Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

External penetration testing: what a stranger on the internet can reach

External penetration testing looks at your organisation from the outside, the way an opportunistic attacker does. It finds the exposed services, weak edges and forgotten hosts before someone else does.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
External penetration testing: find what is exposed, test each service and close the doors

Why external penetration testing is usually the first test

Your internet edge is the part anyone can touch. Because it is public, it is also the part scanned by automated attacks every day. So an external test gives the fastest reduction in real risk for the money.

It is also the test customers ask for most often in security questionnaires, alongside an application test.

What external penetration testing looks at

We start from the domains and IP ranges you give us. Then we look for anything you did not list, because forgotten assets are where most surprises live.

  • Remote access such as VPNs and remote desktop gateways
  • Mail, file transfer and legacy services left running
  • Admin panels and login pages exposed by mistake
  • Old hosts left over from a migration
  • Cloud services that ended up public

Before you book external penetration testing

Tick what you have ready. The more you can list, the faster the scope is fixed.

Your result appears here as you tick, so you can see what is still open.

Assets you did not know you had

Discovery matters as much as testing. For example, a subdomain left pointing at a retired server, or a test environment made public for a demo, often turns out to be the weakest point. However, we only test what you confirm you own. Anything outside the signed scope is reported to you, not touched.

How external penetration testing is reported

The report lists each exposed service, what we proved with it, and the fix. In addition, it names the method, which follows NIST SP 800-115. You also receive a short attestation letter for customers who only need proof that the work took place.

After remediation, one retest inside 30 days confirms the doors are actually shut.

What drives the external penetration testing price

Our published range is $4,000 to $20,000. The main driver is the number of live hosts and services, followed by how many different technologies sit on the edge. A single website and mail server sits low in the range. On the other hand, several data centres with VPN appliances sit higher.

External penetration testing questions

How is external penetration testing different from internal?

External starts from the internet with no access. Internal starts from inside your network, as if a laptop or account were already compromised.

Will our users notice?

Normally not. We agree the noisier steps and their timing with you in advance.

Do we need to tell our hosting provider about external penetration testing?

Some providers ask for notice, and many cloud providers publish their own rules. We check them with you during scoping.

Is a vulnerability scan enough?

Not for most auditors. A scan lists possible issues, while a test shows which ones an attacker could actually use.

Related guides

Book external penetration testing with a fixed fee

Send your domains and IP ranges. We reply with a written scope and price, and testing starts after you sign the authorisation.

Get my estimate