Network

External network pentest

A test of your internet-facing estate — including the hosts nobody remembers standing up — covering what is exposed, what is exploitable and what a determined attacker could do with the credentials your people reuse.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Most external compromises do not start with a novel exploit. They start with something that should not have been reachable: a forgotten test host, a remote access portal without multi-factor, an appliance a patch cycle missed.

We start by finding what you actually expose — which is frequently more than the list you have — then we test it the way an attacker would, including the credential attacks that need no vulnerability at all.

PTES NIST SP 800-115 OSSTMM

What we test

  • Attack-surface discovery: domains, subdomains, IP ranges, cloud estate and forgotten hosts
  • Service enumeration, version exposure and default or leftover configuration
  • Edge devices: VPN concentrators, firewalls, mail gateways and remote access
  • Known-exploitable vulnerabilities, validated by hand rather than reported from a banner
  • Password spraying and credential reuse against exposed portals, within agreed limits
  • Multi-factor coverage gaps across every authentication surface you expose
  • Administrative interfaces, management ports and default credentials
  • Information leakage from certificates, headers, error pages and public repositories
How it runs

From scoping call to retest, here’s what happens.

Typically one to two weeks, depending on the size of the exposed estate.

1

Scope and authorize

We confirm ranges and domains in writing, agree rules of engagement and notify you of the test window.

2

Discover the real surface

We map what is reachable from the internet and bring back anything that is exposed but not on your list.

3

Test what answers

Every live service is probed, fingerprinted and — where a real issue exists — exploited under the agreed rules.

4

Try the front door

Credential attacks and multi-factor gaps are tested with agreed lockout-safe thresholds.

5

Report, readout and retest

You get an evidenced report ordered by what to fix first, a readout, and a retest when fixes land.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Hosts and services nobody on the current team knew were exposed

Remote access portals where multi-factor is optional or partially deployed

Edge appliances running versions with public, working exploits

Management interfaces reachable from the whole internet

Valid credentials recovered through spraying or reuse of breached passwords

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • The IP ranges and domains you own, and written confirmation you own them
  • Your hosting or cloud provider’s testing policy, where one applies
  • Agreed test windows and an escalation contact
  • Whether we should test blind or with your asset list in hand

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.