External penetration testing
How an attacker sees your organisation from the outside — and how a controlled test finds the gaps first. What external testing covers, how it differs from internal testing, and what a good engagement should deliver.
What it covers
An external penetration test looks at everything your organisation exposes to the internet and tries to break in the way a real attacker would — starting with no access at all. Typical targets include:
- Public web servers, portals, and APIs
- Firewalls, VPN gateways, and remote-access services
- Mail servers and other exposed application services
- Misconfigured cloud storage and forgotten or shadow assets
The tester enumerates what is reachable, identifies weaknesses, and — within the agreed rules of engagement — safely demonstrates what could be exploited, rather than just listing theoretical issues.
External vs internal
The two answer different questions. External testing measures your exposure to the open internet: could a stranger get in? Internal testing assumes a foothold already exists — a phished laptop, a rogue insider, a compromised supplier — and measures how far that foothold could spread. A mature programme uses both, because a hard perimeter with a soft interior is a common and dangerous shape.
What a good engagement looks like
Expect a clearly scoped list of in-range assets, a mix of automated and manual testing, and a report that ranks findings by real-world risk with concrete remediation advice — not just raw scanner output. A good firm will also offer a retest once you have fixed the issues, so you can prove the gaps are closed.
Frequently asked
What is external penetration testing?
External penetration testing assesses the systems an organisation exposes to the internet — its perimeter — from the position of an outside attacker with no prior access. It targets public-facing servers, firewalls, VPNs, mail and web services, and anything else reachable from the open internet.
How is it different from internal penetration testing?
External testing starts from the internet with no credentials and asks "what can an outsider reach and exploit?" Internal testing starts from inside the network — as if an attacker already had a foothold, or a malicious insider — and asks "how far can they go from here?" Many organisations do both.
How long does an external test take?
A typical external test runs a few days, depending on how many live hosts and services are exposed. A larger perimeter, or one with many web applications, takes longer.
How often should we run one?
At least annually, and after any significant change to internet-facing infrastructure — a new service, a migration, or a merger. Some compliance regimes require it on a set cadence.
Compare UK penetration testing companies
Our independent directory lets you filter firms by service, accreditation, and size — sourced from public records, never pay-to-play.
Browse the directory