Skip to content

Hedgehog Security

CREST-accredited UK penetration testing and offensive security firm, part of UK Cyber Defence Group, offering infrastructure, web application, network, and specialist wireless/airspace testing.

Visit Website ↗ + Add to Compare
48/100Emerging / Unranked

Overview

Hedgehog Security is a UK offensive security firm providing manual, framework-driven penetration testing — web application (against the OWASP Top 10), infrastructure, network, and specialist wireless/airspace testing — along with Cyber Essentials certification support. Its methodology combines standard testing frameworks with real-world offensive tradecraft such as Active Directory attack simulation, privilege escalation, and lateral movement, rather than relying on automated scanning alone.

Founded in 2010 by Peter Bassill and based at The Officers Mess on the historic RAF base at Duxford, Cambridgeshire, Hedgehog holds CREST, IASME, and NCSC-approved accreditation — independently audited credentials that validate both its testing methodology and assessor competency, rather than relying on self-certification.

Hedgehog is now part of UK Cyber Defence Group, which combines Hedgehog’s offensive security heritage with the CISO advisory practice of Erizo Cibernetica to offer a fuller offensive-plus-advisory capability set under one group.

As a boutique regional provider, Hedgehog’s credibility rests on CREST accreditation and specialist testing niches — including wireless spectrum and airspace security — rather than platform or product scale, competing on assessor quality and specialization rather than breadth of a software offering.

Innovation Matrix Assessment

Innovation Velocity 4/10

As a mature services business, evidence of a fast release cadence doesn't directly apply; the main recent development found is the formation of UK Cyber Defence Group rather than frequent new service launches.

Operational Value 6/10

Covers a genuinely broad set of testing disciplines — web, infrastructure, network, and specialist wireless/airspace testing — under CREST/NCSC-approved accreditation, indicating real operational capability for a boutique firm.

Market Momentum 4/10

Forming UK Cyber Defence Group with Erizo Cibernetica is a real growth signal, but no funding events or independently reported customer growth metrics were found, leaving momentum evidence limited.

Category Disruption 3/10

Penetration testing services are a mature, well-established market category; Hedgehog operates as a credible regional incumbent-style provider rather than a category disruptor.

Real-World Efficacy 6/10

CREST, IASME, and NCSC-approved accreditations are independent, third-party-audited credentials that directly validate testing methodology and assessor quality, stronger independent efficacy evidence than most unaccredited competitors can show.

Enduring Relevance 6/10

Penetration testing remains a persistent, often compliance-driven requirement (Cyber Essentials, PCI DSS) for UK organizations, keeping the service category relevant even if not high-growth.

Why CISOs Should Care

Offers CREST- and NCSC-approved assurance that its penetration testing methodology and staff meet independently audited, UK government-recognized standards, useful for CISOs who need defensible, accreditation-backed testing for compliance or board reporting.

What Makes It Different

Combines broad, CREST-accredited core testing services with specialist niches like wireless spectrum and airspace security testing that most generalist penetration testing firms don't offer.

The Matrix Verdict

48/100 — EMERGING / UNRANKED

A credible, accreditation-backed boutique UK offensive security provider — solid on quality assurance but limited in growth or disruption evidence, best suited to organizations prioritizing accredited assurance over platform scale.

Editorial Note: Claims vs. Verified Findings

CREST, IASME, and NCSC-approved accreditation status are independently verifiable through those bodies' own accreditation registers. Case study outcomes and specific engagement results referenced on the company's site are vendor-published and were not independently corroborated.

Sources