External Penetration Testing
Expert-led testing that attacks your internet-facing perimeter the way a real adversary would: probing exposed services, VPNs, mail servers, cloud tenants, and forgotten hosts to prove what an outsider can actually reach. Delivered by a North Carolina cybersecurity firm that has protected regulated businesses since 2002.
What Is External Penetration Testing?
External penetration testing is an authorized, simulated cyberattack launched from the public internet against everything your organization exposes to the outside world: firewalls, VPN gateways, mail servers, web servers, remote access portals, and cloud services. Security professionals attempt to discover, enumerate, and safely exploit those systems exactly as an unauthenticated attacker would, with no credentials and no insider knowledge. The result is documented proof of which perimeter weaknesses can actually be used to reach your internal network or your data, ranked by real risk rather than by scanner severity.
Key Takeaways
- External penetration testing simulates an outside attacker with zero access, proving which internet-facing systems are genuinely exploitable rather than simply flagged by a scanner.
- Petronella Technology Group has delivered offensive security testing since 2002, holds a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) with a CMMC-RP certified team.
- Our methodology follows NIST SP 800-115, the Penetration Testing Execution Standard, and the OSSTMM, and satisfies perimeter testing requirements in PCI DSS, CMMC, NIST 800-171, HIPAA, and SOC 2.
- Founder Craig Petronella is an MIT-certified cybersecurity professional, NC Licensed Digital Forensics Examiner (License #604180-DFE), and cybersecurity expert witness, so our testing reflects how perimeter breaches actually unfold.
Why Your Perimeter Needs a Real Pen Test
Your external attack surface is the only part of your network that every attacker on earth can reach without any help from an insider. It is scanned continuously, automatically, and indiscriminately, and it is where the overwhelming majority of intrusions begin.
Most organizations do not have an accurate picture of what they expose. A marketing team stands up a landing page on a subdomain. A developer opens a management port for a weekend migration and never closes it. A vendor integration adds an API endpoint nobody documented. A cloud engineer builds a storage bucket for a one-time transfer. Each of these is invisible on an internal asset list and perfectly visible to an attacker running automated discovery against your address space. External penetration testing starts by rebuilding that picture from the outside, which is frequently the single most valuable deliverable of the engagement.
Automated vulnerability scanning is useful, but it stops well short of proof. A scanner will tell you that a VPN appliance is running a version with a published flaw. It will not tell you that the flaw is genuinely reachable through your configuration, that a valid credential can be recovered from a public breach corpus, that multi-factor authentication was never enforced on that gateway, or that the three findings chain together into full remote access. A skilled tester does exactly that chaining, and the difference between "twelve medium findings" and "one proven path from the internet into your file server" is the difference between a report that gets shelved and a report that gets funded.
The commercial pressure is real too. Cyber insurers now underwrite on the strength of your perimeter controls and increasingly ask for evidence of independent testing. Enterprise customers send security questionnaires before they sign. Prime contractors ask their subcontractors to demonstrate assessment activity. Regulators and auditors expect documented testing under PCI DSS, and defense supply chain requirements under CMMC and NIST 800-171 expect vulnerability assessment and remediation to be a repeating practice. A current external penetration test turns all of those conversations from an assertion into evidence.
Petronella Technology Group brings a defender's and an investigator's perspective to every engagement. Because our founder works real digital forensics and expert-witness cases, we have seen exactly how attackers move once they get through a perimeter, and we test the routes that actually get used rather than the ones that merely look impressive in a report. Pair a test with our managed cybersecurity services and the findings get remediated, monitored, and retested rather than filed away.
What We Attack From the Outside
Every internet-reachable asset tied to your organization is in scope, including the ones your team has forgotten about. Discovery comes first, because you cannot defend what you do not know you own.
Perimeter Infrastructure
- Firewalls, edge routers, and exposed management interfaces that should never have been reachable
- VPN concentrators, remote desktop gateways, and jump hosts, including missing or bypassable multi-factor authentication
- Mail servers, webmail portals, and mail security gateways, including relay abuse and authentication weaknesses
- DNS configuration, subdomain takeover candidates, and orphaned records pointing at deprovisioned services
Services, Cloud, and Identity
- Public cloud tenants, storage buckets, serverless endpoints, and misconfigured identity federation
- Exposed databases, file transfer services, backup appliances, and printer or IoT management panels
- Credential exposure: password reuse from public breach data, weak lockout policy, and password spraying against portals
- Open source intelligence: employee enumeration, leaked keys in public repositories, and metadata that aids an attacker
Where your public-facing applications are the primary concern, we recommend pairing this engagement with a dedicated web application penetration test, which examines authenticated workflows, business logic, and API authorization in a depth that a perimeter test does not attempt.
See Your Network the Way an Attacker Does
We will scope an external penetration test against your real internet-facing footprint and show you exactly what an outsider can reach. Call 919-348-4912 or request a quote.
External vs. Internal Penetration Testing
The two tests answer different questions, and most mature security programs run both. Understanding the difference is the first step in scoping an engagement that produces useful answers.
External Penetration Testing
- Starting point: the public internet, with no credentials and no network access
- Question answered: can an anonymous outsider get in at all, and how far?
- Typical findings: exposed services, weak remote access, subdomain takeover, credential reuse, perimeter misconfiguration
- Best for: every organization, as the baseline test and the one auditors ask about first
Internal Penetration Testing
- Starting point: inside your network, simulating a compromised workstation, a rogue insider, or an attacker who already phished a user
- Question answered: once someone is inside, how quickly do they reach domain administrator and your crown-jewel data?
- Typical findings: flat networks, weak Active Directory configuration, credential harvesting, lateral movement paths, excessive privilege
- Best for: organizations with an established perimeter that need to measure blast radius and ransomware exposure
The honest answer to "which one do we need?" depends on where you are. If you have never had an independent test, start externally: it is the attack surface an opportunistic adversary will find first, and it is what your insurer and your customers will ask about. If your perimeter is well managed but a single phished employee would put your entire environment at risk, an internal engagement tells you far more. Organizations under CMMC, PCI DSS, or SOC 2 obligations typically run both on an annual cycle, with external testing repeated more frequently because the perimeter changes constantly.
Both scopes are available from our team, and many clients combine them into a single network penetration testing engagement so that one report covers the full path from the open internet to the data an attacker is actually after. We will help you decide during scoping rather than selling you the larger engagement by default.
Our External Pen Test Process
A structured, standards-aligned engagement built on NIST SP 800-115 and the Penetration Testing Execution Standard, with written rules of engagement agreed before any packet is sent.
Scoping and Rules of Engagement
We agree in writing on the address ranges, domains, and cloud tenants in scope, the testing window, escalation contacts, and the boundaries we will not cross. You receive our source addresses so your team can distinguish our activity from a genuine attack, and we confirm authorization for any assets hosted by a third party.
Reconnaissance and Attack Surface Discovery
We rebuild your external footprint from the outside using passive intelligence, certificate transparency records, DNS enumeration, and cloud asset discovery. This routinely surfaces hosts, subdomains, and services that were never on the client's inventory, and that discovery alone often changes how a security team allocates its budget.
Enumeration and Vulnerability Analysis
Every reachable service is fingerprinted for version, configuration, and exposure. We combine automated tooling for coverage with manual analysis for accuracy, discarding the false positives that make raw scanner output so hard to act on, and identifying the weaknesses that are genuinely reachable in your specific configuration.
Controlled Exploitation and Chaining
We safely validate findings by exploiting them under the agreed rules of engagement, then look for the chains: an information leak that enables user enumeration, enumeration that enables a password spray, a recovered credential that reaches a gateway without multi-factor authentication. Destructive techniques are excluded, and anything with operational risk is coordinated with your team first.
Reporting and Executive Debrief
You receive a report written for two audiences: an executive summary that explains business risk in plain language, and a technical section with reproduction steps, evidence, and specific remediation guidance. We walk your team through it on a live debrief so questions get answered while the findings are fresh.
Remediation Support and Retesting
After you fix the confirmed findings, we retest them to verify the fixes hold and issue an attestation letter suitable for auditors, insurers, and enterprise customers. A finding is only closed once we have proven the fix works in practice.
What You Receive After the Test
External Attack Surface Inventory
A documented list of every internet-facing asset we identified, including the hosts, subdomains, and services that were not on your inventory before the test began.
Ranked Findings With Evidence
Each finding carries a business-risk rating, technical detail, screenshots or captured evidence, and clear reproduction steps so your team can confirm and fix it without guesswork.
Proven Attack Paths
Where we chained findings into a route from the public internet toward your internal environment, that path is documented end to end so leadership understands the actual consequence.
Prioritized Remediation Roadmap
A sequenced plan that separates the fixes to make this week from the architectural work to schedule this quarter, with effort and impact called out for each.
Executive Summary and Live Debrief
A board-ready summary written without jargon, plus a working session with your team to answer questions and align on ownership of each remediation item.
Retest and Attestation Letter
Validation that your fixes hold, documented in a letter you can hand to auditors, cyber insurers, prime contractors, and enterprise procurement teams.
External Pen Test vs. the Alternatives
Perimeter assurance is sold in several forms, and they are not interchangeable. Here is what each one actually delivers.
| Capability | External Pen Test | Automated Scan | DIY Internal Review |
|---|---|---|---|
| Discovers unknown internet-facing assets | Yes, from the outside in | Only what you point it at | Limited to the internal inventory |
| Proves exploitability | Yes, with evidence | No, flags potential issues only | Rarely, and not independently |
| Chains weaknesses into attack paths | Yes, core of the engagement | No | Uncommon without offensive experience |
| False positives filtered by a human | Yes, every finding validated | No, output is raw | Depends entirely on staff capacity |
| Independence for auditors and insurers | Yes, third-party attestation | Partially, tooling evidence only | No, self-assessment |
| Remediation guidance and retest | Included, with attestation letter | Generic vendor advisories | Internal effort, no external validation |
None of this makes scanning worthless. Continuous scanning is exactly the right tool for catching a newly published vulnerability on a known host between engagements, and we build it into our vulnerability assessment programs for that reason. The point is that scanning and testing answer different questions, and only one of them tells you what an adversary can actually accomplish.
Find the Gaps Before Attackers Do
A scoping call takes about twenty minutes and costs nothing. We will tell you honestly whether an external test, an internal test, or an application test gives you the most value right now.
External Testing for Compliance Requirements
Perimeter testing is written into most of the frameworks our clients operate under, and the evidence an assessor wants is specific.
PCI DSS requires external penetration testing at least annually and after any significant change to the cardholder data environment, performed by a qualified party using an industry-accepted methodology and covering the full perimeter of the environment. Our reports are structured to map findings directly to the relevant requirements, which is what makes them usable during an assessment rather than merely informative. See our PCI DSS compliance services for the broader program.
CMMC and NIST 800-171 expect defense contractors to scan for vulnerabilities, remediate them in accordance with risk, and demonstrate that the practice repeats. External testing produces exactly the evidence a C3PAO wants: documented scope, dated results, ranked findings, and proof of remediation. As a CyberAB Registered Provider Organization (RPO #1449) with CMMC Registered Practitioners on staff, our team scopes testing to align with your System Security Plan rather than producing a report that has to be reinterpreted later. Explore our CMMC compliance services.
HIPAA requires covered entities and business associates to conduct an accurate and thorough risk analysis of the risks to electronic protected health information. Independent external testing is one of the strongest inputs to that analysis, and it is the input that regulators find most credible because it is empirical rather than declared. Craig Petronella is the author of How HIPAA Can Crush Your Medical Practice, and that framing informs how we document findings for healthcare clients pursuing HIPAA compliance.
SOC 2 and cyber insurance both look for evidence of independent testing under the security criteria and on renewal questionnaires respectively. Carriers increasingly ask directly whether the applicant performs penetration testing and how recently, and an accurate answer with an attestation letter attached is a materially better position than a checkbox. Our SOC 2 compliance team can align the testing cadence to your audit period.
Why Businesses Trust Our Testing
- Attacker experience, not just tools. Our founder is an NC Licensed Digital Forensics Examiner and cybersecurity expert witness who investigates real breaches, so we test the perimeter routes attackers actually take.
- Manual validation of every finding. Automated tooling gives us coverage, but the exploitation, chaining, and judgment come from experienced testers who confirm each finding by hand before it reaches your report.
- Compliance fluency. As a CyberAB Registered Provider Organization (RPO #1449), we know how PCI DSS, CMMC, HIPAA, and SOC 2 expect perimeter testing to be scoped, executed, and documented.
- We can fix what we find. Many testing firms hand over a report and leave. Our managed security and compliance teams can implement the remediation, which means findings close instead of aging.
- Proven longevity. Founded in April 2002 and BBB A+ rated since 2003, we have defended North Carolina and national clients through more than two decades of evolving threats.
"Petronella's work has been a major factor in our business success, helping it to become one of the most secured networks of its kind on the Internet."
Financial Services Firm, Raleigh, NC
We are rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews. You can read them on our reviews page.
Related Security Services
Industries We Test For
Since 2002 we have tested perimeters for organizations whose exposure carries regulatory as well as financial consequence.
Defense Contractors
Suppliers handling controlled unclassified information who need documented assessment evidence for CMMC and NIST 800-171 obligations flowed down by their primes.
Healthcare Practices
Medical, dental, and behavioral health organizations whose patient portals, remote access, and practice management systems face the internet directly.
Law Firms
Practices holding privileged client material, where a perimeter compromise carries an ethical duty of disclosure alongside the business damage.
Financial Services
Advisors, lenders, and accounting firms operating under GLBA and FTC Safeguards expectations with client financial data reachable through online services.
Manufacturing and Logistics
Operations where remote access to plant systems and vendor connectivity create perimeter exposure that traditional IT inventories miss entirely.
Technology and SaaS
Product companies whose enterprise customers require independent testing evidence before signing, and whose cloud footprint changes every sprint.
External Penetration Testing Questions
What is the difference between external penetration testing and a vulnerability scan?
How is external penetration testing different from internal penetration testing?
How long does an external penetration test take?
Will the test disrupt our services or take anything offline?
How often should we run an external penetration test?
How much does external penetration testing cost?
What compliance frameworks require external penetration testing?
Do you retest after we fix the findings?
Are you local to North Carolina?
Last Updated: July 22, 2026
Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912 · Serving Raleigh, the Triangle, and clients nationwide