Chains walked by a human, not dumped by a scanner
A senior specialist validates and chains every finding. No false positives, only what is real and reachable from the public internet.
Exploited vulnerabilities are now among the top ways breaches begin, and they nearly all start at the perimeter (Verizon DBIR 2024). Our external penetration testing attacks your internet-facing surface with no credentials and no whitelist, chains what we find, and proves which exposed asset leads to a foothold inside your network.
How an external pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















We begin with your apex domain and nothing else, the same position as a stranger on the internet. Tools map the obvious surface. The chain is human work.
The way in is rarely one obvious hole. It is a forgotten subdomain, an unpatched edge appliance, a secret pushed to a public repository, or a login portal with no lockout. We chain them and prove the path to a shell on something internal, with the exact request your team can replay.
An external pentest asks whether someone on the internet can break in. An internal pentest asks how far an attacker gets once inside.
Not sure where to start?
A customer questionnaire, an insurer renewal, an M&A diligence, a cloud migration or a public launch forces the date.
When ISO 27001, ENS, PCI DSS, SOC 2, NIS2 or DORA is on the line, the report has to survive scrutiny: traceable scope, recognised methodology, signed retest, execution certificate.
When the ask is about what your organisation exposes to the internet, you need an external, expert-led pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.
Every change to the perimeter moves what an attacker can see from outside. We test with no credentials and no allowlist, against the surface as it stands after the change, and prove which exposed asset still leads inside.
The question is not ‘do we have findings’ but ‘are there other ways in’. We confirm from the outside that the entry path used, or feared, is closed, and map every adjacent asset that still leads to a foothold.
You inherit whatever the other side left facing the internet, including what nobody documented. We enumerate that perimeter from outside with no credentials and prove which asset leads to a foothold.
An attacker starts with your domain and nothing else. So do we. Your perimeter decides the path.
Most external tests stop at a list of open ports. Here is where we go further.
A senior specialist validates and chains every finding. No false positives, only what is real and reachable from the public internet.
Alongside the report, a live inventory of every internet-facing asset we found, including the shadow IT, expired vendors and forgotten subdomains your CMDB never tracked.
A medium-severity CVE on an unpatched VPN that yields an internal shell outranks a dozen high-severity findings that lead nowhere. We rank by what actually gets an attacker in.
Optional purple-team mode: every step logged and timed, so your SOC, EDR and WAF are measured against the attack chain in parallel.
We at Etnia highly value our collaboration with Asperis Security.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us your apex domain and where you want us to start. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.
An external penetration test is a controlled, manual attack on your internet-facing assets: domains, VPNs, edge appliances, mail, DNS and cloud perimeter, performed with no credentials to prove what an attacker could reach from outside. Unlike an internal test, it starts from the public internet with no prior access. The deliverable is a short list of validated attack chains, ranked by how close each one gets to a foothold inside your network, each with a reproducible proof of concept.
A vulnerability scan returns an automated list of open ports and possible CVEs, mostly unverified and uninterpreted. An external pentest is a specialist chaining OSINT, surface enumeration and controlled exploitation into a path that actually works against your specific perimeter. You get a short list of proven chains ranked by foothold potential and blast radius, not a raw scanner export. We use scanners to accelerate reconnaissance, never as the deliverable.
A focused external pentest of a single apex domain typically runs one to two weeks of active testing, plus scoping beforehand and the retest after your fixes. Larger multi-domain, multi-country or multi-cloud perimeters run two to four weeks. We deliver the proposal and timeline within 48 hours of the first call, so you know the dates before you commit.
No, not without your explicit consent. Every engagement ships with documented Rules of Engagement: test windows, permitted intensity, forbidden actions and a kill-switch contact. Our default posture on live assets is passive reconnaissance and validated proofs of concept, with no destructive testing and no password spraying unless you ask for it. Where production exploitation is agreed, it runs under rate limits with your team on standby, and we abort anything that risks availability.
Price follows scope, complexity and test type (black box, grey box or white box), and we quote a fixed price with no hidden fees and no obligation to renew. A focused assessment of a small apex domain sits at the bottom of the range; larger perimeters scale from there. The retest that confirms your fixes is always included in the price.
Grey box fits most first engagements: you give us your public asset inventory and scope boundaries, so we spend the time testing rather than rediscovering what you already know. Black box mirrors a real attacker with only your apex domain, best for the annual re-baseline. White box adds architecture diagrams and a technical contact for the deepest coverage. We will recommend the right one on the introductory meeting.
The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP credentials, most have worked inside enterprise security or red teams, and we are NASA Bug Bounty verified contributors with published CVEs against widely deployed edge appliances. The same person scopes, executes and retests. They are who you deal with from start to finish.
At least once a year as a compliance floor for ISO 27001, ENS, PCI DSS, SOC 2, NIS2 and DORA. Highly dynamic or highly exposed perimeters warrant every six months or a continuous programme. A fresh test is also warranted by any material change: a new VPN or SSO integration, a public go-live, an acquisition, a cyber-insurance renewal, or a breach in your sector.
Start with a no-obligation introductory meeting. We will review your apex domain, your edge stack and your starting assumption, and define the right external pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Got it.
Request received. A senior specialist will reply within one business day with scope, a fixed quote and a timeline.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.