Skip to content
← All services

External Penetration Testing

Everything your business puts on the internet, your firewall, VPN, email, and web servers, gets tested from the outside, the way a real attacker would size it up. You get a clear picture of what an outsider could actually reach and do, explained in plain English, with a prioritized fix list. No scare tactics, no 200-page scanner dump.

Manual and automated testing. Transparent pricing from $4,000. Retest included.

Get a fair, fixed quote

External penetration testing is a hands-on security test of everything your business exposes to the internet, run from the outside, the same vantage point a real attacker has. It answers a simple, practical question: if someone with bad intent went looking, what could they actually reach, what could they get through, and what should you fix first? We map your internet-facing surface, test it by hand as well as with tooling, and write it up so you know where you stand. If you want the ground-level version first, our guide to what a penetration test is covers the basics in plain language.

What we test

Your internet-facing surface, mapped and tested

An external test starts by finding everything you actually expose, not just what the asset list says, then testing each piece the way an outsider would. Here is what typically lands in scope.

Firewall and perimeter

The edge of your network, where the internet meets your business. We test what is exposed, how it responds, and whether anything is reachable that should have stayed inside.

VPN and remote access

Remote-access portals are supposed to be on the internet. The questions that matter are whether they are patched, whether multi-factor authentication is enforced, and whether a stolen password alone gets someone in.

Email and your domain

Mail servers, login portals, and the records that let the world tell a real message from a spoofed one. We check whether an outsider could impersonate your domain or reach a mailbox they should not.

Public websites and portals

Your site, your customer login, any dashboard with a public address. We look for the exposure an automated scanner walks right past, and we hand the write-up to your developers in plain language.

Exposed services and admin interfaces

Databases, management consoles, and remote-desktop endpoints have a way of ending up on the internet by accident. If one is reachable that should not be, we find it and tell you first.

Your wider external footprint

Forgotten subdomains, a staging box someone spun up and never took down, credentials from an old breach that still work. The parts of your presence you have stopped thinking about are often the ones worth checking.

One thing worth saying plainly: having a VPN, a firewall, or a remote-access portal facing the internet is not a problem by itself. Those are supposed to be reachable. A real test checks whether they are patched, configured right, and behind multi-factor authentication, not whether they exist. We do not cry wolf about normal infrastructure.

How it works

From the first call to a confirmed fix

No jargon, no drama, no surprises. Five steps, and you always know what is happening and why. External testing is the easiest kind to get moving: most of the time it needs nothing from you but the go-ahead, since the work is done from the internet.

Curious what the write-up at the end looks like? We walk through it, section by section, in our guide to what a penetration test report looks like.

  1. 01

    Scope

    A short call to agree exactly what we test and when, with the rules of engagement and the scope put in writing before anything starts. External testing usually needs nothing from you but a yes and the go-ahead.

  2. 02

    Test

    We map what you actually expose to the internet, then test it by hand as well as with tooling. Automated scanning finds the known issues; a person finds the chain of small things that an outsider could actually string together.

  3. 03

    Report

    A clear report in plain English: what we found, how serious each item really is, and proof. An executive summary your leadership can read and a technical section your IT team or provider can act on.

  4. 04

    Fix list

    A prioritized, do-this-first remediation list. Your team or your existing IT provider makes the fixes, and we are happy to walk them through it on a call, in plain language.

  5. 05

    Retest

    Once the findings are fixed, we check the work and confirm the fixes hold. The retest is included on every tier, not billed back as an upsell.

What a test actually turns up

Exposed, reachable, exploitable: not the same thing

Plenty of tools will hand you a long list of everything facing the internet and call it a report. That is not useful, and it is not honest. The value is in the triage: of everything exposed, what is actually reachable, and of what is reachable, what could a real outsider get through. That last, short list is what your fix list is built from.

It is also why we do the work by hand, not just with a scanner. The difference between a scan and a real test is a person chaining findings together, and it is worth understanding the difference before you buy either one.

Pricing

What an external test costs

An external penetration test is our Small External tier, and it starts at $4,000. If you want internal testing too, from inside the network, that is the Medium Full tier at $6,500. The retest is included either way, not billed back as an upsell.

We publish our prices, which most firms will not do, so you can budget before the conversation instead of during it. The final number depends on the size of your environment and what is in scope, and the quote is fixed once we agree it.

Being sold a scan somewhere else?

The cheapest "external penetration test" on the market is often an automated scan with a logo on the report. For an insurance renewal or a serious client requirement, that difference matters, and people can tell. If you are comparing quotes, our plain guide to the two is worth five minutes.

Penetration test vs vulnerability scan

FAQ

External penetration testing: common questions

What is external penetration testing?
External penetration testing is a hands-on security test of everything your business exposes to the internet, run from the outside, the same vantage point a real attacker has. That covers your firewall, VPN, email, web servers, and any public login or admin interface. The goal is not a list of what you have facing the internet. It is an honest answer to which of those things an outsider could actually get through, and what to fix first.
What is the difference between external and internal penetration testing?
External testing looks at your business from the internet, before anyone is inside, and asks what an outsider could reach and exploit. Internal testing starts from the assumption that someone is already on the network, a phished laptop or a malicious insider, and measures how far they could get. Most first tests start external because that is the door the whole world can see. Many businesses add internal testing next.
Is having a VPN or firewall on the internet a security problem?
No. A VPN, a firewall, an email server, and a remote-access portal are supposed to be reachable from the internet. That is their job. An external test does not treat their existence as a finding. It checks whether they are patched, configured correctly, and behind multi-factor authentication. We do not cry wolf about normal infrastructure.
How much does external penetration testing cost?
External testing is our Small External tier, which starts at $4,000. The final number depends on the size of your environment and what is in scope, and the quote is fixed once we agree it. A retest of your fixed findings is included, not billed back as an upsell. We publish our prices so you can budget before the conversation, not during it.
How long does an external penetration test take?
Most small and mid-sized external engagements run about one to two weeks from scoping to report, depending on size and what is in scope. We agree the timeline with you during scoping so it fits around your operations. The one part on your clock rather than ours is the fixing, which is why we plan the retest into the schedule from the start.
Do you need to come on-site to run an external test?
No. External testing is done remotely by design, because it is performed from the internet, exactly where a real attacker would sit. That is normal and just as effective for this kind of work. On-site time only comes up for other assessments, like a wireless test that needs someone physically near your building.

Find out what an outsider can actually reach

Tell us a little about your business and what is prompting the test, an insurance renewal, a client requirement, or just wanting to know where you stand. We will come back with a scope and a fair, fixed quote. No pressure, no sales theater.