Challenges we solve
Annual pen tests aren't enough any more. Your attack surface changes daily — your security testing should too.
Point-in-time testing leaves gaps
A traditional penetration test gives you a snapshot. But new vulnerabilities emerge every day, and the gap between tests is where attackers thrive. By the time your next annual assessment comes around, your risk profile has changed entirely.
Too many findings, not enough context
Automated scanners generate noise. Without expert verification and business-context risk scoring, your team wastes time chasing false positives while genuinely critical vulnerabilities sit unpatched.
Your application estate keeps growing
Every new web application, API, and infrastructure change expands your attack surface. Keeping track of what needs testing — and ensuring nothing slips through the net — becomes a challenge in itself.
No dedicated vulnerability management function
You know vulnerability management matters, but building an in-house programme with the right tooling, processes, and expertise is expensive. You need a partner who can extend your security team, not replace it.
What is Continuous Security Testing?
Continuous Security Testing (CST) is Claranet's always-on vulnerability management service. It combines automated scanning with expert-led manual penetration testing to identify and verify vulnerabilities across your applications, APIs, and external and internal infrastructure and endpoints on an ongoing basis.
Rather than a one-off engagement, CST runs continuously. Your assets are scanned regularly, findings are manually verified by our testers to remove false positives and add business-context risk scoring, and everything is surfaced through the Cyber Portal — a single dashboard where your team can track, prioritise, and manage remediation.
The result? Your vulnerability management programme becomes fast, fine-tuned to your estate, and backed by penetration testers who act as an extension of your own security team. You reduce the workload of remediating vulnerabilities by doing it little and often, rather than facing a wall of findings once a year.
CST is designed to complement, not replace, the rest of your security programme: many customers run it alongside our Penetration Testing service for compliance-driven point-in-time engagements, our External Attack Surface Monitoring service to keep testing focused on the assets that matter, and our Managed Detection and Response service to detect and respond to live threats.
Key Benefits
- Continuous scanning with expert manual verification
- CVSS-scored findings with remediation advice
- Cyber Portal dashboard for live vulnerability tracking
- High-impact vulnerability notifications within 15 minutes
- Re-testing on demand to confirm remediation
- Monthly reports at executive, management, and technical levels
Continuous Security Testing vs traditional penetration testing
Both are genuine, CREST-accredited testing delivered by the same team of expert penetration testers - the difference is timing and depth of coverage.
| Traditional Penetration Testing | Continuous Security Testing | |
|---|---|---|
| Timing | Scheduled engagement, scoped via a Statement of Work | Always-on, with scanning running continuously |
| Coverage between tests | None — your risk profile can change entirely before the next test | Ongoing scanning and monthly manual testing (tier-dependent) close this gap |
| Best suited to | Compliance deadlines, one-off assessments, new system launches | Estates that change frequently — active development, growing application counts, regular releases |
| Reporting | Single report at the end of the engagement | Live dashboard via the Cyber Portal, plus monthly reports |
Many organisations run both: an annual Penetration Testing engagement for point-in-time compliance assurance, alongside Continuous Security Testing to close the gap in between. They're complementary services, not competing ones.
Why Claranet?
Continuous testing expertise, delivered at scale.
Service tiers
Five tiers let you match the depth and frequency of testing to the criticality of each asset — and your budget.
Tier 0
Automated unauthenticated scanning with manual vulnerability verification. Always used for infrastructure assets.
Tier 1
Automated scanning with tailored options: custom headers, scanning intensity, time windows, and authenticated scanning.
Tier 2
Adds limited dedicated manual penetration testing each month to uncover advanced vulnerabilities.
Tier 3
Dedicated penetration testing time for complex applications. Deeper coverage of your attack surface.
Tier 4
Additional dedicated penetration testing for complex and business-critical applications requiring the deepest analysis.
Technical capabilities
Here's what powers your Continuous Security Testing service under the bonnet.
Automated continuous scanning
We scan your internet-facing applications, external infrastructure, internal infrastructure, APIs and endpoints on an ongoing basis. Open port monitoring identifies changes from the previous month, and variations are investigated manually by our testers.
Manual verification and CVSS scoring
Every finding is manually verified by our testers. False positives are removed, each vulnerability is evaluated for business impact, exploitation probability, and difficulty — then classified using the CVSS framework for clear prioritisation.
Cyber Portal
Your single pane of glass for vulnerability management. Track live findings, filter by region, department, or asset tag, access monthly reports, and dive into the detail of each vulnerability — all with CVSS scoring and remediation guidance from our testers.
High-impact and zero-day notifications
When a high-impact vulnerability is verified, you're notified within 15 minutes — with a detailed description, remediation advice, and steps to reproduce. Our team also monitors for zero-day disclosures relevant to your environment.
Re-testing and remediation support
Fixed a vulnerability? Request a re-test at any point and we'll verify it's been remediated effectively. We also provide on-demand remediation support to help your team prioritise and act on findings.
Multi-level monthly reporting
Each month you receive a comprehensive report covering executive summaries for leadership, prioritised vulnerability lists using CVSS v3.1 for management, and detailed technical analysis with evidence and reproduction steps for your engineering team.
Testing methodologies
Our testing follows industry-recognised frameworks to ensure thorough, consistent, and compliant assessments.
OWASP
Open Worldwide Application Security Project — the gold standard for web application security testing, covering the OWASP Top 10 and beyond.
WSTG
The Web Security Testing Guide provides comprehensive methodology for testing web application security controls and identifying weaknesses.
NIST SP 800-115
The National Institute of Standards and Technology's technical guide to information security testing and assessment — ensuring systematic, repeatable results.
PCI DSS
Payment Card Industry Data Security Standard supplement — ensuring your testing meets the requirements for organisations handling cardholder data.
Accreditations & partnerships
Our security testing is backed by the certifications and accreditations that matter.


Data security
Your vulnerability data is treated with the care it deserves.
Encryption
256-bit AES-GCM symmetric encryption at rest. TLS 1.2 and 1.3 in transit. Public-key cryptography for data sharing on a need-to-know basis. SFTP for large file transfers.
Sovereignty and storage
All data is stored in AWS within the European Union. Unfixed vulnerabilities retained for the contract duration. Fixed vulnerabilities available for 12 months. All data deleted 90 days after contract termination.
Access control and vetting
Role-based access control with two-factor authentication. All testers undergo criminal records checks, employment references, and credit history verification. Regular internal security auditing.
Proven results
Ready to stop playing catch-up with your vulnerabilities?
Whether you need always-on scanning for a handful of assets or a full continuous testing programme, we'll scope a service that fits. Let's talk.
Talk to a security testing specialist
Or call us on 0330 390 0507
Frequently asked questions
-
Continuous Security Testing (CST) is Claranet's always-on vulnerability management service. It combines automated scanning with expert-led manual penetration testing to identify and verify vulnerabilities across your applications, APIs, and infrastructure on an ongoing basis, rather than as a single annual snapshot.
-
PTaaS is the industry term for exactly this kind of subscription-based, tiered, always-on testing model. Continuous Security Testing is Claranet's version of it — the two terms describe the same service.
-
Not necessarily — it's designed to complement it. Organisations with compliance-mandated annual testing (for PCI DSS, ISO 27001, or client requirements) typically keep that engagement and add CST to cover the gap in between, rather than replacing one with the other. For organisations that also want to test how their people and defensive controls hold up under a live, simulated attack, our Red Team Exercise service goes a step further.
-
Continuous Security Testing suits organisations whose applications and infrastructure change often enough that an annual test can't keep up — frequent releases, active development, growing API and application counts, or infrastructure that scales up and down. It's also a fit if you're currently relying on in-house vulnerability scanning without the manual verification and business-context risk scoring needed to separate genuine risk from noise.
It's designed to sit alongside your existing compliance testing, not replace it: organisations with mandated annual penetration testing (for PCI DSS, ISO 27001, or client contractual requirements) typically keep that engagement and add Continuous Security Testing to cover the gap in between.
-
Traditional penetration testing is a scheduled, scoped engagement that gives you a snapshot at a single point in time. Continuous Security Testing runs on an ongoing basis, closing the gap between engagements with continuous scanning and regular manual verification. Many organisations run both — traditional testing for compliance deadlines, CST to cover the time in between.
-
Automated scanning runs continuously. The amount of dedicated manual penetration testing depends on your service tier — Tier 0 relies on automated scanning with manual verification of findings, while Tiers 2 to 4 add increasing amounts of dedicated manual testing time each month.
-
Applications, APIs, and external and internal infrastructure and endpoints.
-
Every finding is manually verified by Claranet's testers to remove false positives, then evaluated for business impact, exploitation probability, and difficulty, and classified using the CVSS framework. High-impact findings trigger a notification within 15 minutes.

