Can an outsider get in?
External penetration test
An external penetration test is a manual, adversary-style assessment of every system your organization exposes to the internet. It answers one question with evidence: can an attacker with no prior access get in, and how far would they get?
What you get
- Exploitable perimeter weaknesses, confirmed by hand
- Exposed services and credentials you did not know about
- A prioritized fix list for the paths that lead inside
Overview
We attack your public footprint the way a real adversary would: web servers, VPN gateways, firewalls, exposed services, and the applications behind them. Anything reachable from the internet is in scope, and anything we can exploit we prove.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Public IP ranges, domains, and subdomains you own
- VPN, remote access, and email gateways
- Firewalls, load balancers, and edge appliances
- Internet-facing web applications and APIs at the perimeter level
- Exposed cloud storage and services tied to your domains
- Leaked credentials and secrets found in public sources
- Optional: password spraying against external authentication within agreed limits
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Reconnaissance
We enumerate your attack surface from open sources and active scanning, including assets nobody remembers deploying.
Enumeration and analysis
Every exposed service is fingerprinted, version-checked, and reviewed for misconfiguration and weak authentication.
Exploitation
Confirmed weaknesses are exploited by hand and chained together to reach the inside, always within the agreed rules of engagement.
Post-exploitation
From any foothold we show what an attacker could reach next: data, internal networks, or identity systems.
Reporting and debrief
Findings are ranked by real business impact and walked through live with your team.
Deliverables
- Executive summary written for leadership and auditors
- Technical findings with evidence, severity, and CVSS score
- Attack narrative showing how findings chain together
- Asset inventory of what we found exposed
- Prioritized remediation roadmap
- Attestation letter suitable for customers, auditors, and insurers
- One retest of remediated findings
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Exposed management interface with default credentials
- Severity
- Critical
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
An unauthenticated internet user could log in to a network appliance with vendor default credentials and gain administrative control of a device that routes traffic into the internal network.
Evidence
Authenticated session captured against the appliance login page using the vendor default account, followed by a configuration export containing internal addressing.
Remediation
Restrict management interfaces to the internal management network or VPN, rotate all default accounts, enforce MFA where the vendor supports it, and add the device to the patch and credential rotation process.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 1 to 2 weeks of testing, report within 5 business days
What affects it
Small perimeters finish in a week. Larger estates, or scopes that include password spraying, take longer. Retest is scheduled when your fixes are ready.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001, Cyber insurance, CMMC, NYDFS.
See the full requirement mappingFrequently asked questions
How long does an external penetration test take?
Typically one to two weeks of active testing followed by report delivery within five business days. The exact duration depends on the number of live hosts and applications in scope.
Is a retest included?
Yes. One retest of remediated findings is included, and we update the report and attestation letter to reflect the closed items.
What do we need to provide?
A list of IP ranges and domains you own, a point of contact for emergencies, any testing windows or systems to exclude, and written authorization. We handle the rest.
How is this different from a vulnerability scan?
A scan lists known vulnerabilities by version. A penetration test verifies which ones are actually exploitable in your environment, chains them together, and shows the real impact. The report contains proof, not possibilities.
Will testing disrupt production?
We avoid denial of service techniques by default and agree on testing windows for sensitive systems. Exploitation is controlled and coordinated with your named contact.
Related
Often paired with
Internal penetration test
What damage can an insider do?
Assume the perimeter has failed. Find out what happens next.
Learn moreWeb application test
Can this application be turned against its users?
Deep, manual testing of one application and its APIs.
Learn moreContinuous Threat Exposure Management
What is exposed right now, and does it matter?
A year-round testing program instead of an annual snapshot.
Learn moreReady to scope a external penetration test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.