Penetration Testing / FOCUSED SERVICE

External Network Penetration Testing

Testing of your internet-facing perimeter from an outsider’s position, confirming what is exposed and attempting exploitation by hand.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

External network penetration testing shows what an attacker on the internet can reach and do with your perimeter. We start from public sources: domain and certificate records, address-range ownership, cloud-hosted assets tied to your brand, and credentials exposed in past breaches. We then map the services listening across the agreed ranges to confirm what is actually reachable. Exploitation is by hand: exposed admin interfaces, unpatched remote-access and mail systems, default passwords, weak encryption settings, and cloud storage left readable. Password guessing against your sign-in systems stays within agreed lockout limits. Optional follow-on work shows what a foothold reaches. You receive an exposed-asset inventory checked against your own list, findings rated for severity, and a retest after you remediate. We do not perform denial-of-service testing, and provider rules prohibit it.

WHEN THIS IS THE RIGHT FIT

For security and infrastructure teams that own public-facing systems and need external exposure confirmed before an attacker, an insurer, or a PCI DSS testing cycle does. Common before a renewal or after a cloud migration.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Confirm scope and assets

We agree in-scope domains, IP ranges, and third-party-hosted assets in writing, decide whether to allowlist our source addresses, and set spraying windows and lockout thresholds. You name one emergency stop contact, and any cloud-hosted assets get their provider rules applied.

Enumerate and exploit

We gather intelligence from public domain, certificate, and breach sources, then map the services listening across the ranges. Exploitation is manual: exposed admin panels, unpatched remote-access and mail systems, default passwords, weak encryption settings, and password guessing against your sign-in systems, within the limits we agree.

Report, fix, and retest the perimeter

You receive an exposed-asset inventory checked against your list, an attack narrative, and findings rated for severity with reproduction steps and fixes. After remediation we retest the closed items and issue a shareable attestation letter for customers and insurers.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Organizations with internet-facing systems, remote access, and cloud-hosted assets tied to their domains
  • Security and infrastructure teams asked to prove external exposure to insurers or customers
  • Companies subject to an annual external testing requirement under a recognized standard
  • Businesses whose perimeter has grown through acquisitions, migrations, or unmanaged cloud accounts
WHEN IT’S TIME TO ENGAGE
  • A cyber-insurance renewal or customer questionnaire asks for a recent external test
  • A migration, new public service, or domain change expanded the internet-facing footprint
  • Credentials or subdomains tied to your brand surfaced in public breach data
  • An annual or PCI DSS external testing cycle is coming due
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Discover internet-facing assets from public domain, certificate, and address-range records

  • Confirm listening services across the agreed ranges against your asset inventory

  • Attempt exploitation of exposed admin interfaces, remote access, and mail systems by hand

  • Test password guessing against the agreed sign-in systems within set lockout limits

  • Check exposed cloud storage, encryption settings, and credentials leaked in past breaches

  • Optional post-exploitation to show what an external foothold can reach

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.

Small
$2,400–$3,600

Up to 25 internet-facing addresses, one office, a few public services

About 16–24 hours
Mid-size
$4,200–$6,600

26 to 150 internet-facing addresses across a few sites or cloud providers

About 28–44 hours
Large
$7,200–$12,000

150 to 500 internet-facing addresses, multiple brands, domains, or acquired networks

About 48–80 hours
WHAT MOVES THE PRICE
  • Number of live internet-facing addresses and services
  • Number of domains, brands, and cloud providers tied to your name
  • Remote access, email, and sign-in systems to test
  • Testing windows and lockout limits that slow password checks
TYPICAL TIMELINE

1–2 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Exposed-asset inventory compared against your own authoritative list
  • Findings with reproduction steps, severity ratings, and evidence per exposed service
  • Retest of exploitable findings plus a shareable attestation letter

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Will this knock over our production services?

We plan it so it does not. We do not perform denial-of-service testing, and the major cloud providers prohibit it outright in their testing rules. Password guessing stays within the lockout limits we agree in writing, and you hold a stop contact who can pause any activity. Reconnaissance and service mapping are low-impact, and we schedule the noisier steps with you so production stays available.

Does this satisfy PCI DSS external testing?

It provides the external penetration test that PCI DSS expects, performed by someone organizationally independent of the systems tested, with a documented methodology and a retest of exploitable findings. Whether your cardholder data environment passes is a determination your Qualified Security Assessor makes, not us. We give you the report and the evidence they will want to review.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security