosing to run it.
Findings that connect to everything else. Confirmed findings sit alongside your passive posture, asset inventory and compliance evidence — not in a PDF that never gets opened again.
Evidence that travels. Raw output plus a full audit trail, exportable as a branded PDF report, ready for an auditor, an insurer, or your own board.
Honest by construction. Results never inflate — or deflate — your automatic posture score, and an incomplete scan is always shown as failed, never as clean.

Frequently asked questions

What is Testing & Validation?

Testing & Validation is 786 Cyber's active-testing capability — active web scanning that sends real attack payloads to confirm whether a vulnerability is genuinely exploitable, plus a growing set of DNS, IP and application-layer validation tools. Every action is admin-gated and logged.

Is this the same as a penetration test?

Active web scanning performs the same class of testing a manual web-application penetration test does — sending real attack traffic to confirm exploitability, not just flagging a theoretical issue. It does not replace a scoped, human-led engagement for every use case, but for continuous, on-demand validation it gives you the same class of evidence without commissioning a separate engagement each time you need to check.

Will active scanning trigger my firewall or alerting tools?

Yes, and that is expected — active scanning looks like a genuine attack to a WAF, IDS or SIEM. Scans originate from a single fixed source IP and identify themselves by user agent, so you can allow-list the traffic or simply expect it. We recommend telling your security team before you run a session.

Does Testing & Validation affect my posture score?

No. Results here are never folded into your automatic posture score. Testing is a deliberate, opt-in action you run when you choose to — scoring it would make your score depend on how recently you happened to test, rather than on your continuously-monitored posture. You still get a clear picture: how much of your estate has been validated, how many findings are confirmed, and how recently you last tested.

Who can authorise or run a test?

Anyone on your team can request an active scan; only an administrator can authorise or start one, and only administrators see raw output. Every authorisation is logged — who approved it, which target, and when.

How many active scans are included?

Your plan includes one active scan per domain, per year, as standard. Additional scans are available — talk to us to agree scope and timing.

Testing & Validation sits alongside the always-on work in the Technology & Threats pillar — continuous discovery and prioritisation that runs on its own, with active testing as the deliberate step you take when you need proof.

See what's actually exploitable, not just what's flagged.

Run active scans and validation tools from inside the platform you already use for posture, compliance and asset tracking — gated, logged, and never a surprise.