The challenge behind the engagement.
External network penetration testing shows what an attacker on the internet can reach and do with your perimeter. We start from public sources: domain and certificate records, address-range ownership, cloud-hosted assets tied to your brand, and credentials exposed in past breaches. We then map the services listening across the agreed ranges to confirm what is actually reachable. Exploitation is by hand: exposed admin interfaces, unpatched remote-access and mail systems, default passwords, weak encryption settings, and cloud storage left readable. Password guessing against your sign-in systems stays within agreed lockout limits. Optional follow-on work shows what a foothold reaches. You receive an exposed-asset inventory checked against your own list, findings rated for severity, and a retest after you remediate. We do not perform denial-of-service testing, and provider rules prohibit it.
For security and infrastructure teams that own public-facing systems and need external exposure confirmed before an attacker, an insurer, or a PCI DSS testing cycle does. Common before a renewal or after a cloud migration.
What we do.
What you can use.
Confirm scope and assets
We agree in-scope domains, IP ranges, and third-party-hosted assets in writing, decide whether to allowlist our source addresses, and set spraying windows and lockout thresholds. You name one emergency stop contact, and any cloud-hosted assets get their provider rules applied.
Enumerate and exploit
We gather intelligence from public domain, certificate, and breach sources, then map the services listening across the ranges. Exploitation is manual: exposed admin panels, unpatched remote-access and mail systems, default passwords, weak encryption settings, and password guessing against your sign-in systems, within the limits we agree.
Report, fix, and retest the perimeter
You receive an exposed-asset inventory checked against your list, an attack narrative, and findings rated for severity with reproduction steps and fixes. After remediation we retest the closed items and issue a shareable attestation letter for customers and insurers.
Who it’s for.
When you need it.
- Organizations with internet-facing systems, remote access, and cloud-hosted assets tied to their domains
- Security and infrastructure teams asked to prove external exposure to insurers or customers
- Companies subject to an annual external testing requirement under a recognized standard
- Businesses whose perimeter has grown through acquisitions, migrations, or unmanaged cloud accounts
- A cyber-insurance renewal or customer questionnaire asks for a recent external test
- A migration, new public service, or domain change expanded the internet-facing footprint
- Credentials or subdomains tied to your brand surfaced in public breach data
- An annual or PCI DSS external testing cycle is coming due
What the scope can include.
- 01
Discover internet-facing assets from public domain, certificate, and address-range records
- 02
Confirm listening services across the agreed ranges against your asset inventory
- 03
Attempt exploitation of exposed admin interfaces, remote access, and mail systems by hand
- 04
Test password guessing against the agreed sign-in systems within set lockout limits
- 05
Check exposed cloud storage, encryption settings, and credentials leaked in past breaches
- 06
Optional post-exploitation to show what an external foothold can reach
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
Up to 25 internet-facing addresses, one office, a few public services
About 16–24 hours26 to 150 internet-facing addresses across a few sites or cloud providers
About 28–44 hours150 to 500 internet-facing addresses, multiple brands, domains, or acquired networks
About 48–80 hours- Number of live internet-facing addresses and services
- Number of domains, brands, and cloud providers tied to your name
- Remote access, email, and sign-in systems to test
- Testing windows and lockout limits that slow password checks
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Exposed-asset inventory compared against your own authoritative list
- Findings with reproduction steps, severity ratings, and evidence per exposed service
- Retest of exploitable findings plus a shareable attestation letter
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Will this knock over our production services?
We plan it so it does not. We do not perform denial-of-service testing, and the major cloud providers prohibit it outright in their testing rules. Password guessing stays within the lockout limits we agree in writing, and you hold a stop contact who can pause any activity. Reconnaissance and service mapping are low-impact, and we schedule the noisier steps with you so production stays available.
Does this satisfy PCI DSS external testing?
It provides the external penetration test that PCI DSS expects, performed by someone organizationally independent of the systems tested, with a documented methodology and a retest of exploitable findings. Whether your cardholder data environment passes is a determination your Qualified Security Assessor makes, not us. We give you the report and the evidence they will want to review.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
