See your network the way an attacker does.
External and internal network & infrastructure penetration testing that finds the way in — and how far it goes. Every finding is mapped to PCI DSS, NIST 800-53, ISO 27001, CIS Controls and SOC 2, so one engagement satisfies both your security and your audit.
What is a network penetration test?
A controlled, real-world attack simulation against your network and infrastructure — external (from the internet) and internal (from a foothold inside). It combines automated discovery with manual, safe exploitation to prove what an attacker could actually reach, then maps every finding to the compliance controls you report on.
External attack surface — what we test from the internet
Exposed services & open ports
Every internet-facing port and service is enumerated — the attacker's first map of your estate.
Unpatched & vulnerable services
Known-vulnerable software and missing patches on public-facing hosts (validated against CVEs).
Weak & default credentials
Guessable, reused, or default logins on exposed services, VPNs and management interfaces.
Misconfigured firewalls & devices
Overly-permissive rules, exposed management planes, and insecure network device configs.
VPN & remote-access weaknesses
Vulnerable or misconfigured VPNs, RDP and remote access — a top ransomware entry point.
TLS / certificate weaknesses
Deprecated protocols, weak ciphers, and expired or misissued certificates.
Internal attack surface — once an attacker is in
Breaches rarely stop at the first host. We measure how far an intruder could move, escalate, and reach your crown-jewel systems.
Network segmentation gaps
Flat networks that let an attacker move freely once a single host is compromised.
Lateral movement paths
Chains of access and trust that lead from a foothold to critical systems.
Privilege escalation
Local and domain paths from a standard user to administrator.
Active Directory weaknesses
Kerberoasting, weak delegation, and misconfigurations that expose the domain.
Credential reuse & weak policy
Shared local admin passwords and weak policies that enable rapid spread.
Unpatched internal hosts
Vulnerable internal servers and workstations that never face the internet — but face each other.
Test the way that matches your risk
External network penetration test
From the attacker's perspective on the internet — what can be reached, and what can be broken into, from outside your perimeter.
Internal network penetration test
Assumes a foothold inside the network — how far can an attacker move, escalate, and reach your crown-jewel systems?
Cloud infrastructure review
Network exposure, security groups, and identity paths across your AWS, GCP and Azure environments.
Wireless & segmentation testing
Wi-Fi security and validation that network segmentation actually contains an intruder.
Every finding, mapped to the controls you report on
A pentest finding isn't just a vulnerability — it's a failed control. We map each one across the standards your security and compliance teams already use.
| Finding class | NIST 800-53 | ISO 27001 | CIS v8 | PCI DSS | SOC 2 |
|---|---|---|---|---|---|
| Unpatched / vulnerable services | RA-5, SI-2 | A.8.8 | CIS 7 | Req 6.3 | CC7.1 |
| Weak / default credentials | IA-5 | A.5.17 | CIS 5 | Req 8 | CC6.1 |
| Network misconfiguration | CM-6 | A.8.9 | CIS 4 | Req 1 | CC6.6 |
| Exposed / unnecessary services | SC-7 | A.8.20 | CIS 4, 12 | Req 1 | CC6.6 |
| Weak network segmentation | SC-7 | A.8.22 | CIS 12 | Req 1.3 | CC6.1 |
| TLS / cryptographic weakness | SC-13 | A.8.24 | CIS 3 | Req 4 | CC6.7 |
| Insufficient logging / monitoring | AU-6 | A.8.15 | CIS 8 | Req 10 | CC7.2 |
Representative cross-framework mapping. Full control references (including NIST CSF and GDPR Art. 32) are included per-finding in the report.
Standards we map and test against
PCI DSS 4.0.1
Penetration testing (Req 11.4)
NIST 800-53
RA-5, CA-8 controls
ISO 27001:2022
Annex A controls
CIS Controls v8
Safeguards & IG levels
SOC 2
Common Criteria (Security)
NIST CSF 2.0
Identify / Protect / Detect
GDPR
Article 32 security of processing
OSSTMM / PTES
Testing methodology
Our penetration testing methodology
1. Scoping & reconnaissance
Agree targets, rules of engagement and testing windows; map the external and internal attack surface.
2. Discovery & enumeration
Port and service scanning (Nmap-family), service fingerprinting, and OpenVAS-based vulnerability discovery.
3. Vulnerability analysis
Findings are validated against CVEs and risk-scored with CVSS, enriched by CISA KEV and EPSS exploitability.
4. Controlled exploitation
Confirmed, non-destructive exploitation to prove real impact — never guesswork, never damage to production.
5. Post-exploitation & lateral movement
For internal tests: escalation, lateral movement and reach to critical assets, mapped as attack paths.
6. Reporting & retest
A clear report for executives, engineers and auditors, with prioritized remediation — then a retest to validate closure.
A report your whole team can act on
- Executive summary in plain language — exposure and the issues that matter
- Per-finding detail: severity, affected hosts/services, evidence, and step-by-step remediation
- Mapping to PCI DSS, NIST 800-53, ISO 27001, CIS Controls and SOC 2 on every finding
- Attack-path narrative showing how findings chain to reach critical systems
- Exploitability context (CISA KEV, EPSS) and the exact tools and versions used
- Prioritized remediation plan and retest verification of closed findings
See the depth for yourself
Download a full sample network & infrastructure penetration test report — with example findings, evidence, an attack-path narrative, remediation, and the complete PCI / NIST / ISO / CIS / SOC 2 mapping.
Download Sample Report (PDF)Penetration testing — common questions
What is the difference between an external and internal network penetration test?
An external test attacks from the internet — what an outsider can reach and break into through your perimeter. An internal test assumes a foothold inside the network (e.g. a compromised laptop) and measures how far an attacker can move, escalate privileges and reach critical systems. Most organizations need both.
Which compliance requirements does a penetration test satisfy?
Network penetration testing maps to PCI DSS 4.0 (Requirement 11.4), NIST 800-53 (RA-5, CA-8), ISO 27001:2022, CIS Controls v8, SOC 2 and NIST CSF 2.0 — and every finding in our report is mapped to those controls so it supports your audit directly.
Do you actually exploit vulnerabilities, or just scan?
Both. Automated discovery (Nmap-family, OpenVAS) is combined with manual, controlled exploitation to confirm real, exploitable impact — done safely and non-destructively, so you get proof rather than a raw scanner list of theoretical issues.
What does the report include?
An executive summary, per-finding detail with evidence and remediation, an attack-path narrative, exploitability context (CISA KEV, EPSS), control mapping to PCI DSS / NIST / ISO / CIS / SOC 2, and a prioritized remediation plan. A sample report is available to download on this page.
Know exactly where you're exposed.
Get an external and internal penetration test mapped to the frameworks you already report on — with a clear, prioritized path to fixing what matters.