Penetration Testing

A scan tells you what might be wrong.
A test tells you what an attacker can do about it.

We test your network the way someone attacking it would — from the public internet and from inside your own walls. You get a severity-ranked list of what we found, a remediation roadmap grouped by root cause, and a retest that proves the fixes held.

The problem

Scanners find issues. Attackers find paths.

Most businesses have some form of vulnerability scanning running. It produces a list. The list is long, mostly informational, and nobody has time to read it.

That list has a specific blind spot: it evaluates findings one at a time. A scanner does not know that the shared password on a printer is also the password on a file server, or that a legacy protocol nobody remembers enabling is quietly handing out credentials to anything that asks.

An attacker does not work through a list. They chain findings together — a weak credential here, a cleartext protocol there — until the chain reaches something worth stealing. Individually, each link looks like a medium. Together they're a domain compromise.

Penetration testing is what closes that gap. Instead of listing what's exposed, we attempt the attack and document how far it gets.

Two assessments

External and internal are not the same assessment

These get sold as one product and they answer completely different questions. We run them as two separate engagements because the results almost never look alike.

External penetration test Internal penetration test
Perspective An attacker on the public internet who has never touched your network An attacker who is already inside — a phished user, a contractor laptop, a compromised printer
Question it answers Can someone break in from outside? Once someone is in, how far do they get?
What we assess Public-facing hosts, web and mail services, SSL/TLS configuration, exposed directories and services, information about your business that’s publicly discoverable Credentials and password practices, protocol security, system configuration, outbound filtering, lateral movement between systems
Typical exposure Small and shrinking — most businesses have very little truly exposed Large and persistent — the internal network was built for convenience, not for hostility

If you only buy one, buy the internal test. The external perimeter is the part most businesses have already gotten right. The internal network is the part nobody has ever tested.

What we find

Four root causes account for most of it

Every finding in a report is a symptom. When we group them by cause, internal assessments come back to the same four issues almost every time.

Password deficiencies

Weak, shared, reused, or still-default credentials. This is the most common finding and the most consequential one, because a working password does not look like an attack in any log. It looks like a login. Access to one system usually becomes access to several, and from there to documents nobody intended to share.

Insecure protocols

Communication protocols that send data — including credentials — in cleartext. They are almost never turned on deliberately. They’re enabled by default on something, or left behind by a device that was replaced years ago, and they quietly broadcast to anyone listening on the same network.

Configuration deficiencies

Systems and services deployed without a hardening baseline. Some of these are only exploitable in narrow circumstances, which is exactly why they survive audit after audit. The impact when they are exploitable is not narrow at all.

Egress filtering deficiencies

Firewalls that carefully control what comes in and barely look at what goes out. This is how an attacker establishes a channel back to themselves, and it’s how data leaves. Most outbound rules were written to make something work on a deadline, and never revisited.

Grouping findings this way matters more than the count. Fixing thirty individual findings is a project nobody finishes. Fixing four root causes closes most of the thirty and prevents the next batch.

The engagement

What actually happens

1

Scope of work, agreed in writing first

Before anything runs, we define which systems are in scope, which assessment phases we’ll perform, and what “safe to exploit” means in your environment. You sign it. Nothing outside it gets touched.

2

Discovery

We find what’s actually there. This routinely surfaces more systems than the scope listed — the scope describes what you think you have, discovery describes what you have.

3

Enumeration

Services, versions, configurations, exposed directories, protocol support, certificate and TLS posture. For external tests this also includes what’s publicly discoverable about your business through search engines and social media — the reconnaissance an attacker does before touching anything you own.

4

Controlled exploitation

We attempt the attack. Only exploits judged safe for a production environment are executed, and the intent is validation, not disruption — proving a vulnerability is real rather than theoretical.

5

Severity ranking and rollup

Every finding gets a severity. Findings then get grouped into root-cause categories so remediation is four workstreams instead of thirty tickets.

6

Remediation roadmap

Specific strategies per root cause, written for the people who have to implement them. Where it applies, we map to recognized baselines such as the NIST standards.

7

Retest

We run it again and compare. You get trend data across every assessment, not a standalone PDF.

Honest limits

What a penetration test is not

A clean external report is a real result and it's worth having. It is also narrower than it sounds, and any provider who lets you believe otherwise is selling you something.

It’s a point in time

A clean result describes the systems in scope, on the day tested, in the configuration they were in. A firewall change on Thursday can undo a Tuesday result.

It’s bounded by scope

We test what we agreed to test. Systems outside the scope were not assessed, and “not assessed” is not the same as “secure.”

Zero findings is not zero risk

Third-party services, vendor dependencies, and configuration drift are all live risk that a network penetration test doesn’t measure.

It doesn’t test your people

Credential theft through phishing bypasses most of what a network assessment covers. That’s a separate assessment, and for most businesses it’s the more likely entry point.

It is not compliance by itself

It’s evidence you can hand to an auditor, an insurer, or a customer. It isn’t a certification.

We put this on the page because the alternative is a client believing a clean report means they're finished. That belief is more dangerous than the findings.

Fit

Who this is for

Businesses that have never been tested

If nobody has ever tried to break in on purpose, the first internal assessment is the most informative thing you’ll do this year.

Businesses whose customers or insurers are asking

Contracts, cyber insurance applications, and vendor security reviews increasingly require assessment evidence.

Businesses that have grown faster than their network

New sites, new systems, new integrations, and a firewall configuration that has been added to but never audited.

Businesses that already run security tooling

EDR, email filtering, and monitoring are worth having. A penetration test is how you find out what they miss.

FAQ

Common questions

Will testing take our systems down?

The scope defines what’s safe to run before anything starts, and we only execute exploits judged safe for a production environment. Denial-of-service testing is excluded unless you specifically ask for it and we plan a window for it.

How long does it take?

Fieldwork for a small to mid-sized network is typically a few days. Scoping happens before, reporting happens after. The scoping conversation is where the timeline for your environment gets set.

What do we get at the end?

An executive summary written for people who don’t work in IT, a technical report with every finding and its severity, a root-cause rollup, and a remediation roadmap. If it’s not your first test, you also get trend data comparing this assessment to previous ones.

How often should we do this?

For most businesses, annually as a baseline, plus a retest after significant remediation or a material change to the network. Higher-risk or regulated environments warrant more frequent testing.

Can you fix what you find?

Yes, and we’ll be direct about the tension in that: the party finding the problems also sells the fix. The findings are severity-ranked and evidence-backed so you can hand the report to anyone — including another provider — and the report stands on its own.

Do you need internal access to run the internal test?

Yes. An internal assessment simulates an attacker who already has a foothold, so it starts from a position inside your network. How that access is provided is part of scoping.

Find out what's actually reachable

The scoping conversation costs nothing and is useful on its own — it will tell you which assessment you actually need and what it would cover.

Trusted by dozens of businesses