Skip to content

Home Expertise / Penetration testing

PEN / PEN-01

External penetration testing

An authorised simulation of an internet-based attacker to assess whether exposed services allow unauthorised access or actions.

WHEN IT HELPS

A focused response
to a defined need.

CIO or CISO; a new site, customer portal, remote access service or contractual requirement for independent testing.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Authorised addresses and domains
  • targeted reconnaissance
  • manual validation of vulnerabilities and impacts without destructive actions

Deliverables

  • Executive and technical reports
  • minimised evidence
  • remediation priorities and the actual tested scope

Acceptance evidence

Confirmed vulnerabilities are distinguished from unvalidated leads; time, access and depth limitations are explicit.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Who owns the assets? Does the provider authorise testing? Which actions must trigger an immediate stop?

IMPORTANT BOUNDARIES

Written authorisation is mandatory; denial of service, persistence and real data exfiltration are excluded by default.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

An SME exposes a supplier portal and VPN. Project: black-box testing of authorised assets. Target outcome: a controlled demonstration of unauthorised access or a report with no major finding, followed by a remediation plan matching the evidence.

Scenario 02

A group has an old subdomain within the approved scope. Project: validate exposure with the hosting provider. Target outcome: controlled retirement or hardening; testing never expands to third-party infrastructure without permission.

Technology and reference context

Agreed testing methodology; testing tools used only within the authorised scope.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.