Network penetration testing that finds the way in.
Your network is the backbone of the business, and every device, service, and connection is a potential way in. SubRosa's network penetration testing exposes the internal and external weaknesses an attacker would chain together, then hands you a prioritized path to close them.
Internal & external · Infrastructure · Wireless · Cloud access
What is network penetration testing?
Network penetration testing is a controlled attack on your network infrastructure, both external (internet-facing) and internal, to find and safely exploit the weaknesses a real attacker would use: unpatched devices, weak configurations, exposed services, and paths for lateral movement. The goal is not a list of scanner output but proof of what an attacker could actually reach, and a clear plan to shut it down.
External and internal, every layer.
From your internet-facing perimeter to the inside of your network, we test everything an attacker would target.
External network testing
We attack your internet-facing perimeter the way an outside adversary would: exposed services, VPN and remote access, misconfigurations, and known-exploitable vulnerabilities.
Internal network testing
From an assumed-breach position inside the network, we test segmentation, privilege escalation, and lateral movement, showing how far an attacker gets once they are in.
Full infrastructure coverage
Routers, switches, firewalls and IDS/IPS, load balancers, VPN concentrators, DNS and DHCP, and file, mail, and database servers, all tested against real attack techniques.
Actionable reporting & retest
An executive summary, a detailed technical report with reproduction and remediation steps, a prioritized roadmap, and complimentary retesting once you have fixed the findings.
What actually happens, week by week.
A network test is a defined engagement, not an open-ended exercise. This is the shape of it, and the retest at the end is included rather than quoted separately.
- 01
Scoping and rules of engagement
We agree what is in scope, what is explicitly off limits, and the hours during which testing may run. Emergency contacts are exchanged so that if something looks like a genuine incident rather than our activity, the call takes seconds.
- 02
Reconnaissance and mapping
We build a picture of your external perimeter and, for internal testing, your network from the position an attacker would occupy after a phishing email lands. Exposed services, versions, authentication surfaces and trust relationships all get mapped before anything is touched.
- 03
Exploitation
Findings are proven rather than reported from a scanner banner. Where a weakness is exploitable we demonstrate it safely, which is the difference between a theoretical CVE and evidence that a specific host on your network can be taken.
- 04
Post-exploitation and lateral movement
The question that matters is not whether one machine falls, but how far the attacker gets afterwards. We test segmentation, credential reuse, privilege escalation and the paths toward the systems you would least like reached.
- 05
Reporting and debrief
You get a report written for two audiences: an executive summary that states business risk in plain terms, and technical detail an engineer can act on directly. We walk the team through it live, because the questions that matter rarely arrive by email.
- 06
Remediation window and retest
You fix, we retest, at no additional cost. A finding is not closed because it was reported — it is closed because a second test confirmed the fix holds.
Offensive depth, business context.
20+ years breaking in
Two decades of hands-on offensive work across every kind of network, so testing reflects how attackers actually operate rather than a checklist.
Real exploitation, not scans
We safely chain and exploit findings to prove real-world impact and validate your controls, going well beyond automated scanner output.
Prioritized by real risk
Every finding is ranked by the risk it carries and the access it grants, so your team fixes what matters first.
From report to remediation.
Your network pen test findings land in Sable, prioritized, assigned, and tracked from open to retested, so remediation becomes a managed workflow instead of a PDF that gets forgotten.
- CriticalOpenDefault creds on VPN gatewayExternal
- HighIn progressExposed RDP to the internetExternal
- HighOpenKerberoasting to domain adminInternal
- MediumRetestedSMB signing not requiredInternal
Common questions
- What is network penetration testing?
- Network penetration testing is a controlled attack on your network infrastructure, both external (internet-facing) and internal, to find and safely exploit the weaknesses a real attacker would use: unpatched devices, weak configurations, exposed services, and paths for lateral movement. The output is proof of what an attacker could actually reach, plus a prioritized plan to close it.
- What is the difference between external and internal network penetration testing?
- External network penetration testing attacks your internet-facing perimeter the way an outside adversary would: exposed services, VPN and remote access, and known-exploitable vulnerabilities. Internal network penetration testing starts from an assumed-breach position inside the network and tests segmentation, privilege escalation, and lateral movement to show how far an attacker gets once they are in. SubRosa covers both.
- How often should we run a network penetration test?
- Most organizations test at least annually and after any significant change to the network, such as new infrastructure, a migration, or a merger. Frameworks like PCI DSS require regular testing, and higher-risk environments often test more frequently. SubRosa includes complimentary retesting to verify fixes.
- How long does a network penetration test take?
- Most engagements run one to three weeks of active testing, depending on the number of live hosts, whether both external and internal testing are in scope, and how many locations are involved. Scoping is what determines this, and we would rather size it accurately than quote a week and discover on day three that the estate is twice what was described.
- Will penetration testing disrupt our network?
- The engagement is designed not to. Testing windows, out-of-scope systems and emergency contacts are agreed before anything starts, and genuinely disruptive techniques such as denial-of-service are excluded unless you explicitly ask for them. Fragile legacy systems can be flagged in scoping for a lighter-touch approach rather than being left to chance.
- What do we get at the end of a network penetration test?
- A report with an executive summary written in business terms and technical detail an engineer can act on, a live debrief with your team, and a complimentary retest once you have made the fixes. Findings can also land directly in Sable, so remediation is tracked to closure with owners and due dates rather than living in a PDF.
- Does a penetration test satisfy our compliance requirements?
- It depends on the framework. PCI DSS requires penetration testing explicitly and at defined intervals. SOC 2 and ISO 27001 do not mandate it by name, but auditors routinely expect it as evidence for the relevant controls, and most organisations pursuing either run one. Tell us which framework you are working toward during scoping and the report will be structured to serve as evidence for it.
Find the way in before they do.
Book a network penetration test and see exactly what an attacker could reach across your infrastructure, and how to stop them.