Penetration testing: external, internal, web application, wireless, and social engineering.
A penetration test simulates a real-world attacker against your environment to find what they would find, before they find it. We deliver scoped tests against your external attack surface, internal network, web applications, wireless, and human attack surface. Every engagement produces a written report with verified findings, proof-of-concept evidence, and a prioritized remediation plan your team can execute, plus the attestation letter your customers, auditors, and insurers ask for.

- 5Pen-test scopes
- PTESMethodology aligned
- 2 wksTypical duration
- VerifiedFindings only
Five pen-test types, each answering a different question.
External penetration testing
Tests your internet-facing attack surface as an unauthenticated external attacker would see it. Domain reconnaissance, public-IP scanning, exposed-service exploitation, web-application surface testing. Answers: what could anyone on the internet do to us?
Internal penetration testing
Tests your internal network as an attacker who has already breached the perimeter, the assumed-breach model. Privilege escalation, lateral movement, Active Directory exploitation, sensitive-data access. Answers: how far could a breach spread before detection?
Web application penetration testing
Tests a specific web application against the OWASP Top 10 plus business-logic flaws. Authentication, authorization, session management, input validation, deserialization, and business-logic abuse. Answers: how would an attacker compromise this specific application?
Wireless penetration testing
Tests your WiFi and Bluetooth attack surface. Rogue access points, WPA exploitation, captive portal bypass, guest-network segregation, BLE device exposure. Answers: how would an attacker near your premises compromise the wireless layer?
Social engineering and phishing
Tests the human attack surface. Phishing campaigns, vishing, and pretexting, measured by click rate and credential-disclosure rate. Answers: how resilient is your organization against the vector that starts most real US breaches?
Four reasons IT leaders engage GR for penetration testing.
Methodology-aligned, not script-aligned
Testing aligned to PTES, OWASP, and NIST SP 800-115 methodologies. Manual testing layered on top of automated tooling, with every reported finding verified by exploitation evidence rather than auto-generated from scanner output.
Reports written for two audiences
An executive summary for leadership: business risk, severity heat map, recommended priorities. A technical report for engineers: exploitation steps, evidence, remediation guidance per finding. Both rigorous, both readable, and both usable as compliance evidence.
Remediation support included
Many pen-test firms hand over a report and disappear. We include remediation-support hours: clarification calls, technical guidance on fixes, and a re-test of remediated findings within the engagement window so your final report shows closure, not just discovery.
Built for the people who will read it
SOC 2 auditors, PCI assessors, cyber insurance underwriters, and enterprise procurement teams each want specific things from a pen-test report. We write findings, attestation letters, and control mappings so the report answers their questions the first time, without a follow-up cycle.
Six triggers for a penetration test.
Annual security baseline
SOC 2 and NIST-aligned security programs treat an annual penetration test as a baseline control, and auditors ask for the most recent report.
Pre-launch web application
Before launching a customer-facing web app or API, test the application before attackers get their turn.
Post-major-change validation
After a cloud migration, network redesign, or major infrastructure change, validate that the new posture holds.
Compliance-mandated testing
PCI DSS requires periodic penetration testing for card-data environments, and CMMC/NIST 800-171 programs expect testing evidence.
Post-incident
After an incident or near-miss, a pen test validates the closure of the exploited gap and finds the adjacent ones.
Customer or insurer requirement
Enterprise customers and cyber insurance underwriters increasingly require recent pen-test evidence as part of due diligence.
Three security assessment types compared.
| Feature | Penetration testing | Vulnerability assessment | Red team |
|---|---|---|---|
Scope | Defined, scoped | Broad | Open, adversarial |
Methodology | Manual + tooling | Automated | Real-attacker emulation |
Exploitation attempts | Yes, scoped | No | Yes, full chain |
Duration | 1-3 weeks | 1-3 days | 4-12 weeks |
False-positive rate | Low (verified) | High | Very low |
Output | Verified findings | CVE list | Attack narrative |
Relative cost | Mid | Lower | Highest |
Best for | Annual baseline, pre-launch | Continuous hygiene | Mature program stress-test |
From scoping call to remediation re-test, five stages.
- 1
Scoping and rules of engagement
2-5 days
Define scope: which targets, which exclusions, timing windows, the communication plan, and written rules of engagement covering what is in and out of bounds. Output: a signed scope and ROE document plus an authorization letter.
- 2
Reconnaissance and discovery
2-3 days
Passive and active reconnaissance against in-scope targets. Asset mapping, technology fingerprinting, vulnerability surface enumeration. Output: a target intelligence dossier.
- 3
Exploitation and post-exploitation
5-10 days
Active exploitation of identified vulnerabilities within the rules of engagement. Privilege escalation, lateral movement, sensitive-data identification, with no real persistence implants left behind. Daily status updates to your security contact.
- 4
Reporting and debrief
3-5 days
A written report with executive and technical sections, a debrief presentation, and remediation-support hours to help your team work through the fixes.
- 5
Remediation re-test
Within 60 days
Re-test of remediated findings within 60 days, then a final report with updated status per finding, the version you hand to auditors, customers, and insurers.
What buyers ask before scoping a pen test.
Services that pair with penetration testing.
Vulnerability assessment
Broader, automated vulnerability discovery, often run continuously alongside annual pen testing.
Microsoft Sentinel SOC
The detection capability that offensive testing validates and sharpens.
API security assessment
Focused authorization testing for the API estate behind your applications.
Book a scoping call and get a written scope within a week.
A 60-minute scoping call to identify which tests fit your need, agree the rules of engagement, and produce a written scope. Test execution starts within 2 weeks of scope sign-off.
Related Services
Explore more solutions that work great with this service
Vulnerability Assessment
Vulnerability assessment for US businesses across external attack
Learn moreAPI Security Assessment
API security assessment for US organizations against the published
Learn moreCyber Incident Response
Cyber incident response for US businesses. 24/7 on-call IR engineers
Learn moreRansomware Protection
Layered ransomware protection for US businesses covering prevention
Learn moreMicrosoft Sentinel
Cloud-native SIEM and threat intelligence
Learn more