Cloud, Security & Operations
Security Testing
Security checks built into the QA cycle for every release, including automated SAST, dependency and DAST scans, authorisation test cases and security regression tests, complementing periodic penetration tests.
Capability overview
What security testing involves
Annual penetration tests find vulnerabilities, but software changes every sprint. Security testing within quality engineering makes security a routine part of release verification, catching common weaknesses such as vulnerable libraries, missing access checks and injection flaws as they are introduced rather than months later.
We add static analysis, software composition analysis and dynamic scanning with tools such as Semgrep, SonarQube, Trivy and OWASP ZAP to test pipelines, write security-focused functional test cases based on OWASP ASVS requirements, and turn previously found vulnerabilities into regression tests. Deep manual exploitation remains the job of our penetration testing service. Results feed the same defect workflow as functional issues, so security fixes are planned, prioritised and verified alongside other work rather than handled as a separate, easily ignored report.

What is included
What is tested
Automated code and dependency scans
Static analysis and vulnerable dependency checks run on pull requests with severity thresholds.
Dynamic scanning
OWASP ZAP or similar scanners run against test environments for common web and API weaknesses.
Authorisation test cases
Role and object-level access tests ensuring users cannot view or change data belonging to others.
Input and session tests
Checks for injection, file upload validation, session timeout, logout and cookie security settings.
Security regression suite
Tests created for every fixed vulnerability so it cannot quietly return.
How we work
How we deliver security testing
Requirement mapping
Relevant OWASP ASVS requirements selected for the application's risk level.
Pipeline tooling
Scanners configured, tuned for false positives and connected to defect tracking.
Test case design
Security scenarios added to functional test plans for high-risk features.
Release verification
Scan results and security tests reviewed as part of release criteria.
Periodic deep testing
Findings shared with the penetration testing team to target manual assessments.
Related capabilities
Related capabilities in Quality Engineering & Testing
Web Application Testing
Testing focused on the specific risks of browser-based applications, including forms, sessions, file uploads, responsive layouts, accessibility, browser behaviour, caching and search-visible content.
Mobile Application Testing
Testing Android and iOS apps on real devices and emulators, covering functionality, interruptions, network conditions, permissions, battery and memory use, app store requirements and automation with Appium or native frameworks.
Compatibility Testing
Checking that web and mobile applications work consistently across browsers, operating systems, devices, screen sizes, assistive technologies and configurations your users actually have.
Test Automation Frameworks
Design and build of maintainable test automation frameworks your team can own, with clear architecture, reusable components, test data management, parallel execution, reporting and coding standards.
Explore further
Explore connected pages
Related services
Related solutions
Cloud Transformation Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Cybersecurity Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Managed Technology Solutions
Quality, infrastructure, managed services and dedicated team solutions. Acmez shapes managed…
Where this applies
Healthcare & Life Sciences
Technology systems for regulated environments where privacy, auditability and continuity…
Manufacturing & Industrial
Connected operations, asset, field, supply chain and industrial platforms for complex operating…
Banking, Financial Services & Insurance
Technology systems for regulated environments where privacy, auditability and continuity…
E-Commerce
Digital platforms for customer experience, operations, commerce, content, marketing and service…
Questions & answers
Questions about Security Testing
Cannot find what you need? Our team responds to technical and commercial questions within one business day.
Ask a questionNo. Routine security testing catches common and regression issues continuously. Penetration testing provides deeper manual analysis of complex vulnerabilities and chained attacks, typically annually or after major changes.
Fast scans run on each pull request, while full dynamic scans run nightly or before release, keeping developer feedback quick.
With training and clear test cases, QA engineers can execute many security checks effectively, supported by security specialists for tool tuning and interpretation.
Pipeline tooling setup is fixed price. Ongoing security test execution is included in QA engagements or priced per release.
Next step
Discuss security testing with Acmez
Share what you need to change, build, integrate or support. We will map the practical next step.