08 / 11

External Network Penetration Testing

We test your internet-facing perimeter the way an attacker meets it, with no access and no credentials. Public IP addresses and hostnames, exposed services, remote-access endpoints including VPN and mail, and whether your firewall rules let a stranger reach anything they should not.

External Network Penetration Testing illustration

What is external network penetration testing?

External network penetration testing is a security assessment of everything your organisation exposes to the internet, run from the position an attacker actually starts in: no access, no credentials, no foothold. It covers your public IP addresses and hostnames, the services listening on them, remote-access endpoints such as VPN and mail, and the firewall and DMZ rules that decide what a stranger can reach. It answers one question, which is whether someone can get in from outside.

Testing Checklist

Every engagement covers these critical security areas.

External asset discovery across in-scope IP ranges and hostnames
Port and service enumeration on every live external host
Service version fingerprinting and known-vulnerability identification
VPN endpoint configuration and authentication testing
Remote access exposure: RDP, SSH and management interfaces
Mail perimeter: relay, authentication, SPF, DKIM and DMARC posture
DNS configuration, zone transfer and subdomain takeover checks
TLS configuration and certificate validity on exposed services
Internet-facing login surfaces: credential attack resistance and lockout
Default and weak credentials on edge and network devices
Firewall rule and DMZ boundary validation
Forgotten hosts, staging environments and shadow assets on the perimeter

Testing Methodology

A structured, repeatable process that ensures thorough coverage and actionable results.

STEP 01

Scoping and Authorisation

Agree the exact public IP addresses and hostnames in scope, confirm you own or are authorised to test them, and set the testing window. Nothing outside the written scope is touched.

STEP 02

External Reconnaissance

Build the internet-facing inventory from DNS records, certificate transparency logs and passive sources, then confirm which of it is live and which of it is actually yours. Forgotten hosts surface here more often than anywhere else in the engagement.

STEP 03

Service Enumeration and Fingerprinting

Identify what every reachable port is running and at which version, including edge devices, VPN concentrators, mail servers and management interfaces that were never meant to face the internet.

STEP 04

Perimeter Exploitation

Test authentication on remote-access endpoints, exercise known vulnerabilities against exposed services, and confirm exploitability. A version banner is not a finding until it is shown to be reachable and exploitable.

STEP 05

Boundary Validation

Establish what successful entry would actually reach: whether the DMZ is a boundary or a doorway, and which internal services are reachable through the rules that are live rather than the rules on the diagram.

STEP 06

Reporting and Retest

Every finding carries reproduction steps, the exposure it created, and remediation direction. One free retest within one month of the v1.0 report, delivered as v2.0.

Want to scope your external network pentest engagement? Both founders take the discovery call.

What you get with External Network Pentest at each tier

Tier Includes Price
Startup 1 scope, 5 business days, 6 hours founder-led consulting, 1 free retest within one month of the v1.0 report. INR 74,999
Growth 2 scopes, 10 business days, SOC 2 and ISO 27001 control mapping per finding, a signed Letter of Attestation, 12 hours founder-led consulting, 1 free retest. INR 1,79,999

What counts as one scope: One internet-facing perimeter: up to 24 public IP addresses and the hostnames resolving to them, including the remote-access endpoints on those addresses such as VPN, mail and DMZ services. Additional addresses are counted as additional scopes, 24 per scope. Separately managed perimeters, and engagements beyond 4 scopes, are quoted as a custom proposal.

Each additional scope adds 5 business days, so 3 scopes is 15 and 4 is 20. All prices exclude taxes. See every scope definition.

All prices exclude taxes. International engagements invoiced in local currency at snapshot FX.

Framework Alignment

These are the standards that apply to this scope type. Which of them we run on your engagement depends on what you are buying: a checklist-style assessment covers the baseline categories set out in the standards listed here, while audit-evidence work adds systematic test-case coverage and control verification. We scope that with you before the engagement rather than applying every framework by default.

PTESNIST SP 800-115OSSTMM 3MITRE ATT&CKOWASP WSTG v4.2

Compliance Coverage

PCI
PCI DSS v4.0.1
11.4.3: external penetration testing at least once every 12 months and after significant change, by a qualified internal resource or qualified external third party, with organizational independence of the tester. This is a separate obligation from the internal test under 11.4.2, not an alternative to it. The standard does not require the tester to hold a PCI credential. Cybersecify is not a PCI SSC Approved Scanning Vendor, so we cannot perform the quarterly external vulnerability scans that require an ASV, and we are not a Qualified Security Assessor, so we cannot conduct your assessment or sign your Report on Compliance.
ISO
ISO 27001:2022
A.8.8: Management of technical vulnerabilities. A.8.29: Security testing in development and acceptance. A.8.20: Network security. A.8.22: Segregation of networks
SOC
SOC 2
CC6.6: Protection against external threats. CC7.1: Vulnerability detection
RBI
RBI Directions, 2026
Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (issued 31 July 2026, effective immediately, issued separately per entity class, Commercial Banks version RBI/DoS/2026-27/410): penetration testing at least once in 12 months for critical information systems and those in the DMZ having a customer interface (paragraph 151), conducted by appropriately trained and independent information security experts or auditors (paragraph 155).

Deliverables

What you walk away with at the end of every engagement.

01

Technical report with reproduction steps per finding

02

External attack surface inventory of what is reachable from the internet

03

Executive summary for non-technical stakeholders

04

CVSS v3.1 severity scoring per finding

05

Perimeter and DMZ boundary test results

06

One free retest within one month of the v1.0 report, delivered as v2.0

07

Letter of Attestation signed by the lead pentester (Growth plan)

Frequently Asked Questions

What is the difference between an external and an internal network pentest?

They answer two different questions, and most standards treat them as two separate obligations rather than as alternatives. An external test starts on the internet with nothing. The target is your perimeter: public IP addresses and hostnames, exposed services, remote-access endpoints such as VPN and mail, DMZ services, and the firewall rules that are actually live rather than the ones on the diagram. The question is whether someone can get in. An internal test starts from an assumed breach, with someone already inside. The target is Active Directory, lateral movement, privilege escalation and network segmentation, and the question is how far someone gets once they are in. PCI DSS v4.0.1 draws the same line: Requirement 11.4.2 covers internal penetration testing and Requirement 11.4.3 covers external penetration testing, and satisfying one does not satisfy the other. The two are complements, and buyers frequently run both as a single two-scope engagement.

Does PCI DSS require an external penetration test, and does the tester have to be an ASV or a QSA?

PCI DSS v4.0.1 Requirement 11.4.3 requires external penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change, performed by a qualified internal resource or a qualified external third party, with organizational independence of the tester. The standard notes that the tester is not required to be a QSA or an ASV. What it asks for is a defined methodology, a qualified tester, and independence from the systems under test. Our lead tester holds OSCP, credential OS-101-34173, verifiable with the issuer on Credly, which is the kind of evidence an assessor looks for when judging qualification. Two things we are explicitly not, and this page is where a buyer is most likely to assume otherwise. Cybersecify is not a PCI SSC Approved Scanning Vendor, so we cannot perform the quarterly external vulnerability scans that PCI DSS requires an ASV to run, and this service is not an ASV scan. Cybersecify is not a Qualified Security Assessor either, so we cannot conduct your PCI DSS assessment or sign your Report on Compliance. Those two roles stay with your ASV and your QSA. If someone has told you your penetration tester must hold one of those credentials, ask which requirement they are reading, because 11.4.3 does not impose it.

Do you need credentials or access to run an external network pentest?

No, and that is the point of the exercise. The test starts where an attacker starts, which is with nothing. What we need from you is written authorisation and the list of public IP addresses and hostnames that belong to you, so that we test your perimeter and nobody else. Where your infrastructure sits with a hosting provider or a cloud platform, we confirm their testing rules before the window opens. Everything after that is discovery: we build the internet-facing inventory ourselves from DNS records, certificate transparency logs and passive sources, because the assets you had forgotten about are usually the ones that matter.

What is in scope for an external network pentest at Cybersecify?

One scope is one internet-facing perimeter: up to 24 public IP addresses and the hostnames resolving to them, including the remote-access endpoints on those addresses such as VPN, mail and DMZ services. Inside that boundary we cover external asset discovery, port and service enumeration on every live host, service version fingerprinting against known vulnerabilities, VPN endpoint configuration and authentication, exposed RDP, SSH and management interfaces, mail perimeter posture including SPF, DKIM and DMARC, DNS configuration, zone transfer and subdomain takeover, TLS configuration and certificate validity on exposed services, credential attack resistance on internet-facing login surfaces, default and weak credentials on edge and network devices, firewall rule and DMZ boundary validation, and the forgotten hosts, staging environments and shadow assets that turn up on almost every perimeter. Out of scope: anything behind the perimeter, which is the internal network test, plus denial-of-service against production, physical attacks, and social engineering or phishing. Additional address ranges and separately managed perimeters are quoted as a custom scoping proposal.

Is an external network pentest the same as a vulnerability scan?

No. A scan lists what is listening and what version each service reports, and it stops there. Much of that list is noise, because a version banner is not a vulnerability until someone has shown that the service is reachable, that the vulnerable code path is enabled, and that the exposure is real. An external network pentest starts from that inventory and then does the part a scanner cannot. We confirm exploitability rather than reporting a banner, we test authentication on your VPN rather than noting that a VPN exists, we chain a weak perimeter service into the access it actually grants, and we tell you what an attacker would reach next. You get a short list of things that are true instead of a long list of things that might be.

How long does an external network pentest take and what does it cost?

One external network scope is 5 business days under the Startup Pentest plan at INR 74,999. A two-scope engagement, most commonly external plus internal network, is 10 business days under the Growth Pentest plan at INR 1,79,999, which adds SOC 2 and ISO 27001 control mapping per finding and a Letter of Attestation signed by the lead tester. Scopes run one after another by default, so each additional scope adds 5 business days: 3 scopes is 15 and 4 is 20. If your deadline is tighter than that, ask us. We can sometimes test several scopes at the same time, which changes the schedule rather than the price, but it depends on the engagement and it is not something we promise up front. Business days are Monday to Friday, and the weekend is a quality buffer that is not counted against the timeline. Both plans include one free retest within one month of the v1.0 report, delivered as v2.0. All prices exclude taxes.

Does an external network pentest report work as SOC 2 and ISO 27001 evidence?

Yes, for the controls a perimeter test genuinely evidences. Under ISO 27001:2022 that is A.8.8 management of technical vulnerabilities and A.8.29 security testing in development and acceptance, plus A.8.20 network security and A.8.22 segregation of networks where a finding lands on the boundary itself. Under SOC 2 that is CC6.6 protection against external threats and CC7.1 vulnerability detection. Every finding comes with reproduction steps, a CVSS v3.1 severity score and remediation direction, and the retest evidences that the fix landed, which is the piece auditors ask for and most reports leave out. What the report is not: Cybersecify is not ISO 27001 or SOC 2 certified itself and does not issue certificates. Your accredited certification body and your CPA firm do that. We produce the technical evidence they ask you to bring.

When should we run an external network pentest?

Four triggers cover most of the engagements we see. A compliance requirement, usually PCI DSS Requirement 11.4.3, a SOC 2 or ISO 27001 audit, or the RBI Directions if you are a regulated entity in India. An enterprise customer or an investor asking for evidence during diligence. A change to the perimeter itself: a new site or office, a new VPN, a cloud migration, a merger that joined two networks, or a firewall rebuild. And fear, usually after a breach at a company that looks like yours. Beyond the trigger, the reason a perimeter test keeps finding things is that perimeters drift. Nobody exposes a service on purpose. It arrives through a temporary firewall rule that was never removed, a staging box that picked up a public address, or a supplier who opened a port for an integration and did not tell anyone.

Ready to secure your external network?

Pentest packages from INR 74,999 (~$790 / ~€680, indicative as at August 2026). Includes consulting hours + 1 free retest within one month. Both founders on every engagement: Rathnakara (OSCP) leads testing, Ashok handles delivery + compliance.