External Penetration Testing

External Penetration Testing

Expert-led testing that attacks your internet-facing perimeter the way a real adversary would: probing exposed services, VPNs, mail servers, cloud tenants, and forgotten hosts to prove what an outsider can actually reach. Delivered by a North Carolina cybersecurity firm that has protected regulated businesses since 2002.

CyberAB RPO #1449 | BBB A+ Since 2003 | NC Licensed Digital Forensics
What It Is

What Is External Penetration Testing?

External penetration testing is an authorized, simulated cyberattack launched from the public internet against everything your organization exposes to the outside world: firewalls, VPN gateways, mail servers, web servers, remote access portals, and cloud services. Security professionals attempt to discover, enumerate, and safely exploit those systems exactly as an unauthenticated attacker would, with no credentials and no insider knowledge. The result is documented proof of which perimeter weaknesses can actually be used to reach your internal network or your data, ranked by real risk rather than by scanner severity.

Key Takeaways

  • External penetration testing simulates an outside attacker with zero access, proving which internet-facing systems are genuinely exploitable rather than simply flagged by a scanner.
  • Petronella Technology Group has delivered offensive security testing since 2002, holds a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) with a CMMC-RP certified team.
  • Our methodology follows NIST SP 800-115, the Penetration Testing Execution Standard, and the OSSTMM, and satisfies perimeter testing requirements in PCI DSS, CMMC, NIST 800-171, HIPAA, and SOC 2.
  • Founder Craig Petronella is an MIT-certified cybersecurity professional, NC Licensed Digital Forensics Examiner (License #604180-DFE), and cybersecurity expert witness, so our testing reflects how perimeter breaches actually unfold.

Why It Matters

Why Your Perimeter Needs a Real Pen Test

Your external attack surface is the only part of your network that every attacker on earth can reach without any help from an insider. It is scanned continuously, automatically, and indiscriminately, and it is where the overwhelming majority of intrusions begin.

Most organizations do not have an accurate picture of what they expose. A marketing team stands up a landing page on a subdomain. A developer opens a management port for a weekend migration and never closes it. A vendor integration adds an API endpoint nobody documented. A cloud engineer builds a storage bucket for a one-time transfer. Each of these is invisible on an internal asset list and perfectly visible to an attacker running automated discovery against your address space. External penetration testing starts by rebuilding that picture from the outside, which is frequently the single most valuable deliverable of the engagement.

Automated vulnerability scanning is useful, but it stops well short of proof. A scanner will tell you that a VPN appliance is running a version with a published flaw. It will not tell you that the flaw is genuinely reachable through your configuration, that a valid credential can be recovered from a public breach corpus, that multi-factor authentication was never enforced on that gateway, or that the three findings chain together into full remote access. A skilled tester does exactly that chaining, and the difference between "twelve medium findings" and "one proven path from the internet into your file server" is the difference between a report that gets shelved and a report that gets funded.

The commercial pressure is real too. Cyber insurers now underwrite on the strength of your perimeter controls and increasingly ask for evidence of independent testing. Enterprise customers send security questionnaires before they sign. Prime contractors ask their subcontractors to demonstrate assessment activity. Regulators and auditors expect documented testing under PCI DSS, and defense supply chain requirements under CMMC and NIST 800-171 expect vulnerability assessment and remediation to be a repeating practice. A current external penetration test turns all of those conversations from an assertion into evidence.

Petronella Technology Group brings a defender's and an investigator's perspective to every engagement. Because our founder works real digital forensics and expert-witness cases, we have seen exactly how attackers move once they get through a perimeter, and we test the routes that actually get used rather than the ones that merely look impressive in a report. Pair a test with our managed cybersecurity services and the findings get remediated, monitored, and retested rather than filed away.

The Attack Surface

What We Attack From the Outside

Every internet-reachable asset tied to your organization is in scope, including the ones your team has forgotten about. Discovery comes first, because you cannot defend what you do not know you own.

Perimeter Infrastructure

  • Firewalls, edge routers, and exposed management interfaces that should never have been reachable
  • VPN concentrators, remote desktop gateways, and jump hosts, including missing or bypassable multi-factor authentication
  • Mail servers, webmail portals, and mail security gateways, including relay abuse and authentication weaknesses
  • DNS configuration, subdomain takeover candidates, and orphaned records pointing at deprovisioned services

Services, Cloud, and Identity

  • Public cloud tenants, storage buckets, serverless endpoints, and misconfigured identity federation
  • Exposed databases, file transfer services, backup appliances, and printer or IoT management panels
  • Credential exposure: password reuse from public breach data, weak lockout policy, and password spraying against portals
  • Open source intelligence: employee enumeration, leaked keys in public repositories, and metadata that aids an attacker

Where your public-facing applications are the primary concern, we recommend pairing this engagement with a dedicated web application penetration test, which examines authenticated workflows, business logic, and API authorization in a depth that a perimeter test does not attempt.

See Your Network the Way an Attacker Does

We will scope an external penetration test against your real internet-facing footprint and show you exactly what an outsider can reach. Call 919-348-4912 or request a quote.

Scope Choices

External vs. Internal Penetration Testing

The two tests answer different questions, and most mature security programs run both. Understanding the difference is the first step in scoping an engagement that produces useful answers.

External Penetration Testing

  • Starting point: the public internet, with no credentials and no network access
  • Question answered: can an anonymous outsider get in at all, and how far?
  • Typical findings: exposed services, weak remote access, subdomain takeover, credential reuse, perimeter misconfiguration
  • Best for: every organization, as the baseline test and the one auditors ask about first

Internal Penetration Testing

  • Starting point: inside your network, simulating a compromised workstation, a rogue insider, or an attacker who already phished a user
  • Question answered: once someone is inside, how quickly do they reach domain administrator and your crown-jewel data?
  • Typical findings: flat networks, weak Active Directory configuration, credential harvesting, lateral movement paths, excessive privilege
  • Best for: organizations with an established perimeter that need to measure blast radius and ransomware exposure

The honest answer to "which one do we need?" depends on where you are. If you have never had an independent test, start externally: it is the attack surface an opportunistic adversary will find first, and it is what your insurer and your customers will ask about. If your perimeter is well managed but a single phished employee would put your entire environment at risk, an internal engagement tells you far more. Organizations under CMMC, PCI DSS, or SOC 2 obligations typically run both on an annual cycle, with external testing repeated more frequently because the perimeter changes constantly.

Both scopes are available from our team, and many clients combine them into a single network penetration testing engagement so that one report covers the full path from the open internet to the data an attacker is actually after. We will help you decide during scoping rather than selling you the larger engagement by default.

Methodology

Our External Pen Test Process

A structured, standards-aligned engagement built on NIST SP 800-115 and the Penetration Testing Execution Standard, with written rules of engagement agreed before any packet is sent.

1

Scoping and Rules of Engagement

We agree in writing on the address ranges, domains, and cloud tenants in scope, the testing window, escalation contacts, and the boundaries we will not cross. You receive our source addresses so your team can distinguish our activity from a genuine attack, and we confirm authorization for any assets hosted by a third party.

2

Reconnaissance and Attack Surface Discovery

We rebuild your external footprint from the outside using passive intelligence, certificate transparency records, DNS enumeration, and cloud asset discovery. This routinely surfaces hosts, subdomains, and services that were never on the client's inventory, and that discovery alone often changes how a security team allocates its budget.

3

Enumeration and Vulnerability Analysis

Every reachable service is fingerprinted for version, configuration, and exposure. We combine automated tooling for coverage with manual analysis for accuracy, discarding the false positives that make raw scanner output so hard to act on, and identifying the weaknesses that are genuinely reachable in your specific configuration.

4

Controlled Exploitation and Chaining

We safely validate findings by exploiting them under the agreed rules of engagement, then look for the chains: an information leak that enables user enumeration, enumeration that enables a password spray, a recovered credential that reaches a gateway without multi-factor authentication. Destructive techniques are excluded, and anything with operational risk is coordinated with your team first.

5

Reporting and Executive Debrief

You receive a report written for two audiences: an executive summary that explains business risk in plain language, and a technical section with reproduction steps, evidence, and specific remediation guidance. We walk your team through it on a live debrief so questions get answered while the findings are fresh.

6

Remediation Support and Retesting

After you fix the confirmed findings, we retest them to verify the fixes hold and issue an attestation letter suitable for auditors, insurers, and enterprise customers. A finding is only closed once we have proven the fix works in practice.

Deliverables

What You Receive After the Test

External Attack Surface Inventory

A documented list of every internet-facing asset we identified, including the hosts, subdomains, and services that were not on your inventory before the test began.

Ranked Findings With Evidence

Each finding carries a business-risk rating, technical detail, screenshots or captured evidence, and clear reproduction steps so your team can confirm and fix it without guesswork.

Proven Attack Paths

Where we chained findings into a route from the public internet toward your internal environment, that path is documented end to end so leadership understands the actual consequence.

Prioritized Remediation Roadmap

A sequenced plan that separates the fixes to make this week from the architectural work to schedule this quarter, with effort and impact called out for each.

Executive Summary and Live Debrief

A board-ready summary written without jargon, plus a working session with your team to answer questions and align on ownership of each remediation item.

Retest and Attestation Letter

Validation that your fixes hold, documented in a letter you can hand to auditors, cyber insurers, prime contractors, and enterprise procurement teams.

Comparison

External Pen Test vs. the Alternatives

Perimeter assurance is sold in several forms, and they are not interchangeable. Here is what each one actually delivers.

Capability External Pen Test Automated Scan DIY Internal Review
Discovers unknown internet-facing assets Yes, from the outside in Only what you point it at Limited to the internal inventory
Proves exploitability Yes, with evidence No, flags potential issues only Rarely, and not independently
Chains weaknesses into attack paths Yes, core of the engagement No Uncommon without offensive experience
False positives filtered by a human Yes, every finding validated No, output is raw Depends entirely on staff capacity
Independence for auditors and insurers Yes, third-party attestation Partially, tooling evidence only No, self-assessment
Remediation guidance and retest Included, with attestation letter Generic vendor advisories Internal effort, no external validation

None of this makes scanning worthless. Continuous scanning is exactly the right tool for catching a newly published vulnerability on a known host between engagements, and we build it into our vulnerability assessment programs for that reason. The point is that scanning and testing answer different questions, and only one of them tells you what an adversary can actually accomplish.

Find the Gaps Before Attackers Do

A scoping call takes about twenty minutes and costs nothing. We will tell you honestly whether an external test, an internal test, or an application test gives you the most value right now.

Compliance

External Testing for Compliance Requirements

Perimeter testing is written into most of the frameworks our clients operate under, and the evidence an assessor wants is specific.

PCI DSS requires external penetration testing at least annually and after any significant change to the cardholder data environment, performed by a qualified party using an industry-accepted methodology and covering the full perimeter of the environment. Our reports are structured to map findings directly to the relevant requirements, which is what makes them usable during an assessment rather than merely informative. See our PCI DSS compliance services for the broader program.

CMMC and NIST 800-171 expect defense contractors to scan for vulnerabilities, remediate them in accordance with risk, and demonstrate that the practice repeats. External testing produces exactly the evidence a C3PAO wants: documented scope, dated results, ranked findings, and proof of remediation. As a CyberAB Registered Provider Organization (RPO #1449) with CMMC Registered Practitioners on staff, our team scopes testing to align with your System Security Plan rather than producing a report that has to be reinterpreted later. Explore our CMMC compliance services.

HIPAA requires covered entities and business associates to conduct an accurate and thorough risk analysis of the risks to electronic protected health information. Independent external testing is one of the strongest inputs to that analysis, and it is the input that regulators find most credible because it is empirical rather than declared. Craig Petronella is the author of How HIPAA Can Crush Your Medical Practice, and that framing informs how we document findings for healthcare clients pursuing HIPAA compliance.

SOC 2 and cyber insurance both look for evidence of independent testing under the security criteria and on renewal questionnaires respectively. Carriers increasingly ask directly whether the applicant performs penetration testing and how recently, and an accurate answer with an attestation letter attached is a materially better position than a checkbox. Our SOC 2 compliance team can align the testing cadence to your audit period.

Why Us

Why Businesses Trust Our Testing

  • Attacker experience, not just tools. Our founder is an NC Licensed Digital Forensics Examiner and cybersecurity expert witness who investigates real breaches, so we test the perimeter routes attackers actually take.
  • Manual validation of every finding. Automated tooling gives us coverage, but the exploitation, chaining, and judgment come from experienced testers who confirm each finding by hand before it reaches your report.
  • Compliance fluency. As a CyberAB Registered Provider Organization (RPO #1449), we know how PCI DSS, CMMC, HIPAA, and SOC 2 expect perimeter testing to be scoped, executed, and documented.
  • We can fix what we find. Many testing firms hand over a report and leave. Our managed security and compliance teams can implement the remediation, which means findings close instead of aging.
  • Proven longevity. Founded in April 2002 and BBB A+ rated since 2003, we have defended North Carolina and national clients through more than two decades of evolving threats.

"Petronella's work has been a major factor in our business success, helping it to become one of the most secured networks of its kind on the Internet."

Financial Services Firm, Raleigh, NC

We are rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews. You can read them on our reviews page.

Who We Test For

Industries We Test For

Since 2002 we have tested perimeters for organizations whose exposure carries regulatory as well as financial consequence.

Defense Contractors

Suppliers handling controlled unclassified information who need documented assessment evidence for CMMC and NIST 800-171 obligations flowed down by their primes.

Healthcare Practices

Medical, dental, and behavioral health organizations whose patient portals, remote access, and practice management systems face the internet directly.

Law Firms

Practices holding privileged client material, where a perimeter compromise carries an ethical duty of disclosure alongside the business damage.

Financial Services

Advisors, lenders, and accounting firms operating under GLBA and FTC Safeguards expectations with client financial data reachable through online services.

Manufacturing and Logistics

Operations where remote access to plant systems and vendor connectivity create perimeter exposure that traditional IT inventories miss entirely.

Technology and SaaS

Product companies whose enterprise customers require independent testing evidence before signing, and whose cloud footprint changes every sprint.

FAQ

External Penetration Testing Questions

What is the difference between external penetration testing and a vulnerability scan?
A vulnerability scan is automated and produces a list of potential weaknesses on the hosts you point it at, many of which are false positives or not actually exploitable in your configuration. An external penetration test goes further: a human tester discovers assets you did not know you exposed, safely exploits the weaknesses that are real, and chains them together to prove what an anonymous outsider could actually reach. A scan tells you what might be wrong; a pen test tells you what an adversary could do with it.
How is external penetration testing different from internal penetration testing?
External testing starts from the public internet with no credentials and answers whether an outsider can get in at all. Internal penetration testing starts inside your network, simulating a phished employee or a compromised laptop, and answers how far an attacker gets once they are already inside: how quickly they reach domain administrator, and what data is in the blast radius. Most mature programs run both, and organizations under PCI DSS, CMMC, or SOC 2 obligations typically test both scopes annually.
How long does an external penetration test take?
Most engagements run one to three weeks from kickoff to final report, depending on the size of your external footprint, the number of live services in scope, and the testing depth you choose. Discovery and reporting are usually the longest phases. We agree on the schedule during scoping and coordinate testing windows so there is minimal impact on your operations.
Will the test disrupt our services or take anything offline?
We design every engagement to be safe. Denial-of-service techniques and destructive testing are excluded by default, exploitation is controlled and staged, and anything carrying operational risk is coordinated with your team before we proceed. The written rules of engagement define exactly what is in scope and what is off limits before any testing begins, and you receive our source addresses so your monitoring team can distinguish our activity from a genuine attack.
How often should we run an external penetration test?
Annually at minimum, and after any significant change to your internet-facing environment such as a new remote access gateway, a cloud migration, a merger, or a major infrastructure change. PCI DSS explicitly requires testing annually and after significant change. Because the perimeter shifts constantly, many clients pair an annual test with continuous vulnerability scanning between engagements so newly published flaws on known hosts are caught quickly.
How much does external penetration testing cost?
Cost depends on scope: the number of live internet-facing hosts and services, the size of your address space and domain footprint, whether cloud tenants are included, and the depth of testing you choose. We price each engagement after a short scoping call so the figure reflects your actual exposure rather than a generic package. That call is free and carries no obligation.
What compliance frameworks require external penetration testing?
PCI DSS requires external penetration testing at least annually and after significant changes to the cardholder data environment. CMMC and NIST 800-171 expect defense contractors to perform vulnerability assessment and remediation as a repeating practice. HIPAA requires a thorough risk analysis, for which independent testing is among the strongest inputs. SOC 2 auditors and cyber insurance carriers both look for evidence of independent testing.
Do you retest after we fix the findings?
Yes. After you remediate, we retest the confirmed findings to verify the fixes hold and provide an attestation letter suitable for auditors, insurers, prime contractors, and enterprise procurement teams. Validation is part of the engagement, because a finding is only truly closed once we have confirmed the fix works.
Are you local to North Carolina?
Petronella Technology Group is headquartered in Raleigh, NC, and serves clients across the Triangle, the wider Carolinas, and nationwide. External penetration testing is performed remotely by its nature, so we support businesses anywhere in the country. Local clients frequently combine it with an onsite cybersecurity risk assessment or an internal engagement.

Last Updated: July 22, 2026

Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912 · Serving Raleigh, the Triangle, and clients nationwide