External Penetration Test

A hands-on attempt to break into your internet-facing systems, carried out the way a real attacker would, and written up so you can act on it. This is a test by a person, not an automated scan — a scanner finds known issues, a tester finds the chain of three small ones that together let someone in.

What you get

  • Scoping session: what is in, what is out, and what must not be touched
  • Manual testing of exposed hosts, applications and authentication
  • A findings report ranked by what an attacker gets, not by generic severity
  • A remediation call to walk your team through the fixes
  • One free retest of the findings within 60 days

What this does not cover

  • Social engineering and phishing of your staff
  • Physical access testing
  • Fixing what is found — the remediation itself is quoted separately

Who it fits

A business that has to show a customer, an insurer or an auditor that someone competent has tried. Not a first security step: if nothing has been hardened yet, the baseline hardening finds more for less.