Get a free audit

External Penetration Testing · United Kingdom

External penetration testing. We start where the attacker starts: outside, with nothing.

We attack your internet-facing estate the way an anonymous intruder would, using nothing you handed us. You get every door an attacker can see today, ranked by how easily it opens, with the fix for each.

CREST-certified operators · zero-knowledge start · every finding human-verified

What is external penetration testing?

External penetration testing is an authorised attack on everything your organisation exposes to the internet. The tester works from outside your perimeter with no credentials and no network access, finds what is reachable, and proves which of it opens a door.

The value sits in the reconnaissance. Most UK firms know about their main website and their VPN. Almost none have a current list of every subdomain, every legacy login page, every forgotten test environment and every third-party service still pointed at their domain. An attacker builds that list in an afternoon. So do we, and then we attack it.

This is the test that catches the exposure nobody owns any more. In most engagements the way in is not the flagship application. It is the thing somebody stood up two years ago and never switched off.

What we attack

Everything pointed at the internet

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

SurfaceWhat we look for
Attack-surface discoveryEvery subdomain, IP range, certificate and third-party service tied to your domain, including the ones no longer in your asset register.
Exposed authenticationRemote access portals, webmail, admin panels and VPN endpoints. We test for weak and reused credentials, missing multi-factor authentication and password spraying.
Unpatched edge devicesFirewalls, gateways and remote-access appliances running versions with known, exploited weaknesses.
Web and API endpointsAnything serving traffic: injection, authentication bypass, exposed configuration files, directory listings and debug interfaces left on.
Mail and DNSSPF, DKIM and DMARC gaps that let an attacker send mail as you, plus subdomain takeover through dangling DNS records.
Credential exposureCompany credentials already circulating from third-party breaches, tested against your live login pages under agreed rules.

What you get

Your perimeter, ranked by how easily it opens

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

Your deliverable
  • A current inventory of everything you expose to the internet, including what you had forgotten
  • Proof of exploit for each finding: the request that worked, not a scanner score
  • Findings ranked by how easily each door opens and what sits behind it
  • The specific fix for each one, written for the person who has to apply it
  • Verified by a CREST-certified operator before it reaches you
  • A year of unlimited re-tests through RTP Robin, so a new exposure reaches you before it reaches an attacker
CRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNISTCRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNIST

Before you ask

External penetration testing, answered

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

What is external penetration testing?

External penetration testing is an authorised attack on your internet-facing systems, carried out from outside your network with no credentials and no insider knowledge. The tester discovers everything reachable from the internet, attacks it, and proves which weaknesses genuinely open a door. It answers one question precisely: what can an anonymous attacker reach and exploit today, without help from anyone inside your organisation?

What is the difference between external and internal penetration testing?

External testing starts outside your perimeter with nothing, and measures what an anonymous attacker can reach from the internet. Internal testing starts inside, from a position an attacker would occupy after a successful phish, and measures how far they travel once they are already on your network. The two answer different halves of the same question. Most organisations run external first, then internal, because the external result usually tells you how an attacker gets in.

How often should we run an external penetration test?

At least annually, and after any significant change to what you expose. The problem with an annual cadence on its own is that your perimeter changes weekly: a new subdomain, a supplier integration, a credential that leaked overnight. That is why one paid test with us includes a year of unlimited re-tests through RTP Robin, so the picture stays current between engagements rather than ageing for eleven months.

Do you need access to our systems to run an external test?

No. That is the point of the test. We start with your organisation name and domain, and we build the picture the way an attacker would. You provide the authorisation and confirm which assets are yours, so we stay inside legal boundaries, but we do not want your network diagram or your asset list until after the reconnaissance phase. Comparing our list against yours is often the most useful conversation of the engagement.

See what an attacker reaches from outside, within 14 days.

Get a free audit