Remote Access & VPN Penetration Testing
Remote access VPN penetration testing against SSL VPN, IPsec and Citrix gateways. We test the edge attackers hit first, fixed price with a full report.
Remote access VPN penetration testing puts your remote-work edge under the same pressure a real attacker applies: the SSL VPN portal, the IPsec tunnels, the Citrix and RDP gateways that let staff in from anywhere. These devices sit at the boundary between the internet and everything you care about, and a single flaw here often means the whole network.
What remote access and VPN penetration testing covers
The remote-access appliance is the most attacked box on many corporate networks, and for good reason. It is exposed to the entire internet by design, it terminates trusted sessions, and the vendors behind it have shipped a steady run of critical vulnerabilities. When one of those appliances falls, the attacker is already inside, past the firewall, holding a foothold that looks like a legitimate user.
Our testing covers the full remote-access stack rather than just running a version scanner against the portal. We examine the gateway software and its known weaknesses, the authentication and MFA flow, session handling after login, and what a user can actually reach once the tunnel is up. The goal is to find the path from an anonymous internet client to sensitive internal systems, then help you close it.
How we test your remote-access edge
We work in phases that mirror a real intrusion, starting from an anonymous position on the internet and building access as far as your controls allow.
Reconnaissance and fingerprinting
First we identify exactly what is exposed: the vendor and model of each gateway, the software version, the authentication methods on offer, and any secondary services the appliance exposes. Version detection matters here because the remote-access space has seen so many critical bugs. An out-of-date Fortinet, Ivanti or Citrix box is often exploitable before login even happens.
Authentication attacks
Next we pressure the login. We test resistance to credential stuffing using breach data tied to your domains, run controlled password-spray checks that respect lockout thresholds, and probe the MFA implementation for bypasses. Weak second factors, tokens that can be replayed, and portals that reveal valid usernames all get flagged. This is where many real breaches actually begin.
Exploitation and known vulnerabilities
Where a gateway runs a version affected by a known flaw, we verify the exposure safely rather than assuming the version banner tells the truth. The last few years brought pre-authentication vulnerabilities in SSL VPN products from several major vendors, some enabling remote code execution on the appliance itself. We confirm whether yours is genuinely affected, with evidence, and without knocking the device over.
Post-access and segmentation
Getting a tunnel is not the end of the story. Once connected, we assess what a compromised remote user can actually reach. A flat network where the VPN drops you next to the domain controllers is a very different risk from one where remote users are boxed into a tightly segmented zone. We test split-tunnel configuration, lateral-movement paths and whether the session can be hijacked or extended.
Vulnerability classes we find on remote-access systems
Certain weaknesses recur across the remote-access engagements we run for European clients.
Unpatched appliance vulnerabilities
SSL VPN and gateway appliances are patched far less often than the servers behind them, partly because taking the remote-access edge down disrupts everyone. That lag is exactly what attackers exploit. Pre-authentication path traversal, authentication bypass and remote code execution have all appeared in mainstream products, and unpatched boxes remain live targets long after a fix ships.
Weak or bypassable MFA
Plenty of gateways technically have MFA but implement it in a way that can be sidestepped: a legacy protocol that skips the second factor, an enrollment flow an attacker can hijack, or push notifications vulnerable to fatigue attacks. We test whether your MFA actually stops a valid password from being enough.
Over-permissive access after login
The most common configuration failure is not at the perimeter, it is inside. When the tunnel grants broad network access instead of least-privilege routing, one phished VPN credential becomes access to file servers, databases and admin interfaces. We map exactly how far a single account reaches.
Session and token weaknesses
Sessions that never re-authenticate, tokens that can be replayed from another location, and portals that leak internal details all extend an attacker’s window. We check the full lifecycle of a remote session, not just the moment of login.
Information leakage before login
Remote-access portals often reveal more than they should before anyone authenticates: internal hostnames, software build numbers, valid usernames through timing or error differences, and version banners that hand an attacker a precise target list. We flag every pre-authentication leak, because reducing that noise makes your edge meaningfully harder to profile and attack.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
You receive a report your network team can act on immediately, plus the summary leadership needs to understand the risk.
Findings with proof and CVSS
Every finding includes a clear impact statement, a CVSS score, the exact steps to reproduce it, and a prioritized fix. Where a known CVE applies, we cite it and confirm your specific exposure rather than relying on a version guess. Screenshots and request captures back up each issue.
A remediation and hardening plan
Beyond the individual fixes, we give you a hardening path for the remote-access edge: patch priorities, MFA improvements, and segmentation changes that shrink the blast radius of a stolen credential. A free retest confirms the fixes held.
Evidence for auditors
The report is written to satisfy external-testing requirements under the frameworks you work to, so the same engagement that hardens your edge also feeds your compliance file.
Compliance and standards mapping
Remote-access testing supports several obligations that European organizations carry.
ISO 27001 and PCI DSS
ISO 27001:2022 control A.8.20 addresses network security and A.8.21 the security of network services, both directly relevant to remote-access design. For anyone handling cardholder data, PCI DSS 4.0 requirement 11.4 mandates regular penetration testing of the environment, and remote access into the cardholder data environment is squarely in scope.
NIS2 and DORA
NIS2 pushes essential and important entities to secure remote access as part of network-security and access-control measures, and a documented VPN penetration test is strong evidence of that. Financial entities under DORA can use the results within their ICT risk-management and resilience testing. We map each finding to the framework you name.
Why manual testing beats a version scanner
A vulnerability scanner reads the banner on your gateway, matches it to a CVE list, and files a ticket. That approach produces false positives when a vendor back-ports a fix without changing the version string, and false negatives when the real problem is a configuration choice no scanner understands. Our engineers confirm whether an appliance is genuinely exploitable, test the MFA and session logic by hand, and, crucially, walk the path from the internet to your internal systems the way an attacker would. The difference is knowing whether your edge would actually hold, not just what version it claims to run.
Remote-access architectures we test
Remote access has moved well beyond a single VPN concentrator, and we test the range of designs European organizations now run.
Traditional and always-on VPN
Classic SSL VPN and IPsec setups, whether user-initiated or always-on, remain the backbone for most companies. We test the concentrator, the client authentication, and the routing that decides what a connected device can reach. Always-on designs deserve particular scrutiny because a compromised endpoint is effectively permanently on your network.
Cloud and vendor-hosted gateways
Cloud-delivered remote access and vendor-hosted gateways shift some risk to the provider, but not the authentication, the authorization, or the integration with your identity system. We test those layers and the trust you place in the service, since a misconfigured cloud gateway exposes the same internal systems a physical appliance would.
Zero-trust access and its gaps
Many organizations are moving from network-level VPN to zero-trust access that brokers each application individually. Done well it shrinks the blast radius considerably. Done partially, it leaves a VPN running alongside it as a soft backdoor. We test both the new broker and any legacy path that undermines it, because attackers target the weakest route in, not the one on your architecture diagram.
Pricing
Pricing depends on how many gateways and remote-access services are exposed, whether we test authenticated access with credentials you provide, and how deep the internal segmentation review goes. Testing only the external edge costs less than a full external-plus-internal assessment.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Edge assessment | Single VPN or gateway, external testing, version and CVE verification, authentication and MFA checks, report | 3–5 working days | from €1,800 |
| Standard remote access | Multiple gateways or protocols, authenticated testing, session-handling review, exec + technical report | 5–8 working days | €2,500–€6,000 |
| Edge plus segmentation | Remote-access testing combined with an internal segmentation review of what the tunnel can reach | 8–12 working days | from €3,000 |
| Compliance add-on | Mapping and attestation for PCI DSS, ISO 27001, NIS2 or DORA external-testing requirements | with any tier | from €800 |
| Custom / large estate | Many sites and gateways or a full remote-workforce environment, scoped to your needs | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote
FAQ
How much does remote access VPN penetration testing cost?
Will the test knock our VPN offline?
Do you check for the recent Fortinet, Ivanti and Citrix vulnerabilities?
Can you test whether our MFA can be bypassed?
Do you test what happens after someone connects?
Does this satisfy PCI DSS or NIS2 requirements?
How long does the engagement take?
What will you deliver?
Related services
Any European organization with a remote or hybrid workforce reaching in through an SSL VPN, IPsec tunnel or Citrix and RDP gateway. It is especially relevant if you run an appliance from a vendor with a recent critical CVE, are preparing for PCI DSS or NIS2, or have never tested what a stolen VPN credential could actually reach. If your remote workforce grew quickly during the shift to hybrid work and the edge was stood up under pressure, this is exactly the review it needs.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.