Skip to content
MD-5

// Network Pentest

Network Penetration Testing

External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.

Overview

Your external attack surface is whatever the internet can reach: firewalls, VPNs, mail servers, forgotten staging servers and cloud hosts someone spun up two years ago. Internal networks are what an attacker reaches after one phished laptop.

A network penetration test maps both, identifies exploitable weaknesses, and demonstrates, safely and within agreed rules, how far an attacker could get.

Who this is for

  • Businesses with on-premise infrastructure or a hybrid cloud estate
  • Organizations that need an annual external test for insurance or compliance
  • Teams that have never had their exposed services independently reviewed

What gets tested

External

  • Discovery of exposed hosts, services and forgotten assets
  • VPN, remote access, mail and web server weaknesses
  • Default credentials, outdated software and misconfigurations

Internal (remote or on-site)

  • Network segmentation and exposed internal services
  • Active Directory configuration weaknesses
  • Credential exposure and privilege escalation paths

Cloud-hosted infrastructure

  • Publicly exposed storage, databases and management ports
  • Security group / firewall rule review for in-scope hosts

What you receive

  • Asset inventory of what was found to be exposed
  • Prioritized findings with evidence and remediation
  • Attack-path narrative showing how issues chain together (internal tests)
  • Live readout call to walk your team through the results
  • Retest of fixed findings and an updated report
  • Letter of attestation you can share with customers and auditors

Standards followed

  • PTES
  • NIST SP 800-115
  • MITRE ATT&CK
  • CVSS v3.1 / v4.0

Read the full testing methodology.

// Process

How the engagement runs

  1. 01 Day 0

    Scope

    A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.

  2. 02 Days 1 to 10

    Test

    Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.

  3. 03 +3 days

    Report

    A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.

  4. 04 When you’re ready

    Retest

    Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.

// FAQ

Network Pentest questions

Will testing disrupt our systems?

No denial-of-service testing is performed unless explicitly agreed. Testing windows, rate limits and emergency contacts are agreed in the rules of engagement before anything starts.

How does remote internal testing work?

You run a small, pre-configured virtual machine or device inside your network that we connect to over an encrypted tunnel. It’s removed at the end of the test.

Do you need permission from our hosting provider?

Most major cloud providers no longer require pre-approval for testing your own resources, but some hosting companies do. We check this during scoping.

// Further reading

// Also available

Other services

Web App Pentest

An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.

API Pentest

Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.

Vulnerability Assessment

A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.