An external penetration test that shows what an attacker could reach
Our testers attack your internet-facing systems the way a real attacker would, then show you what they found and how to fix it. After you fix the issues, we test again at no extra cost.

Up to 25 external IP addresses
Each test covers up to 25 internet-facing IP addresses, such as firewalls, remote access gateways, mail servers and websites.
Exploitative or not, your choice
Choose a non-exploitative test that finds weaknesses, or an exploitative test that proves which ones can be used to break in.
Proven tools
We use Metasploit, tools from the Open Worldwide Application Security Project (OWASP) and Kali Linux, alongside commercial subscription-based tools.
Web application checks
Web applications are tested for SQL injection, broken authentication, cross-site scripting, broken access control and the rest of the OWASP Top 10.
Free retest
Once you fix the findings, we test again for free to confirm the fixes work.
Clear reports
Management and executive reports list critical vulnerabilities, best-practice recommendations and every test performed.
Why test from the outside
Your firewalls, remote access gateways and public websites face the internet every day. An external penetration test shows which of them an attacker could break into and how, so you fix the real gaps first. Our testers bring experience from financial institutions, where security standards are strict.
How the test works
We agree on the targets and whether the test may exploit what it finds. Our testers then scan and probe each target with the same tools attackers use and, if agreed, try to exploit the weaknesses they find. Web applications are checked against the OWASP Top 10 list of the most critical web application risks.
What you receive
You get a report that lists critical vulnerabilities, recommends fixes based on best practice and documents every test performed. When you have fixed the issues, we run the test again at no extra cost to confirm.
Questions buyers ask
What does the test cover?
An external test of up to 25 IP addresses that face the internet. Testers use an automated toolkit alongside standard attack tools to find and, if you agree, exploit weaknesses.
What is the difference between an exploitative and a non-exploitative test?
A non-exploitative test finds and reports weaknesses without using them. An exploitative test goes further and tries to use them, which proves the real impact. We agree on the approach with you before we start.
How often should we test?
Each engagement covers one test. Many organizations test at least once a year and after major changes to their internet-facing systems, and we offer better pricing for recurring tests.
How much does a penetration test cost?
Pricing depends on the scope. Contact us for a quote.
Get a quote
Tell us about your environment. We reply within one business day with scope, timing and price.