Contact

Contact the editors

One address for corrections and sources, another for listings. Both reach the editorial desk; using the right one gets you an answer sooner.

Last updated: September 2026

Addresses are placeholders

The mailboxes below are not live yet. They are published here so the contact routes are documented, and they will be activated on the domain before launch. If you need to reach us before then, the routes are the same — the addresses are simply not receiving mail today.

Corrections, sources and questions about a listing

editorial [at] best-external-penetration-testing-companies.com

Use this for a factual error, a source we should have consulted, a broken link, or a question about why a company is positioned where it is. We read every correction request and check it against the primary-source standard in our editorial policy before changing anything. If it means looking up a register entry or contacting a third party, expect a few days rather than a few hours.

The most useful correction you can send is a link. A register entry, a certificate reference, a dated press item with a named source — anything we can open and verify moves faster than a description of the problem.

Company inclusion or a listing update

listings [at] best-external-penetration-testing-companies.com

Please read Submit a company before writing. It sets out exactly which evidence our process needs, and a submission that arrives with that evidence attached is reviewed considerably faster than one that does not. Sending it to the editorial address instead will only add a hop.

Privacy requests

privacy [at] best-external-penetration-testing-companies.com

To ask what data we hold about you or to request deletion. See the privacy policy for what is collected and how long correspondence is kept.

What we cannot help with

  • We do not sell penetration testing. We are not a provider, reseller or broker, and we do not pass enquiries to vendors.
  • We cannot scope, budget or time your engagement. That conversation belongs with a shortlisted provider who can see your environment. Our buyer guide covers what to ask them.
  • We cannot tell you whether a framework applies to you. DESC, NESA, CBUAE and PCI DSS applicability is a question for your compliance team or counsel. We link the primary sources so you can take them the actual text.
  • We cannot guarantee a response deadline, and sending information does not guarantee a listing, an update, or any particular position.