Home/Services/External Network Penetration Testing
security service

External Network Penetration Testing

External network penetration testing across Europe: attack-surface discovery, perimeter CVEs, password spraying. From €1,800, free retest. Get a quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

External network penetration testing looks at your organisation exactly as an attacker on the internet sees it: the services you meant to expose, the ones you forgot, and the single weak login or unpatched appliance that turns your perimeter into an open door. We find the way in before someone else does, then hand you the fix in priority order.

What external network penetration testing actually covers

Your external footprint is bigger than you think. It is not just the corporate website and the mail server; it is the VPN appliance nobody has patched, the staging box left on a public IP, the old admin panel behind a URL someone bookmarked two years ago, and the login page that will happily accept ten thousand password guesses. An attacker starts by mapping all of it, and so do we. An external network pen test is the exercise of finding every internet-facing asset you own and testing whether any of them gives up a foothold.

A full engagement typically covers:

Full attack-surface discovery: hosts, subdomains, shadow assets and forgotten services
Perimeter devices: VPN gateways, firewalls and remote-access appliances with known CVEs
Exposed services: RDP, SSH, databases and management interfaces that should not be public
Authentication attacks: password spraying, credential stuffing and weak or default logins
Web-facing applications on the perimeter, tested for the flaws that lead to server access
Email and DNS exposure: SPF, DKIM, DMARC gaps and information leakage that aids an attacker

How we run an external network penetration test

The work is manual and led by an engineer, with automated tooling used for what it is good at: fast, broad coverage of a large address space. A scanner can tell us which of a thousand ports are open in an hour. It cannot tell us that the open port is a forgotten Jenkins instance with no password that leads to your source code. That judgement, and the exploitation that proves it, is the test.

Reconnaissance and discovery

We start where the attacker starts, with open-source intelligence and enumeration. We map your IP ranges, discover subdomains, and hunt for the assets that never made it onto anyone’s inventory. Shadow IT and forgotten infrastructure are where a surprising number of real breaches begin, so we spend real effort making the target list complete before we test anything.

Scanning and service analysis

With the surface mapped, we identify every live host and the services running on it using tools such as nmap, then analyse each service for version, configuration and known vulnerabilities. This is where automated scanning earns its place, and also where a scanner’s raw output has to be verified by hand, because a report full of false positives helps nobody.

Exploitation

Here we confirm what is actually exploitable. We test perimeter appliances against known CVEs, run controlled password-spraying and credential-stuffing attacks against exposed logins, probe web applications for the flaws that yield server access, and chain findings together where one weakness enables the next. Every finding is demonstrated, not assumed, so you know the difference between a theoretical risk and a genuine way in.

Reporting and retest

You get an executive summary for leadership and a technical report with every finding, its CVSS score, the exact reproduction steps, and a prioritized fix your team can action. If we find something critical, you hear about it the same day rather than at the end. After you remediate, a free retest confirms the fixes hold.

48h
typical time to first findings
100%
manual verification, no raw scanner dumps
Free
retest after you fix

The weaknesses we find most often

External estates fail in familiar ways, and the causes are rarely exotic. A handful of issues account for most of the serious footholds we report.

Unpatched perimeter appliances

VPN gateways, firewalls and remote-access appliances are a favourite target because a single known CVE on one of them can hand an attacker straight into the internal network. Several of the largest breaches of recent years started exactly here. We check every edge device against the vulnerabilities that matter and confirm whether it is genuinely exploitable.

Exposed management and remote access

RDP open to the world, SSH with password authentication, database ports reachable from any IP, admin panels that were only ever meant for the office. These are found constantly, and each is an invitation to a brute-force or credential-stuffing attack. We find them and test how hard they would be to walk through.

Weak and reused credentials

An exposed login with no rate limiting and no multi-factor authentication is a slow-motion breach. We run careful password-spraying against the services in scope, using common and organisation-specific patterns, and show you which accounts would fall to an attacker doing the same thing without your permission.

Forgotten and shadow assets

The staging server on a public IP, the marketing microsite nobody maintains, the old subdomain still pointing at a decommissioned host. Assets nobody remembers are rarely patched and often the softest target on the perimeter. Discovery is not a formality in our process, it is frequently where the real finding comes from.

What you get

The deliverable is built to be acted on. Leadership gets a clear read on external risk and the handful of findings that matter most, and your technical team gets every issue with its impact, a CVSS score, reproduction steps and a specific remediation, ordered so the internet-facing critical gets fixed before the informational note.

Where a finding reflects a process gap rather than a one-off mistake, such as no asset inventory or no patching cadence for edge devices, we say so, because fixing the process prevents the next exposure rather than just closing this one. The free retest then confirms your fixes held under the same pressure that found the issue.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

External and internal testing together

An external test answers one question: can an attacker get in from the internet? It does not tell you what happens next. Once inside, through a phished employee or a compromised laptop, an attacker moves laterally, escalates privilege and hunts for domain admin, and only an internal test reveals how far that goes. Many organisations scope internal and external network penetration testing together for exactly this reason, so they understand both the way in and the damage once someone is inside. Where you need the internal view as well, we scope both as one coordinated engagement.

Standards and compliance

We build the assessment to satisfy the frameworks that require regular external testing.

PCI DSS

PCI DSS requires external penetration testing at least annually and after significant change, under requirement 11.4. Our report and attestation letter are structured to meet that obligation and to give your assessor what they expect to see.

ISO 27001 and SOC 2

Both frameworks expect regular, evidence-based technical testing of internet-facing systems. The report supports your certification and audit, and the attestation letter documents that an independent external test was carried out.

DORA and NIS2

For financial entities under DORA and operators of essential services under NIS2, external testing is part of demonstrating operational resilience. We are a European team and structure the evidence to fit how these obligations are being applied across the EU.

How often you should test

An external test is a snapshot of a moving target. Your perimeter changes every time a new service goes live, a firewall rule is edited, or an appliance ships a new firmware, and any of those can open a door that was shut last quarter.

Annually and after significant change

At a minimum we recommend an annual test, which is also what PCI DSS and most frameworks expect, plus a test after any significant change to the perimeter such as a new internet-facing application or a migration. Testing only once and treating the result as permanent is one of the more common mistakes we see.

Continuous discovery between tests

Because shadow assets appear between engagements, lightweight attack-surface discovery in the intervening months catches the forgotten staging box before an attacker does. It is a cheap insurance policy against the finding that would otherwise wait a full year to surface.

Why manual testing beats an automated scan

An automated vulnerability scan is a starting point, not an external penetration test, and the two are often confused because some vendors sell the first while calling it the second. A scanner lists potential issues, many of them false positives, and stops there. A penetration test verifies which of those issues is real, exploits the ones that matter, and chains them into the actual attack an intruder would run. The value is in the verification and the exploitation, because a fixed list of five hundred maybes is not security, and knowing the one unauthenticated appliance that hands over your network is.

Pricing

Pricing depends on scope, and for external testing that mostly means the number of live hosts and services exposed to the internet. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Essential Small perimeter, up to a handful of live hosts, full discovery, exploitation and report, free retest 3–5 working days from €1,800
Standard Typical SME estate, broader host range, perimeter web apps and authentication attacks, exec + technical report 5–8 working days €2,500–€6,000
Advanced Large or complex external footprint, multiple sites and services, deep attack-chaining to a demonstrated foothold 8–15 working days €6,000–€15,000
External + internal External test plus an internal assessment of lateral movement and privilege escalation from inside the network on scoping from €4,500
Custom / large estate Extensive perimeter across many hosts and sites, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote

FAQ

How much does external network penetration testing cost?
External network penetration testing cost starts from €1,800 and is priced by the number of live hosts and services exposed to the internet. You get a fixed quote after a free scoping call, so there are no hourly surprises.
How long does the test take?
A typical external network pen test runs 3–8 working days plus the report, depending on how large the perimeter is. If we find something critical, you hear about it the same day, not at the end of the engagement.
What is the difference between external and internal testing?
An external test attacks your perimeter from the internet to find the way in; an internal test starts from inside the network and maps lateral movement and privilege escalation. Many organisations scope internal and external network penetration testing together to see both the entry point and the blast radius.
What will you actually deliver?
An executive summary for leadership and a technical report with every finding, its CVSS score, the exact steps to reproduce it, and a prioritized fix. A free retest confirms your fixes hold.
Does this satisfy PCI DSS, ISO 27001 or SOC 2?
Yes. The report and attestation letter are written to satisfy PCI DSS requirement 11.4 external testing, along with ISO 27001, SOC 2, DORA and NIS2 expectations. Tell us your framework and we align the deliverables.
Will the test disrupt our services?
No. We test carefully, agree any noisy checks such as password spraying in advance, and can run intrusive steps out of hours. Availability is never the price of finding a hole.
Is this just a vulnerability scan?
No, and that distinction matters. A scan lists possible issues and stops; our external network penetration testing services verify what is real, exploit what matters, and chain findings into the attack an intruder would actually run.
Do you work with clients across Europe?
We are a European external network penetration testing company and provider working with clients across Europe and remotely worldwide, so your perimeter can be tested wherever it is hosted.

Related services

Who needs this

Any organisation with an internet-facing presence: companies facing a PCI DSS, ISO 27001, SOC 2, DORA or NIS2 requirement for regular external testing; teams after a merger or rapid growth who are unsure what is exposed; and security owners who want proof that the perimeter holds before an attacker tests it for them.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "External Network Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.