Penetration Testing

See your network the way an attacker does.

External and internal network & infrastructure penetration testing that finds the way in — and how far it goes. Every finding is mapped to PCI DSS, NIST 800-53, ISO 27001, CIS Controls and SOC 2, so one engagement satisfies both your security and your audit.

What is a network penetration test?

A controlled, real-world attack simulation against your network and infrastructure — external (from the internet) and internal (from a foothold inside). It combines automated discovery with manual, safe exploitation to prove what an attacker could actually reach, then maps every finding to the compliance controls you report on.

From the outside

External attack surface — what we test from the internet

Exposed services & open ports

Every internet-facing port and service is enumerated — the attacker's first map of your estate.

Unpatched & vulnerable services

Known-vulnerable software and missing patches on public-facing hosts (validated against CVEs).

Weak & default credentials

Guessable, reused, or default logins on exposed services, VPNs and management interfaces.

Misconfigured firewalls & devices

Overly-permissive rules, exposed management planes, and insecure network device configs.

VPN & remote-access weaknesses

Vulnerable or misconfigured VPNs, RDP and remote access — a top ransomware entry point.

TLS / certificate weaknesses

Deprecated protocols, weak ciphers, and expired or misissued certificates.

From the inside

Internal attack surface — once an attacker is in

Breaches rarely stop at the first host. We measure how far an intruder could move, escalate, and reach your crown-jewel systems.

Network segmentation gaps

Flat networks that let an attacker move freely once a single host is compromised.

Lateral movement paths

Chains of access and trust that lead from a foothold to critical systems.

Privilege escalation

Local and domain paths from a standard user to administrator.

Active Directory weaknesses

Kerberoasting, weak delegation, and misconfigurations that expose the domain.

Credential reuse & weak policy

Shared local admin passwords and weak policies that enable rapid spread.

Unpatched internal hosts

Vulnerable internal servers and workstations that never face the internet — but face each other.

Engagement types

Test the way that matches your risk

External network penetration test

From the attacker's perspective on the internet — what can be reached, and what can be broken into, from outside your perimeter.

Internal network penetration test

Assumes a foothold inside the network — how far can an attacker move, escalate, and reach your crown-jewel systems?

Cloud infrastructure review

Network exposure, security groups, and identity paths across your AWS, GCP and Azure environments.

Wireless & segmentation testing

Wi-Fi security and validation that network segmentation actually contains an intruder.

One test, every framework

Every finding, mapped to the controls you report on

A pentest finding isn't just a vulnerability — it's a failed control. We map each one across the standards your security and compliance teams already use.

Finding class NIST 800-53 ISO 27001 CIS v8 PCI DSS SOC 2
Unpatched / vulnerable services RA-5, SI-2A.8.8CIS 7Req 6.3CC7.1
Weak / default credentials IA-5A.5.17CIS 5Req 8CC6.1
Network misconfiguration CM-6A.8.9CIS 4Req 1CC6.6
Exposed / unnecessary services SC-7A.8.20CIS 4, 12Req 1CC6.6
Weak network segmentation SC-7A.8.22CIS 12Req 1.3CC6.1
TLS / cryptographic weakness SC-13A.8.24CIS 3Req 4CC6.7
Insufficient logging / monitoring AU-6A.8.15CIS 8Req 10CC7.2

Representative cross-framework mapping. Full control references (including NIST CSF and GDPR Art. 32) are included per-finding in the report.

Standards we map and test against

PCI DSS 4.0.1

Penetration testing (Req 11.4)

NIST 800-53

RA-5, CA-8 controls

ISO 27001:2022

Annex A controls

CIS Controls v8

Safeguards & IG levels

SOC 2

Common Criteria (Security)

NIST CSF 2.0

Identify / Protect / Detect

GDPR

Article 32 security of processing

OSSTMM / PTES

Testing methodology

How it works

Our penetration testing methodology

1. Scoping & reconnaissance

Agree targets, rules of engagement and testing windows; map the external and internal attack surface.

2. Discovery & enumeration

Port and service scanning (Nmap-family), service fingerprinting, and OpenVAS-based vulnerability discovery.

3. Vulnerability analysis

Findings are validated against CVEs and risk-scored with CVSS, enriched by CISA KEV and EPSS exploitability.

4. Controlled exploitation

Confirmed, non-destructive exploitation to prove real impact — never guesswork, never damage to production.

5. Post-exploitation & lateral movement

For internal tests: escalation, lateral movement and reach to critical assets, mapped as attack paths.

6. Reporting & retest

A clear report for executives, engineers and auditors, with prioritized remediation — then a retest to validate closure.

The deliverable

A report your whole team can act on

  • Executive summary in plain language — exposure and the issues that matter
  • Per-finding detail: severity, affected hosts/services, evidence, and step-by-step remediation
  • Mapping to PCI DSS, NIST 800-53, ISO 27001, CIS Controls and SOC 2 on every finding
  • Attack-path narrative showing how findings chain to reach critical systems
  • Exploitability context (CISA KEV, EPSS) and the exact tools and versions used
  • Prioritized remediation plan and retest verification of closed findings

See the depth for yourself

Download a full sample network & infrastructure penetration test report — with example findings, evidence, an attack-path narrative, remediation, and the complete PCI / NIST / ISO / CIS / SOC 2 mapping.

Download Sample Report (PDF)
FAQ

Penetration testing — common questions

What is the difference between an external and internal network penetration test?

An external test attacks from the internet — what an outsider can reach and break into through your perimeter. An internal test assumes a foothold inside the network (e.g. a compromised laptop) and measures how far an attacker can move, escalate privileges and reach critical systems. Most organizations need both.

Which compliance requirements does a penetration test satisfy?

Network penetration testing maps to PCI DSS 4.0 (Requirement 11.4), NIST 800-53 (RA-5, CA-8), ISO 27001:2022, CIS Controls v8, SOC 2 and NIST CSF 2.0 — and every finding in our report is mapped to those controls so it supports your audit directly.

Do you actually exploit vulnerabilities, or just scan?

Both. Automated discovery (Nmap-family, OpenVAS) is combined with manual, controlled exploitation to confirm real, exploitable impact — done safely and non-destructively, so you get proof rather than a raw scanner list of theoretical issues.

What does the report include?

An executive summary, per-finding detail with evidence and remediation, an attack-path narrative, exploitability context (CISA KEV, EPSS), control mapping to PCI DSS / NIST / ISO / CIS / SOC 2, and a prioritized remediation plan. A sample report is available to download on this page.

Know exactly where you're exposed.

Get an external and internal penetration test mapped to the frameworks you already report on — with a clear, prioritized path to fixing what matters.