What we test
Network Penetration Testing
Testing the network perimeter from outside, and the internal network as though a foothold has already been established. PCI DSS requires both; most other frameworks are satisfied with the external half.
Who asks for this
Companies with corporate infrastructure, offices or non-cloud systems, and anyone under PCI DSS, where internal and external testing are separate named requirements.
What the test covers
- Perimeter discovery and exposed service enumeration across the real address space
- Remote access: VPN, jump hosts, management interfaces and anything that answers on a known port
- Patch level and configuration of exposed services
- Internal lateral movement from an assumed foothold
- Credential reuse and password policy in practice rather than in the policy document
- Segmentation testing where segmentation is being used to reduce audit scope
What this test typically finds
Classes of finding, not a severity table. These are the issues that recur on this surface.
Exposure nobody knew about
A host outside the inventory, usually from a project that ended, still reachable and still unpatched.
Management interfaces on the public internet
Administrative panels, database ports and remote access services reachable from anywhere, often behind a password that has not been rotated.
Segmentation that does not hold
Traffic crossing a boundary the audit scope depends on. Under PCI DSS 11.4.5 this is a specific, testable requirement rather than a general concern.
Questions people ask
What is the difference between internal and external penetration testing?
External testing starts from the public internet with no access, establishing what an unauthenticated attacker can reach. Internal testing starts from a position inside the network, as though an attacker already has a foothold, and establishes how far that position gets them. PCI DSS Requirement 11.4 requires both.
Do cloud-only companies need a network penetration test?
Usually the cloud infrastructure test covers the same ground more usefully. A separate network test earns its place when there are offices, non-cloud systems, or a PCI DSS requirement that names internal and external testing specifically.
Related surfaces
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.