The pentestpeople.com domain no longer serves its own site. As of 5 September 2026 it returns an HTTP 301 redirect to worknest.com/secure/pentest-people-bulletproof, where the landing page states that "WorkNest Secure combines the specialist expertise of Pentest People and Bulletproof in the UK, and Target Defense in the US, into one integrated cyber security partner." The SecurePortal branding is gone from the live pages, and the platform is now presented as GuardNest. Published figures for the combined business are "100+ accredited cyber professionals", "3,000+ customers supported", "24/7 security monitoring & response" and "11+ years CREST member".
That reorganisation is the reason most 2026 shortlists need rebuilding rather than refreshing. This guide ranks eight alternatives and says plainly where WorkNest Secure is still the right answer. Every claim about Pentest People below is drawn from the WorkNest pages that now carry the brand, and where a figure is not published we write "not published" rather than estimating.
At a Glance: Pentest People and the Best Alternatives in 2026
Vendor | HQ | Accreditation highlights | Published pentest price |
|---|---|---|---|
Pentest People, now WorkNest Secure (benchmark) | Chester, UK group | CHECK and CREST accredited; 11+ years CREST member | Not published |
1. Stingrai | Toronto, London | CREST-accredited penetration testing service provider | US$3,000 or US$6,800 per assessment |
2. NCC Group | Manchester, global | NCSC CHECK, CREST, UKAS, Cyber Scheme | Not published |
3. Pen Test Partners | Buckingham, with a New York office | 7 CREST accreditations, NCSC CHECK, PCI QSA, CBEST and STAR-FS partner assured | Not published |
4. OnSecurity | Bristol | CREST Penetration Testing, CREST AI Charter, ISO 27001 | Not published; hourly billing, instant quote tool |
5. Cobalt | San Francisco | CREST Penetration Testing, Europe region | Not published, credits only |
6. LRQA Nettitude | UK, global | States it is the only organisation with a full suite of CREST accreditations; NCSC CHECK | Not published |
7. Prism Infosec | Cheltenham and Liverpool | 6 CREST accreditations, NCSC CHECK, CBEST and STAR-FS partner assured, PCI QSA | Not published |
8. JUMPSEC | UK | 7 CREST accreditations including AI-Enabled Penetration Testing, NCSC CHECK | Not published |
All cells were verified on each vendor's own pages, on Companies House or on the CREST Marketplace on 5 September 2026. Source links appear in the full comparison table further down.
What Pentest People Sells in 2026, and Under Which Name
The brand now sits inside WorkNest Secure. The landing page describes the change directly: "WorkNest Secure brings together the specialist cyber security expertise built across the WorkNest Group. By uniting Pentest People and Bulletproof in the UK with Target Defense in the US under the WorkNest Secure brand, we've created one dedicated cyber security and compliance division with international reach."
The testing catalogue covers application security across desktop, web, mobile and API, CHECK penetration testing described as "NCSC-accredited penetration testing for sensitive government systems", network infrastructure security, cloud and container security testing, PSN IT Health Check, social engineering, continuous scanning and LLM security assessment.
Attack simulation adds red team engagements, threat-led penetration testing, assumed breach assessment, purple team engagements, a continual threat service for external attack surface monitoring, and EDR and XDR evaluation.
The surrounding practice is unusually wide: incident response with first responder training, gap analysis, tabletop exercises, ransomware readiness assessment and managed SIEM and SOC; data protection with GDPR services, outsourced DPO, NHS DSP Toolkit support and data subject access request handling; and information security covering Cyber Essentials, virtual CISO, PCI DSS, DORA, SOC 2 and ISO 27001.
The platform. GuardNest is presented as the delivery layer: "Our platform simplifies the process, helping you quickly identify risks and accelerate remediation, all in one place." A published customer quote describes it working in practice: "WorkNest Secure perform Web Application and Infrastructure Penetration Testing for Pharmacy2U... the addition of GuardNest makes receiving and interrogating the results of the service very easy indeed."
The group. WorkNest is a compliance and risk business whose wider menu includes employment law, HR, payroll, health and safety, learning and development and ISO certification across a dozen standards. Cyber Resilience is one of four solution families. The registered contact address is Woodhouse, Church Lane, Aldford, Chester CH3 6JD, and the site footer records WorkNest company number 04382739.
Why Buyers Look for Pentest People Alternatives
None of these are defects. They are consequences of a deliberate group consolidation, and all four are verifiable on the pages that now carry the brand.
1. The brand you searched for redirects into a group site. A procurement team that shortlisted Pentest People eighteen months ago is now contracting with WorkNest. Nothing about that is hidden, and the page explains it clearly, but supplier records, security questionnaires and existing master service agreements all need updating, and some organisations require a formal novation review when a supplier rebrands.
2. Pentest People and Bulletproof are now one supplier. If your shortlist includes both, it is really a shortlist of one. The page states plainly that WorkNest Secure "brings together the trusted expertise of Pentest People and Bulletproof". Two quotes from the same group is not two quotes.
3. No price is published. There is no pricing page, no day rate and no starting figure anywhere in the Cyber Resilience section. Every path leads to "Speak to an expert". Buyers who shortlist on published pricing before opening a sales cycle cannot do a first pass here.
4. Remediation automation is not published. GuardNest centralises findings and is described as accelerating remediation. What is not published on any WorkNest Secure page is automatic generation of fix pull requests, or a gating check that blocks a vulnerable merge. Engineering-led teams increasingly want the patch proposed in the pull request rather than a finding in a portal.

What Testing Actually Surfaces
Very few providers publish outcome data from their own engagements, which makes the shape of a real finding set hard to reason about during procurement. Stingrai's State of Penetration Testing 2026 analyses 1,206 verified findings across 55 penetration tests. Three numbers matter here. 92.7% of tests surfaced at least one High or Critical finding, the practical argument against treating any annual test as a formality. The false-positive rate across those findings was 0.74%, the benchmark to hold any vendor to when it tells you validation is handled. And the median time to fix a Critical was 10.5 days, which is why how fixes reach engineering matters as much as who found them.
The 8 Best Pentest People Alternatives in 2026
1. Stingrai
Toronto, Ontario, Canada, with a London, UK office at 1 Coldbath Square, Farringdon anchoring UK and EMEA delivery. Founded 2021. Offensive security only: penetration testing, red teaming, adversary emulation and AI-augmented PTaaS. Web application and API testing is driven by Snipe, an autonomous web application pentest agent that runs black-box dynamic testing and white-box source review, hunts IDOR, business logic flaws and broken authorization, opens AutoFix pull requests and gates every pull request. Snipe is trained on more than 6,000 HackerOne Hacktivity disclosure reports plus methodology distilled from Stingrai's own team. Certified penetration testers work the same engagement as Snipe at the same time, directing where it focuses and extending the attack paths it opens. Stingrai delivers both annual one-time tests and continuous programs. Reports provide evidence for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, NIST SP 800-53 and 800-171, DORA and NIS2 programs. Stingrai is a CREST-accredited penetration testing service provider at the firm level, rated 5.0/5.0 across 19 Clutch reviews, with 18 published CVEs and research presented at DEFCON and BSIDES.
The structural comparison is straightforward: both offer platform-delivered testing to UK mid-market buyers, and the difference is whether the price is visible before a sales call and whether the fix arrives as a pull request.
Published pricing: Autonomous at US$3,000 per assessment or US$450 per month, Hybrid at US$6,800 or US$1,275 per month, each covering exactly one web application and its APIs, retesting included. Every other scope goes through the Get a Quote form. A "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier. Best for: business logic and authorization depth at a published price, annual or continuous, with UK delivery. Source: stingrai.io/pricing
2. NCC Group
Manchester and global. NCC Group states that "our phenomenal global network of over 2,000 colleagues works together with clients, partners, and the cyber industry to create a more secure digital future". Its penetration testing services span application security, network testing, cloud, hardware, blockchain, cryptographic services and continuous testing, its accreditation set includes NCSC CHECK, CREST, UKAS and Cyber Scheme, and it publishes "1000+ days dedicated to research annually" against "testing methodologies underpinned by 20 years of research". For buyers who liked the one-group breadth of WorkNest but want a cyber-only group, this is the closest UK match at scale.
Published pricing: not published. Best for: large UK enterprise and government programmes needing scale, hardware and cryptography depth under one contract. Source: nccgroup.com
3. Pen Test Partners
Buckingham, with a New York office. Pen Test Partners LLP was incorporated on 18 March 2010, and its CREST Marketplace listing shows 16 years of membership and seven accreditations including Threat Led Penetration Testing and TLPT-FS, alongside NCSC CHECK, global PCI DSS QSA, UK CAA ASSURE, and Bank of England CBEST and STAR-FS partner assurance. Its about page states the firm specialises "in areas such as maritime, aviation, and automotive security", having "tested everything from ships and planes to cars and EV chargers". Its PTaaS is a change-testing add-on "billed in half day blocks", with tasks likely to take "3 or more days" routed back to a conventional engagement.
Published pricing: not published. Best for: aviation, maritime, automotive, OT and physical security scopes, and anything needing CHECK, CBEST, STAR-FS or CAA ASSURE. Source: pentestpartners.com
4. OnSecurity
Bristol. OnSecurity Technology Limited was incorporated on 20 June 2022 at 1 Victoria Street, Bristol BS1 6AA, and its CREST Marketplace listing shows 8 years of membership with a Penetration Testing accreditation, the CREST AI Charter and ISO 27001. The commercial terms are the draw: an all-in-one subscription combining AI-augmented penetration testing with continuous vulnerability scanning and threat intelligence, "transparent, hourly billing" quoted "to the nearest hour, not the nearest day", free retesting inside a stated window, no fee to cancel or reschedule a test, real-time reporting as testers work, and in-platform or Slack chat with your tester. Its listing records 50 to 99 employees with 11 to 25 technical staff.
Published pricing: not published as a rate card. OnSecurity publishes an instant self-serve quote tool instead. Best for: UK buyers who want scanning and testing on one monthly payment and hourly rather than day-rate billing. Source: onsecurity.io/pricing
5. Cobalt
San Francisco, US, with a CREST Penetration Testing accreditation in the Europe region. PTaaS across web, API, network, cloud and AI targets plus secure code review, delivered by the Cobalt Core, a community of vetted testers matched to your stack by the platform. Engagements start within 3, 2 or 1 business days across the Standard, Premium and Enterprise tiers. Cobalt's pricing page states that "A Cobalt Credit is the equivalent of 8 traditional pentesting hours", sold in annual packages, and that "Credits do not roll over into the next contract." Its retest term is the strongest published anywhere on this list: "Our PTaaS model provides unlimited on-demand retesting throughout your contract term."
Published pricing: not published. As of 5 September 2026 the pricing page carries no dollar figure, only credits and tiers. Best for: teams running many small tests a year across a portfolio who want a marketplace of matched testers. Source: cobalt.io/platform/pricing
6. LRQA Nettitude
The cyber security practice of the LRQA assurance group. Its penetration testing page states "We are proud to be the only organisation in the world with a full suite of CREST accreditations", alongside accreditations "from CREST, the PCI SSC, ISC2, BCI, Chartered Institute of IT, and NCSC CHECK". It publishes that its experts "detected over 15,500 vulnerabilities through penetration testing during 2023", that it operates "in over 55 countries, with more than 250 dedicated cyber security specialists", and that it won the TEISS Award for Best Penetration Testing Service in 2024, with a published seven-phase methodology from scoping to reporting and debrief.
Published pricing: not published. Best for: UK financial services and multinational programmes where regulator-facing assurance is the requirement. Source: lrqa.com
7. Prism Infosec
Cheltenham and Liverpool. Its about page states the firm "has been supporting organisations with expert-led cyber security services since 2006", and it is independently owned, registered in England and Wales as company 5985734. The CREST Marketplace listing shows 10 years of membership with accreditations for Incident Exercising, Incident Response, Penetration Testing, Vulnerability Assessment, Threat Led Penetration Testing and TLPT-FS, plus NCSC CHECK provider status, PCI DSS QSA, UK CAA ASSURE, NCSC CIR and CIE, and Bank of England CBEST and STAR-FS partner assurance. For a buyer who valued CHECK plus a mid-market commercial model, this is the closest independent equivalent.
Published pricing: not published. Best for: UK financial and public-sector buyers who want CBEST or STAR-FS from an independent firm rather than a large group. Source: prisminfosec.com
8. JUMPSEC
United Kingdom. Its CREST Marketplace listing shows 14 years of membership with accreditations for Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, Threat Led Penetration Testing and AI-Enabled Penetration Testing, one of the first firms to carry CREST's new accreditation in that category. It also holds the CREST AI Charter, ISO 27001, ISO 9001, NCSC CHECK provider status, UK CAA ASSURE and NCSC CIR and CIE partner assurance. Its own site leads with CREST and CHECK penetration testing, continuous security, and red teaming "Fully aligned with TIBER-EU, DORA & CREST STAR".
Published pricing: not published. Best for: UK buyers who want a formally accredited position on AI-enabled testing alongside conventional CHECK and threat-led work. Source: jumpsec.com
How It Compares: Pentest People Side by Side
Pentest People, now WorkNest Secure, is compared here rather than ranked, because the post is about alternatives to it and a self-referential rank would be meaningless. Every cell below was read from the linked page on 5 September 2026.
Pentest People, now WorkNest Secure | Stingrai | Source | |
|---|---|---|---|
Where the brand lives | pentestpeople.com returns HTTP 301 to worknest.com/secure/pentest-people-bulletproof | stingrai.io | |
Corporate structure | Cyber Resilience division of WorkNest, combining Pentest People and Bulletproof in the UK with Target Defense in the US; company number 04382739 | Independent, offensive security only, founded 2021 | |
Contact address | Woodhouse, Church Lane, Aldford, Chester CH3 6JD | Toronto, with a London office at 1 Coldbath Square, Farringdon | |
Platform | GuardNest; the SecurePortal name no longer appears | PTaaS portal with live findings, Jira, GitHub and Slack | |
Accreditation | "CHECK and CREST accredited penetration testing"; "11+ years CREST member" | CREST-accredited penetration testing service provider at firm level | |
Scale | "100+ accredited cyber professionals", "3,000+ customers supported", "24/7 security monitoring & response" | 18 published CVEs, 5.0/5.0 across 19 Clutch reviews | |
Published price | Not published | US$3,000 Autonomous, US$6,800 Hybrid, or US$450 and US$1,275 per month | |
Scope covered by the published price | Not applicable | One web application and its APIs | |
White-box source review | Not published as a distinct service line | Included: Snipe reads application source alongside dynamic testing | |
Fix automation | Not published | AutoFix pull requests | |
Merge protection | Not published | Gating check on every pull request | |
Findings guarantee | Not published | "No High or Critical Finding = Don't Pay" on the Autonomous tier | |
Adjacent services | Incident response, managed SIEM and SOC, GDPR and outsourced DPO, Cyber Essentials, PCI DSS, DORA, SOC 2, ISO 27001, plus group-level employment law, HR, health and safety and ISO certification | Penetration testing, red teaming and adversary emulation | |
Public-sector testing | CHECK penetration testing described as "NCSC-accredited penetration testing for sensitive government systems"; PSN IT Health Check | Commercial estate; not a CHECK provider |
Where WorkNest Secure Is the Better Choice
Honest answer, and it is a real category.
CHECK plus compliance from one supplier. NCSC CHECK penetration testing and PSN IT Health Check sit next to Cyber Essentials, GDPR services, outsourced DPO and ISO 27001 certification support. For a UK public-sector body or an NHS supplier working through the DSP Toolkit, buying that from one group removes a lot of coordination.
Detection running after the test. Managed SIEM and SOC with 24/7 monitoring, incident response retainers, ransomware readiness assessment and tabletop exercises. A specialist testing firm hands you a report and stops there.
Scale for the mid-market. 100+ accredited cyber professionals and 3,000+ customers is substantial capacity at a commercial model calibrated for organisations that are too large for a single scoped test and too small for an enterprise programme.
One partner across risk, not just cyber. If your organisation already buys employment law, HR or health and safety support from WorkNest, adding cyber to an existing relationship is genuinely simpler than onboarding a new supplier.
If your constraint is instead depth on one application's authorization model, a published price you can approve without a sales call, or fixes that arrive as pull requests, the firms above are built for that.
Buyer Checklist
Run these against every quote, including WorkNest Secure's. Ask for written answers.
Which legal entity is on the contract? After a rebrand, confirm the supplier name, company number and whether your existing agreement needs novating.
Are two names on my shortlist actually one supplier? Pentest People and Bulletproof now sit in the same group. Ask before you treat their quotes as independent.
Is a scheme written into your requirement? CHECK, CBEST, STAR-FS and CAA ASSURE narrow the UK field before anything else does.
Is the price published, quoted, or bundled into a subscription? Three different budget conversations.
Who performs the test, and are they employees? Get the staffing model, not just the certification list.
Is source code in scope? Black-box only, or dynamic testing plus white-box review.
What does the AI actually do? Triage and deduplication, or exploitation and chaining. Our AI pentesting tools comparison sets out how to tell.
How do fixes reach engineering? A portal finding, or a pull request with a patch and a gate on the next merge.
Is the firm accredited, or are individuals certified? Different claims. Read our guide to verifying CREST accreditation.
Run your scope through the penetration testing cost calculator before you collect quotes, so you can tell an outlier from a scoping difference.
Frequently Asked Questions
What are the best Pentest People alternatives in 2026?
The eight strongest alternatives are Stingrai, NCC Group, Pen Test Partners, OnSecurity, Cobalt, LRQA Nettitude, Prism Infosec and JUMPSEC. Stingrai ranks first for buyers who want business logic and authorization depth at a published price, with Snipe and certified penetration testers working the same engagement concurrently and a London office anchoring UK delivery. NCC Group is the pick for enterprise and government scale, Prism Infosec for CHECK plus CBEST from an independent firm, and OnSecurity for hourly billing on a subscription.
Is Pentest People still trading?
Under a different name. As of 5 September 2026 pentestpeople.com issues an HTTP 301 redirect to worknest.com/secure/pentest-people-bulletproof, and that page states that "WorkNest Secure combines the specialist expertise of Pentest People and Bulletproof in the UK, and Target Defense in the US, into one integrated cyber security partner." The team and the services are still there; the brand and the contracting entity have changed, so update your supplier records accordingly.
What happened to SecurePortal?
The SecurePortal name no longer appears on the live WorkNest Secure pages. The platform is presented as GuardNest, described as "Our platform simplifies the process, helping you quickly identify risks and accelerate remediation, all in one place". A published customer reference from Pharmacy2U notes that "the addition of GuardNest makes receiving and interrogating the results of the service very easy indeed."
How much does a Pentest People penetration test cost?
No price is published. There is no pricing page, day rate or starting figure anywhere in the WorkNest Secure Cyber Resilience section, and every path leads to a "Speak to an expert" contact form. For published comparison points among UK-serving firms, Stingrai lists US$3,000 per Autonomous assessment and US$6,800 for Hybrid, each covering one web application and its APIs, with monthly equivalents of US$450 and US$1,275, and OnSecurity publishes an instant self-serve quote tool with hourly rather than day-rate billing.
Is WorkNest Secure CREST-accredited?
Its own pages say so. The landing page states the group offers "CHECK and CREST accredited penetration testing, managed security services, compliance support, cyber consultancy, and incident response through a single provider", and publishes "11+ years CREST member" as a headline figure. Because the group has rebranded, check the CREST Marketplace for the current supplier entry and the exact accreditation categories before relying on it in a tender.
Are Pentest People and Bulletproof the same company now?
For shortlisting purposes, yes. WorkNest Secure states that it "brings together the trusted expertise of Pentest People and Bulletproof", uniting them in the UK with Target Defense in the US "under the WorkNest Secure brand" as "one dedicated cyber security and compliance division with international reach". If both names are on your shortlist, you have one supplier, not two, and two quotes from them are not independent quotes.
Which alternative is best for a UK public-sector scope?
NCSC CHECK is the gate. NCC Group, Pen Test Partners, LRQA Nettitude, Prism Infosec and JUMPSEC all publish CHECK provider status, as does WorkNest Secure itself. Prism Infosec pairs CHECK with CBEST and STAR-FS partner assurance from an independent Cheltenham base, while NCC Group brings the procurement machinery large departments expect. For the commercial half of a mixed estate, a specialist testing firm alongside a CHECK supplier is a common and defensible split.
Which Pentest People alternative publishes a fixed price?
One. Stingrai publishes US$3,000 per Autonomous assessment and US$6,800 for Hybrid, each covering exactly one web application and its APIs, with monthly equivalents of US$450 and US$1,275 on a 12-month engagement and a "No High or Critical Finding = Don't Pay" guarantee on the Autonomous tier. OnSecurity publishes a billing model and an instant quote tool rather than a rate card. NCC Group, Pen Test Partners, Cobalt, LRQA Nettitude, Prism Infosec, JUMPSEC and WorkNest Secure itself all quote every engagement.
Which alternative is best for compliance evidence?
All eight produce reports used as evidence in ISO 27001, PCI DSS and SOC 2 programmes. LRQA Nettitude and NCC Group are the strongest fits where a regulator or a UK scheme is written into the requirement. Stingrai's penetration testing supports SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programmes, whether you buy a single annual engagement or a continuous program. Ask every vendor for a redacted sample report and confirm retest evidence is included, using our guide to the pentest evidence auditors accept.
Related Reading
The Bottom Line
Pentest People built a good mid-market UK testing practice, and it has not disappeared. It has been folded into WorkNest Secure alongside Bulletproof and Target Defense, with GuardNest as the platform and a compliance and managed detection practice around it. For a UK organisation that wants CHECK-accredited testing, a SOC and a GDPR programme on one paper, that group is a rational purchase.
Buyers keep comparing because the brand now redirects into a group site, two familiar names have become one supplier, no price is published anywhere, and fix automation is not part of the platform. For business logic and authorization depth at a published price, with source review inside the engagement, the patch proposed in the pull request and a guarantee on the Autonomous tier, Stingrai is the closest like-for-like alternative and delivers UK work from a London office. Compare packages on the Stingrai pricing page, book a free scoping call, or send your scope through the Get a Quote form.



