CREST Penetration Testing: How the Claranet Cyber Portal Makes It Easier
Discover how Claranet's enhanced Cyber Portal makes CREST-accredited penetration testing easier to manage. Built from customer feedback, the latest updates help security teams streamline vulnerability management, improve collaboration, accelerate remediation, and maintain continuous visibility across their security testing programme.
Claranet has upgraded the portal our security testing customers work in every day, adding new capabilities and sharpening existing ones. Almost every change started as a customer request, and together they do one thing: turn a CREST-accredited penetration test into assurance your whole team can manage, act on, and prove.
Here’s what’s new, why we built it, and how each piece maps to the standards a CREST penetration test is held to.
Why a CREST pen test is only the start?
CREST – the Council of Registered Ethical Security Testers – sets the standard for how penetration testing is scoped, delivered, reported, and handled. Its accreditation covers the whole engagement: preparation and scoping, execution, secure handling of your data, clear reporting, and continuous improvement. Accredited companies also align to ISO 27001 and ISO 9001. Claranet is a CREST-accredited penetration testing provider, and our testing is recognised under the National Cyber Security Centre’s CHECK scheme.
But the standard doesn’t stop at the report. A finding only reduces your risk once someone owns it, fixes it, and proves it’s gone. That’s the part our portal is built for.
What our customers asked us to build?
We keep a close eye on what customers ask for in the portal. The features below are the ones we hear most often, and the ones that change how you run a testing programme.
Scope testing the way you run your business
Start by creating a project, adding your assets, and scoping them. From there, choose how each asset is tested: continuous security testing (CST) for the things that change often and carry the most risk, or a one-off offensive security engagement when a point-in-time test is what you need. As priorities shift, move assets between the two – three months of continuous testing on a new service, then back to an annual test once it settles.
How this maps to CREST? Scoping is the first thing the CREST standard asks a provider to get right. Putting it in your hands, asset by asset, is how we make sure the test that runs is the test you actually need.
Findings you can read, prove, and trust
Every finding lands in one view, scored for severity with the Common Vulnerability Scoring System (CVSS) and filterable by type, asset, or status. The breadth on show matters: web applications, infrastructure, APIs, mobile, cloud, configuration reviews, and more, all reported the same way.
Open a finding and you get the full picture – a synopsis, the technical detail, a recommended fix, and, where it helps, a video proof of concept that shows the issue being reproduced. Teams with a lot of findings can export the lot to a spreadsheet (CSV) in one click, something several customers asked us for because a PDF doesn’t cut it at volume.
How this maps to CREST? This is the heart of the CREST reporting standard: clear evidence, real impact, and remediation guidance a practitioner can act on, not a wall of unranked issues.
From finding to fix, faster
Findings don’t fix themselves, so we’ve made the portal the place where the work happens. Leave a comment on any finding to ask our testers a question or request a retest once you’ve remediated. Set an ‘acceptable risk’ where you’ve made a considered decision not to fix something yet, so the noise drops and your team focuses on what’s live.
And when a finding needs to reach your developers, our Jira and IT service management (ITSM) integration pushes it straight into their workflow. One customer used to copy every vulnerability into a ticket by hand; now the same job takes minutes.
How this maps to CREST? Retesting and post-test support are what separate a mature testing service from a one-off report. This is where CREST-grade testing turns into measurable risk reduction.
Control, access, and audit-ready evidence
As soon as more than one team relies on the portal, who sees what matters. Role-based access control (RBAC) lets you decide exactly that, project by project – useful when you’ve assets and teams spread across an organisation.
Every report we’ve ever sent you sits in one place too: penetration test reports, security advisories, and high-impact notifications, filterable by project and going back years. Customers can also generate their own reports on demand. When an auditor asks for evidence against ISO 27001, PCI DSS, SOC 2, or GDPR, it’s already there.
Finally, asset tags let you organise assets by site, brand, or business unit. A hotel group, for example, can tag every asset by the property it belongs to and filter the whole portal by location.
How this maps to CREST? Secure data handling and controlled access aren’t extras; they’re core to the CREST standard and the ISO 27001 alignment behind it.
One platform, every type of testing
Web application, infrastructure, mobile, API, cloud, configuration review, or social engineering: whatever the test, you’ll work with the results in the same place. One-off or continuous, it’s one view of your security testing, not a folder of disconnected reports.
CREST-grade testing, made manageable
Choosing a CREST-accredited provider tells you the testing was done to a recognised standard by qualified people. What you do with it is up to your team, and that’s where our portal earns its place. Everything above exists to close the gap between a finding and a fix.
If you’d like to see it, we’ll walk you through the portal and how our CREST penetration testing works in practice. Talk to our team to book a demo.
