Skip to content
For MSPs and businesses

We find the weaknesses.
Before someone else does.

From vulnerability scans to hands-on penetration testing, Fig helps you understand where your systems are exposed and what to do next. MSPs can offer these services under their own brand and keep the client relationship.

Six services. The right depth for your needs.

Choose a focused review or combine services around the systems and risks that matter to you.

01 · Scanning

Vulnerability scanning

Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.

Explore vulnerability scanning
02 · Devices

Device security reviews

Review laptop and mobile-device protection, including encryption, screen locks, updates and lost-device risks.

Explore device security reviews
03 · Cloud

Cloud security reviews

Review AWS, Azure or Google Cloud configurations, including access permissions, exposed storage, account protection and logging.

Explore cloud security reviews
04 · Exposure

Public exposure checks (OSINT)

Identify information an attacker can find publicly, such as exposed files, leaked credentials and lookalike domains.

Explore public exposure checks
05 · Code

Code security reviews

Examine source code for weaknesses such as embedded secrets, unsafe input handling and missing access checks.

Explore code security reviews

For MSPs

Deliver testing under your own brand.

Keep the client relationship while Fig provides the specialist testing. We agree scope, permissions, reporting and client communications with your team before the engagement.

Use the Fig platform to manage findings, remediation tasks and evidence alongside your wider client work. Work with us to certify clients when they need a scheme assessment.

Explore the MSP partnership

Before you book

Practical questions about testing, scope and how we work with your team.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan checks for known weaknesses using automated tools. A penetration test adds manual investigation and attempts to exploit weaknesses within an agreed scope. They provide different levels of assurance and are not interchangeable.

Can an MSP offer these services under its own brand?

Yes. MSPs can white-label Fig’s security testing services and retain the client relationship. We agree the testing scope, permissions, reporting format and communication responsibilities before work begins.

How is penetration testing scoped and priced?

We agree the systems, testing depth, dates and written authorisation before testing. Your statement of work records the scope, fixed quote, deliverables and retest arrangements. Whitebox, greybox and blackbox approaches are available, depending on how much access and information you provide.

Does a security test provide certification or guarantee security?

No. Testing reports on findings within its agreed scope and testing period. It does not guarantee that every weakness has been found, and it is not a substitute for Cyber Essentials, Cyber Essentials Plus or DCC assessment.

Tell us what you need to test.

Share the systems involved, your objectives and any deadline. We’ll discuss the right scope and provide a quote.

Discuss a security test