Get a quote
GRC Wave Graphics

External Network Penetration Testing

Our external network penetration testing service identifies and assesses exploitable vulnerabilities across your internet-facing systems, services and infrastructure before criminal hackers can use them.

What is an external network penetration test?

An external network penetration test is used to detect vulnerabilities and security issues in a network that could be exploited by criminal hackers.

An external network penetration test identifies vulnerabilities and security issues in your internet-facing systems that a criminal hacker could exploit from outside your organisation, without any existing access.

It involves identifying vulnerabilities, attempting to exploit them, and providing a report with risk ratings and remediation advice.

The target is typically the same as an internal network penetration test, but an external test starts with no authorised access, simulating what a criminal hacker could achieve from the internet. This makes it an essential part of a robust network security strategy, testing your perimeter defences before an attacker ever reaches your internal systems.

Our external network test assesses your specified internet-facing network devices and services, using both automated scans and advanced manual testing techniques to identify vulnerabilities and understand the wider information security risks to your organisation.

Speak to an expert

For more information on how our CREST- and CHECK-accredited penetration testing services can help safeguard your organisation, call us now on +44 (0)333 800 7000, or request a call back using the form below.

What is included in an external network penetration test?

Our external network penetration test covers:
  • Secure configurations
  • Network traffic
  • Secure passwords
  • Patching
  • Secure authentication
  • Encryption
  • Information leakage

Identified vulnerabilities are presented in a report that allows your organisation to assess business risks and remediation costs, so issues can then be resolved in line with your budget and risk appetite.

Testing

External vs internal penetration testing

  • External network penetration testing looks at internet-facing assets, such as your website, applications and network perimeter, to identify what a criminal hacker without existing access could exploit from outside your organisation.
  • Internal network penetration testing assesses what could happen if an attacker, employee or third party already has access inside your network, whether through a compromised account, physical access or malicious intent.

Many organisations run both types of test as part of a complete network security strategy.

cyber security assurance

Understanding your external attack surface

Your external attack surface is every internet-facing asset a criminal hacker could target: firewalls, VPNs (virtual private networks), web servers, file servers, exposed services and other public-facing infrastructure.

Because these systems are visible to anyone on the internet, they’re usually the first place a criminal hacker will look for a way in, whether through an unpatched service, a weak password or a misconfigured firewall.

External network penetration testing helps you understand which of these assets are exposed, how they could realistically be exploited and what needs to be fixed before an attacker finds them first.

Red team assessment report showing cyber security testing data and attack analysis

Common external network vulnerabilities we test for

During an external network penetration test, we commonly identify:
  • Weak or default passwords
  • Missing security patches
  • Insecure system and firewall configurations
  • Exposed or unnecessary services
  • Authentication weaknesses
  • Information leakage
  • Unencrypted network traffic

Each finding is assessed for its potential business impact, so you can prioritise remediation in line with your risk appetite and budget.

Is an external network penetration test right for you?

If you are responsible for your external network, you should ask yourself:
  • Are my systems fully patched and properly configured?
  • Are any systems or applications secured with weak or default passwords?
  • Have I accounted for all the services exposed to the Internet?
  • Could malware be present on my system?
  • Is every device secured by a correctly configured firewall?
  • Is my confidential information properly segregated or secured?
GRC Wave Graphics

Our external network penetration testing process

Our external network penetration test follows our proprietary security testing methodology, which is closely aligned with the SANS and OSSTMM (Open Source Security Testing Methodology Manual) methodologies.

This service assesses external network perimeter targets that you specify, such as file servers and web servers.

We use both automated scans and advanced manual testing techniques to assess your security and identify vulnerabilities. Our process typically includes:

  • Scoping – agreeing the systems, IP ranges and assets to be tested.
  • Scanning – running automated scans to map your external attack surface and identify potential vulnerabilities.
  • Manual validation – an ethical hacker manually verifies findings, removing false positives and uncovering issues automated tools miss.
  • Exploitation attempts – for Level 2 tests, our ethical hackers attempt to exploit identified vulnerabilities to demonstrate real-world impact.
  • Reporting – providing a clear report with risk ratings and practical remediation advice for technical and management teams.
  • Remediation guidance and retesting – supporting you to fix identified issues, with retesting available to confirm they have been resolved.

Types of external network penetration test

We offer two levels of penetration tests to meet your budget and technical requirements.

Level 1

A fixed-scope vulnerability assessment package for your external infrastructure, combining manual and automated scans. Allows you to evaluate your security posture and make more accurate budgetary decisions. Please contact us to purchase one of our quick, affordable and fixed-price penetration tests.

Level 2

Scoped according to your specific requirements, a level 2 test attempts to access your assets and resources by exploiting identified security vulnerabilities. Assesses your security posture in greater detail so you can make better decisions about investing in securing your business-critical systems. Please contact us to request a quote or speak to a penetration testing expert for further information.

Benefits of an external network penetration test

Our external network penetration tests will help you:
  • Identify and understand the technology-related vulnerabilities affecting your external infrastructure;
  • Understand the potential business impacts of vulnerabilities;
  • Demonstrate a strong security posture to clients by providing third-party assurances that your external infrastructure is secure;
  • Comply with ISO 27001, the UK Data Protection Act 2018 the UK GDPR, the PCI DSS, and other legal and contractual requirements; and
  • Protect brand loyalty and corporate image by reducing the likelihood of a security breach.

External network penetration testing also supports audit readiness, supplier assurance and security reviews, giving clients, auditors and other stakeholders independent evidence that your internet-facing infrastructure is secure.

CREST-accredited

CREST-accredited penetration testing services give you all the technical assurance you need.

Straightforward packages

We are pioneers in offering easy-to-understand and quick-to-buy penetration testing.

Choose your test

You can choose the level of penetration test to meet your budget and technical requirements.

Reports you can understand

We provide clear reports that can be followed by technical and management teams alike.

Our penetration tests comply with the Microsoft Rules of Engagement

For Azure clients, this means we take care to limit all penetration tests to your assets, thereby avoiding unintended consequences to your customers or your infrastructure.

Explore all our penetration testing services

View our complete range of application, Cloud, infrastructure and specialist security testing services

FAQs (frequently asked questions)

A Level 1 test is a fixed-scope vulnerability assessment that combines manual and automated checks to give you a clear, budget-friendly view of your security posture. A Level 2 test goes further: it’s scoped to your specific requirements and attempts to exploit identified vulnerabilities, giving you a more detailed assessment to support decisions about securing business-critical systems.

External network penetration testing is carried out in a controlled and authorised manner, with scope agreed in advance so testing stays limited to your specified assets. Our tests also comply with the Microsoft Rules of Engagement, so Azure clients can be confident that testing is limited to their own assets. This minimises the risk of disruption to your live services.

We’ll need the IP addresses, domains or hostnames in scope for testing, along with written authorisation to test them. Your penetration testing expert will confirm the full scoping requirements with you before testing begins.

Yes. A test report provides independent evidence that your internet-facing infrastructure has been assessed for vulnerabilities, which supports ISO 27001, the UK GDPR, the PCI DSS and other compliance requirements, as well as supplier assurance and security review processes.