External network penetration test
Find out what an attacker can reach from the internet.
I test your network perimeter, whatever it is made of: VPNs, bastion hosts, SFTP and FTP servers, proxies, gateways, and anything else that faces the internet.
What gets tested
Your perimeter, mail, and DNS.
Mail and DNS records are part of the external network, and they are often overlooked.
- Perimeter
- VPNs, bastion hosts, proxies, gateways, and the other hosts and services in scope that face the internet.
- SSH, SFTP, and FTP
- Remote access and file transfer: the versions and settings they expose, and whether they let an outsider in.
- DNS
- Records that point at something you no longer control, such as a subdomain someone else could claim, or an A record for an address you have given up.
- SPF, DKIM, and DMARC, including subdomains whose DMARC policy is weaker than the main domain's.
How a test runs
From scoping to retest.
- 01
Scoping
We agree on the addresses and hostnames in scope, the testing window, and the rules of engagement.
- 02
Testing
I map what is exposed, test it for weaknesses, and show where any way in leads.
- 03
Report
An executive summary you can share, and the full report: each finding with its evidence, its severity, and how to fix it.
- 04
Retest
Once you have fixed the findings, I test them again.
- Timeline
- Two weeks
- You get
- An executive summary you can share
- The full report
- One retest
- Source address
- Testing comes from the manual-testing address listed on the Scanning page.
The business case
Enterprise customers, vendor security reviews, and cyber insurance applications often ask for a recent third-party penetration test. The executive summary is written to be shared with them.
The compliance case
Supporting evidence for:
- SOC 2 CC4.1, CC7.1
- HIPAA §164.308(a)(8)
- ISO 27001 A.8.8
- PCI DSS 11.4.3, 11.4.4
- NIST CSF ID.RA-01, ID.IM-02
- NIST 800-53 CA-8
References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, ISO/IEC 27001:2022 Annex A, PCI DSS v4.0.1, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.
Pricing
A fixed fee, quoted after a scoping call.
External network tests start at $5,000.
The price depends on how many internet-facing addresses and hostnames are in scope.
The fee covers the scoping call, the test, the executive summary, the full report, and one retest.
Start with a conversation.
The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.