
Identify exposed services and weak external defences
Our penetration testers review your internet-facing systems to uncover risks like exposed services, outdated software, and weak authentication. We assess patch levels, identify misconfigurations and check whether admin portals or forgotten services can be exploited. Testing is conducted from the public internet, with or without prior knowledge of your environment, and may include unauthenticated enumeration.
Unlike red teaming, this test does not include social engineering or phishing attempts. It is focused on identifying how exposed you are to an attacker with no internal access.
- Uncover outdated or misconfigured public-facing services
- Identify exposed login portals and forgotten subdomains
- Highlight weak or default credentials on external systems
External penetration testing to uncover real-world exposure
Expose weaknesses before attackers do
Go beyond automated scans
We use attacker-style reconnaissance and exploitation techniques to identify vulnerabilities across your external surface. From open ports to forgotten admin panels, we show you how an attacker would target your systems.
- Identify exposed services, admin panels and forgotten assets
- Detect outdated software, misconfigurations and open ports
- Flag risks like default passwords or unauthenticated access points
How is it delivered
Why choose Bastion for external testing
Frequently asked questions
What is an external penetration test?
An external penetration test simulates how an attacker would target your internet-facing systems. It identifies real-world risks like exposed services, weak authentication or outdated software, all without internal access.
How is an external penentration test different from a vulnerability scan?
A vulnerability scan checks for known weaknesses using automated tools. An external penetration test goes further by simulating attacker behaviour to validate those risks and uncover more complex issues.
Will the testing affect our systems or customers?
External testing is carefully scoped to avoid disruption. We work with you to define safe boundaries and use non-intrusive methods unless otherwise agreed.
What will I get after the test?
You’ll receive a prioritised report that explains the risks, affected assets and practical next steps. We also provide remediation advice and support if needed.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia