External Pentest
An external penetration test shows you what an attacker could achieve from outside. We test your internet-facing systems using realistic attack scenarios.
What is an external pentest?
In an external pentest, we test everything reachable via the internet: web servers, mail servers, VPN gateways, firewalls, DNS configuration and other internet-facing services. The approach simulates an external attacker with no prior knowledge — comparable to how a cybercriminal would approach your organisation.
What do we test?
- External infrastructure — web servers, mail servers, VPN and remote access portals
- Network perimeter — open ports, unsecured services, outdated software
- DNS & certificates — misconfigurations, expired certificates, subdomain takeover
- Credential exposure — leaked passwords and accounts via OSINT
- Web applications — publicly accessible applications and APIs
Black box approach
An external pentest is carried out as black box by default: no prior knowledge, no credentials — exactly how a real attacker operates. On request, we add a grey box component for deeper application testing. More on the differences on the pentest methodology page.
FAQ
Will this disrupt our production environment?
We plan and test in a controlled manner. If there’s a risk of disruption, we discuss timing and approach in advance.
Can this be repeated periodically?
Yes, periodic validation is recommended — especially after infrastructure changes or as part of NIS2 or ISO 27001 compliance.
How long does an external pentest take?
Usually 1 to 3 business days, depending on the size of the external surface.
Request an external pentest · Web application pentest · Pricing
Compliance & Sector-Specific Pentests
Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.
- DigiD Pentest & IT Security Assessment — mandatory for organisations with a DigiD connection
- ISO 27001 Pentest — support for certification
- NIS2 Pentest — technical assessment for NIS2-obligated organisations
- PCI DSS Pentest — mandatory test for payment environments
- Government Pentest — BIO-aligned for the public sector
- Healthcare Pentest — NEN 7510 and GDPR-focused
- SaaS Pentest — for software and platform companies
