External Infrastructure Penetration Testing

External infrastructure penetration testing

See your internet-facing perimeter the way an attacker does.

Independent, manual testing of everything you expose to the internet, delivered to a recognised methodology by a Cyber Scheme Team Leader qualified tester.

Cyber Scheme Team Leader qualified Manual testing, not just scanning Free retest once fixed
The perimeter

Your front door to the internet, tested from the outside

Every service you publish, a website, a mail server, a VPN, a remote-access portal, is reachable by anyone in the world. That reachable surface is where an external attack starts.

We test it with no prior access or credentials, mapping what you expose and then probing it for weaknesses: unpatched services, weak or default credentials, exposed admin interfaces, misconfiguration, and the small information leaks that help an attacker plan. The aim is to establish what someone could actually achieve, and to give you a clear, prioritised list of what to fix first.

Scope

What we test for

Exposure

Exposed services and open ports

What is listening on your perimeter, whether it should be, and whether any of it hands an attacker a foothold.

Access

Remote access and VPN gateways

VPNs, remote desktop and management portals: the doors built for staff that attackers try hardest to walk through.

Patching

Missing patches and known vulnerabilities

Internet-facing software running with known, exploitable flaws, validated by hand to rule out false positives.

Credentials

Weak and default credentials

Default logins, weak passwords and exposed management interfaces that turn a minor exposure into full access.

Configuration

Misconfiguration and encryption

Firewall and service misconfiguration, weak TLS and certificate handling, and headers that quietly widen your attack surface.

Reconnaissance

Information leakage

The details you unintentionally publish, in metadata, error messages and exposed files, that help an attacker plan the next step.

Delivered to a recognised standard

Tested by a qualified infrastructure tester, not a scanner with a logo

Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards. Our lead tester is also a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

In practice that means industry-standard tooling for breadth, then manual testing to work out what an attacker could really do with what it finds, and a report you can act on rather than a raw export.

Deliverables

A report you can act on, and a retest to prove it worked

The report

Written for the board and the technical team

  • An executive summary in plain English
  • Each finding risk-rated, with evidence and step-by-step reproduction
  • Specific, practical remediation advice, not generic boilerplate
Afterwards

A debrief and a free retest

  • A walkthrough of the findings if it helps your team
  • A retest once you have fixed the issues, to confirm the fixes hold
  • Included as standard, not sold as an add-on
How it works

Straightforward from first email to retest

  1. Tell us what you expose

    A short enquiry, answered by a tester rather than a sales team.

  2. A quick scoping call

    15 to 30 minutes to confirm the hosts, ranges and services in scope.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

  4. Testing and reporting

    Agreed rules of engagement, testing to a recognised methodology, then a report you can act on.

  5. A free retest

    Once you have fixed the findings, we confirm the fixes hold at no extra cost.

From our Insights

More on penetration testing

ISO 27001

Working towards ISO 27001?

ISO 27001 does not mandate an annual penetration test, but it is risk-based, and testing is often the clearest way to show that technical vulnerabilities are being found, understood and managed.

We provide independent testing that supports an ISO 27001 programme, scoped to your risks rather than a generic checklist, with a report that feeds straight into your risk register and remediation plan.

Does ISO 27001 require penetration testing?
Where testing fits

The most relevant Annex A controls

  • A.8.8: management of technical vulnerabilities
  • A.8.29: security testing in development and acceptance

Independent testing provides evidence that these controls work in practice, not just on paper.

Common questions

External infrastructure testing, answered.

What is external infrastructure penetration testing?

It is a test of everything your organisation exposes to the internet: the servers, services, remote-access gateways and devices an outsider can reach without any prior access or credentials. We approach it exactly as an external attacker would, mapping your perimeter and then probing it for ways in.

What do you actually test?

Exposed services and open ports, remote access and VPN gateways, web and mail servers, firewalls and edge devices, along with missing patches and known vulnerabilities, weak or default credentials, exposed management interfaces, certificate and encryption weaknesses, and information leakage that helps an attacker. We then try to establish what could actually be achieved, not just what is theoretically present.

Who carries out the testing?

An experienced, senior tester runs your engagement from scoping to report, with no hand-off to a junior halfway through. Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and our lead tester is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

How is this different from an automated vulnerability scan?

A scanner is fast and good at breadth, catching known issues and missing patches. It cannot confirm whether a finding is genuinely exploitable, chain several small issues into a real compromise, or rule out false positives. An external penetration test combines that tooling with a skilled tester doing exactly that, so you get a prioritised picture of real risk rather than a raw export.

Will testing disrupt our services?

We agree the rules of engagement in writing before any testing begins, avoid genuinely disruptive techniques against production, and can schedule around your quiet periods. We stay in contact throughout, so there are no surprises and minimal impact on your normal operations.

What do we get at the end?

A clear report written for both your board and your technical team: an executive summary, then each finding with a risk rating, the evidence, step-by-step reproduction, and specific remediation advice. Once you have fixed the issues we retest to confirm the fixes hold, at no extra cost.

How much does external infrastructure testing cost?

There is no fixed public price, because it depends on the size of your perimeter: how many hosts, IP ranges and services are in scope. Tell us what you expose on a short scoping call and we will come back with a fixed-price quote, typically within 48 hours.

Get a quote

Find out what your external test would cost

Tell us what you expose to the internet and we'll recommend an appropriate scope and provide a no-obligation quotation.

  1. We read your enquiry

    A real tester, not a sales team, so the first reply is already useful.

  2. A short scoping call

    15 to 30 minutes to understand your perimeter and what you need to prove.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

Not sure whether you need external, internal or both? Tell us what you're trying to achieve and we'll help you scope it.