Network penetration testing
Test what faces the internet and what sits inside—service exposure, weak configurations, and segmentation gaps that put SaaS control planes at risk.
Scope
External: agreed IP ranges and exposed services. Internal: segmented access as provided (VPN/jump host). Focus on service identification, insecure configurations, authentication weaknesses on network services, and lateral paths in scope. Wireless only if explicitly scoped.
Method
CREST-aligned network testing with validated findings—not unchecked destructive DoS. Our testers hold OSCP and CREST certifications.
Deliverables
Network findings with evidence, remediation guidance, optional retest. Useful when SOC 2 boundary or office/cloud hybrid networks are in buyer questionnaires.
Common questions
Possible; internal adds segmentation value.
Often better as /pentesting/cloud or combined.
Agreed in rules of engagement.
Still distinct from app/API tests—kept as its own page.