✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

External Pentest

An external penetration test shows you what an attacker could achieve from outside. We test your internet-facing systems using realistic attack scenarios.

What is an external pentest?

In an external pentest, we test everything reachable via the internet: web servers, mail servers, VPN gateways, firewalls, DNS configuration and other internet-facing services. The approach simulates an external attacker with no prior knowledge — comparable to how a cybercriminal would approach your organisation.

What do we test?

  • External infrastructure — web servers, mail servers, VPN and remote access portals
  • Network perimeter — open ports, unsecured services, outdated software
  • DNS & certificates — misconfigurations, expired certificates, subdomain takeover
  • Credential exposure — leaked passwords and accounts via OSINT
  • Web applications — publicly accessible applications and APIs

Black box approach

An external pentest is carried out as black box by default: no prior knowledge, no credentials — exactly how a real attacker operates. On request, we add a grey box component for deeper application testing. More on the differences on the pentest methodology page.

FAQ

Will this disrupt our production environment?

We plan and test in a controlled manner. If there’s a risk of disruption, we discuss timing and approach in advance.

Can this be repeated periodically?

Yes, periodic validation is recommended — especially after infrastructure changes or as part of NIS2 or ISO 27001 compliance.

How long does an external pentest take?

Usually 1 to 3 business days, depending on the size of the external surface.

Request an external pentest  ·  Web application pentest  ·  Pricing

Compliance & Sector-Specific Pentests

Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.

Scroll to Top