A practical guide for executives on building a penetration testing programme that boards, customers and insurers can trust.

October is Cyber Security Awareness Month. It’s a good time to check whether your leadership team can answer four simple questions about security testing.

Cyber security used to start and finish with the IT director. Now it turns up in the board pack, the customer questionnaire and the insurance renewal. When something goes wrong, it’s the chair, the CEO or the CFO who gets asked why.

We see this across the 1,200+ UK organisations we work with. As a CEO who reports to a board, I recognise it too. The leadership teams who handle it well treat cyber as a business risk they own, and they can back up what they say with evidence.


Why It’s on the Board Agenda

The board. Boards have seen it happen. The Government’s Cyber Security Breaches Survey 2025/26 found that 69% of large and 65% of medium-sized UK businesses had a breach or attack in the past 12 months. Many directors have been through one or watched a peer go through one, and they’re asking harder questions.

Customers. Customers want proof. Verizon’s 2025 Data Breach Investigations Report found third-party involvement in breaches doubled in a year, from 15% to 30%. Supplier questionnaires now ask who tested you, when, to what standard and what you fixed. A vague answer slows the deal down, and sometimes loses it.

Cyber insurers. Insurers want evidence on day one. We’re seeing renewals that used to take a fortnight now take six weeks when the evidence isn’t ready. Through our partnership with Capsule, the same evidence can also lower your premium.

AI adoption. Then there’s AI. If your business hasn’t formally adopted it, your suppliers probably have, and some of your staff are likely using tools nobody approved. That needs a policy, approved tools, testing and training, with someone senior who owns it.

Compliance requirements. And regulation is tightening. Since April 2026, the Cyber Essentials declaration, signed by a board member or director, commits the organisation to maintaining every control for the full certification period. The Cyber Security and Resilience Bill, now at committee stage in the House of Lords, will add tighter incident reporting and stronger enforcement.


Reduce your cyber insurance premium with CyberLab and Capsule.

Through our partnership, the evidence from your security testing can convert directly into savings on your premium.

Speak to us to find out how much you could save.

Get in Touch

Four Questions to Answer

The fix is simpler than it sounds. You and your executive team should be able to answer these four questions, with evidence:

  1. When was our last independent penetration test?
  2. Who did it, and to what standard?
  3. What did they find, and what have we fixed?
  4. What are we doing differently this year as a result?

If you can answer all four, you’re in a strong position. If you can’t, the gap is usually smaller than it feels. Close it before it becomes a board paper or a lost deal.

Not sure how you'd score? Get a free Security Posture Assessment

What Good Penetration Testing Looks Like

Good testing is planned around your risks and spread across the year. Use an accredited tester: CREST and CHECK are the standards I’d ask for. Findings should be ranked by business impact, with a clear plan to fix them.

That last point matters. Edgescan’s 2025 Vulnerability Statistics Report found 45% of vulnerabilities in large enterprises were still unpatched after 12 months, and 17% of those were high or critical. In my experience the reason is usually simple: nobody turned the finding into a business risk that someone owned.

The CyberLab Difference

That’s where we put our effort. After every test, our consultants sit down with your team in a report review session. We go through the findings and agree what to fix first, based on how your systems are built, what data is at risk and where you are with compliance. Something that looks critical on paper may matter less in your environment, and the reverse is also true.

How We Structure a Programme

One test is a snapshot. A test in January tells you nothing about the API your developers release in June, or a critical vulnerability disclosed in September. So we help clients plan a year of testing, for example infrastructure, web application and social engineering, timed around their risks, compliance deadlines and budget. We agree scope and cadence up front, usually quarterly or twice a year, and review progress at each stage.

Success in Action

Moat Homes, a South East housing association managing more than 20,000 homes, took this approach. Its internal IT team couldn’t watch for threats around the clock, so it combined penetration testing with Sophos MDR and our wraparound support.

Read all Success Stories

Podcast: Hacking Critical Infrastructure Explained with CyberLab

This episode puts the boardroom questions above into practice. Adam Myers sits down with Steve Clarke, Head of Penetration Testing at CyberLab, to explore what proper testing looks like when the systems involved keep the lights on, the water running and the trains moving, and why evidence of what was found and fixed matters even more when the risk is physical, not just financial.


Speak to an Expert

We’ve worked with more than 1,200 UK organisations on this. As a CREST-, CHECK- and NCSC-accredited cyber security consultancy and managed service provider, we deliver penetration testing programmes built for the audiences they need to serve: your board, your customers, your insurers, and your own technology team.

If the questions in this article are ones you’d rather be ahead of than behind, speak to one of our penetration testing experts to get a clearer view of where your cyber security posture is, and how to build a security testing programme that meets the needs of your business.

Speak with an Expert