Services / 01

External Security Testing

Network, web, API, cloud and wireless testing run by hand against your real perimeter. Every finding is reproduced by a second analyst before it is written up, and the report tells your engineers exactly how to fix it.

PENTESTRED TEAMRETEST
Overview

What the practice does.

Scanners find what scanners find. We start where they stop: logic flaws, chained weaknesses, authentication and authorization gaps, and the configuration drift that only shows up when someone looks at your environment the way an attacker would.

The engagement is scoped in writing, run by named consultants, and finished with a retest window so you can prove the fixes landed.

What you get

Deliverables.

Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.

01

Scope and rules of engagement

Assets, testing windows, exclusions, escalation contacts and the questions you want answered, signed before any traffic is sent.

02

Manual testing against the live perimeter

External network, web applications, APIs, cloud control planes and wireless, tested by hand with tooling in support. Depth is agreed up front: unauthenticated, authenticated or role-based.

03

Reproduced, scored findings

Each issue carries exact reproduction steps, evidence, a CVSS score adjusted for your context, and a fix. A second analyst reproduces every finding before it ships.

04

A report for two audiences

An executive summary that reads in ten minutes, a technical appendix your engineers can work from, and a prioritised fix list.

05

Retest and closure letter

A retest window to confirm remediation, with a closure letter you can hand to customers, auditors and your board.

How it runs

The four steps, applied.

The method is the same for every practice. This is what each step means here.

01 / SCOPE

The asset list is confirmed against DNS, certificate transparency and cloud inventories, so nothing in scope is missed and nothing out of scope is touched.

02 / TEST

Reconnaissance, then manual testing in agreed windows. Daily notes are shared during the engagement and critical findings are called in the same day.

03 / VERIFY

A second analyst reproduces every finding from the notes alone. Anything that cannot be reproduced does not make the report.

04 / REPORT

Executive summary, technical appendix, fix list and retest window. Delivered as a document and as a findings export your tracker can import.

When to call us

The situations this is built for.

Before a customer or auditor asks

SOC 2, ISO 27001 and most enterprise procurement teams expect an annual external test from an independent party. We write the report with that reader in mind.

After a change that moved the perimeter

A new public API, a cloud migration, an acquisition or a new identity provider. Test what changed before the change becomes the story.

When the last test was a scan

If your previous report was an exported scanner result, you have a list of version numbers, not evidence. We start from scratch and reproduce everything.

Questions

Asked before most engagements.

How long does an external test take?

A focused web application or external network test usually runs five to ten working days from scoping to report, depending on the number of assets and the depth agreed. Larger scopes are phased so you receive findings as they are verified rather than at the end.

Will testing affect production?

Testing is scheduled in windows you choose, with denial-of-service and destructive techniques excluded by default. Anything riskier is agreed in writing first and run with your team on standby.

What is the difference between this and Frontier Verify?

Frontier Verify is our self-serve platform: you pick assets and depth, pay by card, and receive a human-verified report inside a week. It suits defined, repeatable scopes. A consulting engagement suits complex environments, custom rules of engagement, red team objectives, or when you want the consultants in the room.

Do you retest?

Yes. Every engagement includes a retest window. Fixed findings are re-verified and the report is reissued with a closure summary.

Request a quote

Tell us what you need tested, assessed or governed.

A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.

Start on Frontier Verify