External IT Infrastructure Penetration Test

Fixed project price from 4,200 €, no hourly billing

30 minutes, no preparation needed. You will receive a written offer within a few working days.

Martin Grottenthaler

Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017.

External penetration test, test external IT infrastructure and attack surface

Diese Seite ist auch auf Deutsch verfügbar.


An External IT Infrastructure Penetration Test assesses your internet-facing systems (servers, VPNs, mail, remote access) for exploitable vulnerabilities and exposure that an attacker could use to gain a foothold.

If your system is exposed to the internet, it could potentially be hacked by anyone. Okay, I exaggerate a bit, but I think you understand. Vulnerabilities in your external infrastructure can lead to very bad press and threaten your customers’ personal information. Regular external infrastructure penetration testing keeps that attack surface in check.

Looking for the internal test instead? This one covers your internet-facing systems. To test what an attacker could do after already getting a foothold inside your network, see the Internal IT Infrastructure Penetration Test.

Scope

This test can focus on a range of externally accessible IPs. Another approach is to collect information about your external attack surface, meaning what information can an attacker find out about your company and which services are exposed (that you might not even know about). These are the main focus points of the test:

  • Detection of vulnerabilities in your external infrastructure. VPN gateways, mail servers, RDP/Citrix gateways, and other remote access solutions are common entry points
  • Identification of outdated software and used libraries, including known CVEs in internet-facing appliances
  • Check for missing hardening measures that can protect you in case there is a vulnerability
  • Publicly exposed sensitive information, e.g. in cloud storage, code repositories, or misconfigured file shares
  • Insecure configuration of services

Internet-facing appliances are a recurring source of critical findings industry wide. See Exploiting a CheckPoint VPN Gateway with One Simple Command for a concrete example of the kind of vulnerability class this test is designed to catch.

As an optional add-on, this test can be combined with OSINT (Open Source Intelligence): researching what an attacker could learn about your company, infrastructure, and employees from public sources (leaked credentials, exposed subdomains, metadata, code repositories) before ever sending a packet. This is not part of the standard scope and is agreed separately during scoping.

Why

  • Do you even know all the services that are exposed to the internet?
  • Are you sure you are not unintentionally leaking sensitive data?
  • Did you apply all the additional security measures that can prevent attacks?
  • Are all your services configured according to best practices?

Why VidraSec 🦦

I have worked in penetration testing and red teaming since 2017. In this time, I have seen many different systems and found a lot of vulnerabilities. Fun fact: in all this time, there have been worse and better systems, but there has never been a system without any vulnerabilities. Let’s improve your security together!

Typical Duration

2+ days of testing (heavily scope-dependent, depends on the number of IPs and services in scope). Reporting takes roughly 30 to 50% of the test time on top.

Typical Price

from 4,200 €

The final price depends on the scope and is calculated from the planned effort, which the offer itemizes transparently (person-days times daily rate). The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same.

Deliverables

Every engagement includes:

  • Written findings report with all vulnerabilities, prioritized by severity, with remediation steps
  • Management summary tailored to your audience (technical or executive)
  • Live debriefing to walk through findings and answer questions
  • Retesting after remediation available on request

See example reports for what a VidraSec report looks like.

Compliance

Directly relevant for NIS2 (Article 21), ISO 27001, and GDPR: exposure of internet-facing services can directly risk customer personal data.

Frequently asked questions

What is the difference between an external and an internal penetration test?

An external penetration test attacks your perimeter from the internet, the way an outside attacker would. An internal penetration test simulates an attacker who already has a foothold inside the network. Many organizations combine both to cover the full attack chain.

Will the test affect our live systems?

Testing is conducted carefully to avoid disruption. Potentially intrusive checks are coordinated with you in advance, and a contact is kept available during testing so anything unexpected can be paused immediately.

How long does an external penetration test take?

From around 2 days, heavily dependent on the number of IPs and services in scope, plus roughly 30 to 50 percent of that time for reporting.

How much does an external penetration test cost?

From 4,200 euros. The final price depends on the number of systems in scope and is calculated individually based on the required effort.

More questions on pricing, lead times, NDAs, or compliance: see the general FAQ

Testimonials

Schedule a free initial call

In 30 minutes we discuss your environment and your goals, with no obligation. You then receive a tailored offer with a fixed price. I usually reply within one business day. Get in touch however suits you best:

Fastest way to an offer

Book appointment (opens in a new tab)

martin​@​vidrasec.com

+43 670 3081275

+43 670 3081275 (opens in a new tab)

Related Blog Posts