UTMStack

An external penetration test that shows what an attacker could reach

Our testers attack your internet-facing systems the way a real attacker would, then show you what they found and how to fix it. After you fix the issues, we test again at no extra cost.

A protected system surrounded by network nodes, probed by beams of light
  • Up to 25 external IP addresses

    Each test covers up to 25 internet-facing IP addresses, such as firewalls, remote access gateways, mail servers and websites.

  • Exploitative or not, your choice

    Choose a non-exploitative test that finds weaknesses, or an exploitative test that proves which ones can be used to break in.

  • Proven tools

    We use Metasploit, tools from the Open Worldwide Application Security Project (OWASP) and Kali Linux, alongside commercial subscription-based tools.

  • Web application checks

    Web applications are tested for SQL injection, broken authentication, cross-site scripting, broken access control and the rest of the OWASP Top 10.

  • Free retest

    Once you fix the findings, we test again for free to confirm the fixes work.

  • Clear reports

    Management and executive reports list critical vulnerabilities, best-practice recommendations and every test performed.

What’s included

  • External test of up to 25 IP addresses
  • Testing with an automated toolkit and standard attack tools
  • Exploitative or non-exploitative testing, as agreed with you
  • Checks for SQL injection, broken authentication, sensitive data exposure, XML external entities, broken access control, security misconfiguration, cross-site scripting, insecure deserialization, components with known vulnerabilities, and insufficient logging and monitoring
  • Report with critical vulnerabilities, best-practice recommendations and the full list of tests
  • Management and executive reports
  • Free retest after you fix the findings

Why test from the outside

Your firewalls, remote access gateways and public websites face the internet every day. An external penetration test shows which of them an attacker could break into and how, so you fix the real gaps first. Our testers bring experience from financial institutions, where security standards are strict.

How the test works

We agree on the targets and whether the test may exploit what it finds. Our testers then scan and probe each target with the same tools attackers use and, if agreed, try to exploit the weaknesses they find. Web applications are checked against the OWASP Top 10 list of the most critical web application risks.

What you receive

You get a report that lists critical vulnerabilities, recommends fixes based on best practice and documents every test performed. When you have fixed the issues, we run the test again at no extra cost to confirm.

Questions buyers ask

What does the test cover?

An external test of up to 25 IP addresses that face the internet. Testers use an automated toolkit alongside standard attack tools to find and, if you agree, exploit weaknesses.

What is the difference between an exploitative and a non-exploitative test?

A non-exploitative test finds and reports weaknesses without using them. An exploitative test goes further and tries to use them, which proves the real impact. We agree on the approach with you before we start.

How often should we test?

Each engagement covers one test. Many organizations test at least once a year and after major changes to their internet-facing systems, and we offer better pricing for recurring tests.

How much does a penetration test cost?

Pricing depends on the scope. Contact us for a quote.

Get a quote

Tell us about your environment. We reply within one business day with scope, timing and price.

We reply within one business day. See our privacy policy.