Skip to content

Penetration testing

External Network Testing

What an attacker on the internet can see, reach and exploit before anyone at your company notices.

Why it matters

What this protects you from

  • Your perimeter is larger than your inventory

    Most organisations discover during testing that they are exposing hosts nobody remembered were running.

  • Exposure is continuous, testing is not

    A service published for a migration two years ago is still published. Attackers scan for exactly that.

  • Credentials leak outside your network

    Employee credentials surface in third-party breaches and get reused against your perimeter. That path needs no exploit at all.

  • The first foothold is the expensive one

    Almost every serious incident starts with one externally reachable weakness. Everything after it is cleanup.

Coverage

What we test

  • Attack surface discovery

    Subdomain enumeration, IP range validation, and identification of hosts and services you may not have inventoried.

  • Service enumeration and fingerprinting

    Open ports, running services, software versions and end-of-life components across the confirmed scope.

  • Credential and information exposure

    Public and breach-sourced credential exposure, exposed documents, metadata and other openly available intelligence.

  • Authentication surfaces

    VPN portals, webmail, remote access and admin interfaces, tested for weak configuration and credential attacks within agreed limits.

  • Misconfiguration and exposed management

    Default credentials, open administrative interfaces, permissive access rules and unnecessary exposure.

  • Exploitation of identified weaknesses

    Confirmed exploitation where it is safe and in scope, to establish real impact rather than theoretical severity.

Approach

Three ways to run it

  • Black box

    We start from your organisation name alone and discover the perimeter as an attacker would. The most realistic option.

  • Grey box

    You supply a confirmed IP and domain inventory, and testing depth goes into the hosts rather than into finding them.

  • White box

    Inventory plus network documentation and firewall rules, so exposure can be compared against what was intended.

Process

How the engagement runs

  1. Scoping and authorisation

    We agree address ranges, domains, exclusions and testing windows in writing, with authorisation confirmed before anything starts.

  2. Discovery and enumeration

    Full external discovery and enumeration to establish what is actually reachable, then validation of each host against the agreed scope.

  3. Vulnerability identification

    Automated and manual identification of weaknesses, with every automated result verified by hand before it reaches a report.

  4. Targeted exploitation

    Controlled exploitation of confirmed weaknesses to establish real impact. Denial of service is always excluded.

  5. Reporting and remediation

    Findings written with affected hosts, evidence and remediation steps, prioritised by what actually reduces exposure fastest.

  6. Retest

    After remediation we retest the affected hosts and issue a retest summary confirming closure.

Standards

What we test against

NIST SP 800-115
The assessment structure follows the NIST technical guide, which is what procurement and audit teams expect referenced.
OSSTMM
Methodology discipline and scope control, so testing stays inside agreed boundaries and results are repeatable.
PTES
Execution standard for intelligence gathering and exploitation phases, keeping discovery systematic rather than ad hoc.
MITRE ATT&CK
Findings are mapped to initial access techniques, so results line up with how your defensive team already models threats.

Deliverables

What lands in your inbox

  • Executive summary

    A plain-language account of perimeter exposure, written for the people who approve the remediation budget.

  • Overall security grade

    A single grade derived from the most severe confirmed finding, using published thresholds.

  • Confirmed asset inventory

    What we found exposed, which is frequently more than the inventory you started with.

  • Detailed technical findings

    Every finding with CVSS vector, CWE classification, affected hosts and reproduction steps.

  • Proof-of-concept evidence

    Evidence for each finding, captured from our declared testing IP range so every action is traceable.

  • Retest summary

    Issued after remediation, confirming what is closed and what remains exposed.

Find out what an attacker would find first.