Published 27/05/2025 – est. 7 minutes to read.
Penetration testing – pen testing for short
It does not need to be a full-blown simulated cyber attack. In most cases, a pen test focuses on one or more aspects of your company’s digital assets, and it is conducted openly and transparently. The aim of a pen test may be to uncover security issues in your external infrastructure, your Internet-connected, public asset, or to focus on a single web or mobile application. It could also examine how your cloud-based infrastructure is configured (rather than the infrastructure itself). A penetration test could be one of these things, or a combination of them, depending on what you have and where the biggest threats are likely to be.
At the more advanced end of pen testing is red teaming, which aims to simulate a real attack and test your blue team’s capabilities. If you’re reading this, you may be your company’s blue team, or you may not have one yet. Red team engagements are usually reserved for organisations that already conduct regular pen testing and are confident in their overall security posture. There are plenty of ways of improving security across the board before reaching the red team stage. This includes actions you can take internally, as well as services offered by trusted partners.
In this blog series
The team at Cyber Security Specialists will take you through the various types of penetration testing – what they are and how they can benefit your business. We will also show you how best to prepare for these security assessments, the information penetration testers require from you (and why they need it), and what you can do on your own to bolster security.
First up, we will take a look at the external penetration test (often referred to as an external assessment). This can be considered the starting point for any organisation that exposes devices to the public Internet. These could be web servers, API servers, firewall appliances, VPN servers, anything with a public IP address, regardless of how or where it’s hosted.
External Infrastructure Assessment
The penetration tester, whom you will already have met, will let you know when they begin. Most external assessments commence with port scanning. This means that each computer system reachable on the public Internet will be checked to determine which ports are open and accessible. This includes both Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) ports. You will provide a list of Internet Protocol (IP) addresses in advance, and these hosts form the scope of the assessment.
After port scanning, more details about any open ports will be gathered. The pen tester will determine which software is running on any identified open ports and the versions of that software. If a publicly known vulnerability exists in any of the observed software, it will be investigated further. A good penetration tester will always attempt to exploit any identified vulnerabilities, but only when it can be done safely and without causing disruption. You should expect them to contact you if there is any question over whether an exploitation attempt is likely to cause disruption.
When vulnerabilities are identified, you will receive information either in real time or at the end of the assessment in the penetration test report, or both. Most penetration testers will notify you when they find something deemed high risk. It is up to you whether you would like to be informed of lower-severity vulnerabilities in real time as well.
Pen testing does not stop at finding known vulnerabilities. The tester will investigate anything that seems out of place or does not look right, and if you think this does not sound like an exact science, it is not! Methodology and automated tools work up to a point, but the manual, exploratory approach is also needed. Testers will also look for anything misconfigured, depending on what they encounter. Anything that poses a security risk now or is likely to pose one in the future will be raised, with a score provided based on the perceived risk.
What We Need From You
The following information is required ahead of time to ensure a report free from caveats:
- A list of external hosts that you own and have permission to authorise testing on
- Access to key personnel for clarification and information gathering both before and during the assessment
- Agreement on the start and end dates of the assessment
- Your signed, written permission to test
Why You Need This Type of Assessment
You should assume that your external assets are under constant surveillance by threat actors. The less you expose here, the lower the chance of an (often simple and automated) attack taking critical services offline. Simple attacks could also allow bad actors to access your customers’ data or abuse your infrastructure for other nefarious purposes. External penetration testing identifies weaknesses that attackers outside your organisation may target and exploit. By identifying and mitigating vulnerabilities in your externally facing systems, you can help prevent unauthorised access, data breaches, and other cyber threats originating from the public Internet.
What Can I Do Now?
- Start by making an inventory of your external hosts or checking that your existing lists are up to date. You cannot protect what you do not know about!
- Use a well-known, freely available tool like Nmap (“network mapper”) to identify which ports and services you are currently exposing to the Internet.
- Scan for known vulnerabilities using automated tools – these tools are often not free, but you do not necessarily need to buy them yourself. Consider using Cyber Security Specialists’ CS 360 Managed Service, which includes external vulnerability scanning on all plans, plus much more!
- Keep the software that exposes services externally up to date; perform regular checks for updates and patches.
- Reduce what you expose publicly by removing what you do not need or by moving it behind a VPN or firewall rule that allows only trusted hosts.
- Schedule regular external penetration tests to supplement the other work you are doing – Cyber Security Specialists provide this as a separate service.
Okay, so you’ve got your external assets locked down – what’s next? I can relax now, right?
Getting your external infrastructure in order is a crucial part of improving your organisation’s overall security, so you should celebrate any small wins you’ve accrued so far. Do not stop here, though; there’s more work to be done. In the next instalment, we will take a look at web application testing, why anyone with a web app should be doing it, and why it was not covered in your external penetration test!
Cyber Security Specialists are committed to helping you protect your business from cyber threats through comprehensive penetration testing services. Whether you need to secure your external-facing assets, internal network, web applications, or cloud infrastructure, our team of experts is here to assist you. Contact us today to learn how we can help you enhance your security posture and defend against cyberattacks.
To get your penetration test quote, conduct a Cloud Security audit, or discuss our other services, connect directly with our sales team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
