Penetration Testing

Network penetration testing that finds the way in.

Your network is the backbone of the business, and every device, service, and connection is a potential way in. SubRosa's network penetration testing exposes the internal and external weaknesses an attacker would chain together, then hands you a prioritized path to close them.

Internal & external · Infrastructure · Wireless · Cloud access

Network penetration testing, defined

What is network penetration testing?

Network penetration testing is a controlled attack on your network infrastructure, both external (internet-facing) and internal, to find and safely exploit the weaknesses a real attacker would use: unpatched devices, weak configurations, exposed services, and paths for lateral movement. The goal is not a list of scanner output but proof of what an attacker could actually reach, and a clear plan to shut it down.

What we test

External and internal, every layer.

From your internet-facing perimeter to the inside of your network, we test everything an attacker would target.

External network testing

We attack your internet-facing perimeter the way an outside adversary would: exposed services, VPN and remote access, misconfigurations, and known-exploitable vulnerabilities.

Internal network testing

From an assumed-breach position inside the network, we test segmentation, privilege escalation, and lateral movement, showing how far an attacker gets once they are in.

Full infrastructure coverage

Routers, switches, firewalls and IDS/IPS, load balancers, VPN concentrators, DNS and DHCP, and file, mail, and database servers, all tested against real attack techniques.

Actionable reporting & retest

An executive summary, a detailed technical report with reproduction and remediation steps, a prioritized roadmap, and complimentary retesting once you have fixed the findings.

How the engagement runs

What actually happens, week by week.

A network test is a defined engagement, not an open-ended exercise. This is the shape of it, and the retest at the end is included rather than quoted separately.

  1. 01

    Scoping and rules of engagement

    We agree what is in scope, what is explicitly off limits, and the hours during which testing may run. Emergency contacts are exchanged so that if something looks like a genuine incident rather than our activity, the call takes seconds.

  2. 02

    Reconnaissance and mapping

    We build a picture of your external perimeter and, for internal testing, your network from the position an attacker would occupy after a phishing email lands. Exposed services, versions, authentication surfaces and trust relationships all get mapped before anything is touched.

  3. 03

    Exploitation

    Findings are proven rather than reported from a scanner banner. Where a weakness is exploitable we demonstrate it safely, which is the difference between a theoretical CVE and evidence that a specific host on your network can be taken.

  4. 04

    Post-exploitation and lateral movement

    The question that matters is not whether one machine falls, but how far the attacker gets afterwards. We test segmentation, credential reuse, privilege escalation and the paths toward the systems you would least like reached.

  5. 05

    Reporting and debrief

    You get a report written for two audiences: an executive summary that states business risk in plain terms, and technical detail an engineer can act on directly. We walk the team through it live, because the questions that matter rarely arrive by email.

  6. 06

    Remediation window and retest

    You fix, we retest, at no additional cost. A finding is not closed because it was reported — it is closed because a second test confirmed the fix holds.

Why SubRosa

Offensive depth, business context.

20+ years breaking in

Two decades of hands-on offensive work across every kind of network, so testing reflects how attackers actually operate rather than a checklist.

Real exploitation, not scans

We safely chain and exploit findings to prove real-world impact and validate your controls, going well beyond automated scanner output.

Prioritized by real risk

Every finding is ranked by the risk it carries and the access it grants, so your team fixes what matters first.

Every finding, tracked to closed.

From report to remediation.

Your network pen test findings land in Sable, prioritized, assigned, and tracked from open to retested, so remediation becomes a managed workflow instead of a PDF that gets forgotten.

Network findings in Sable
Network findingsExternal + internal
  • Critical
    Default creds on VPN gateway
    External
    Open
  • High
    Exposed RDP to the internet
    External
    In progress
  • High
    Kerberoasting to domain admin
    Internal
    Open
  • Medium
    SMB signing not required
    Internal
    Retested
18 findings · 3 criticalPrioritized · assigned

Common questions

What is network penetration testing?
Network penetration testing is a controlled attack on your network infrastructure, both external (internet-facing) and internal, to find and safely exploit the weaknesses a real attacker would use: unpatched devices, weak configurations, exposed services, and paths for lateral movement. The output is proof of what an attacker could actually reach, plus a prioritized plan to close it.
What is the difference between external and internal network penetration testing?
External network penetration testing attacks your internet-facing perimeter the way an outside adversary would: exposed services, VPN and remote access, and known-exploitable vulnerabilities. Internal network penetration testing starts from an assumed-breach position inside the network and tests segmentation, privilege escalation, and lateral movement to show how far an attacker gets once they are in. SubRosa covers both.
How often should we run a network penetration test?
Most organizations test at least annually and after any significant change to the network, such as new infrastructure, a migration, or a merger. Frameworks like PCI DSS require regular testing, and higher-risk environments often test more frequently. SubRosa includes complimentary retesting to verify fixes.
How long does a network penetration test take?
Most engagements run one to three weeks of active testing, depending on the number of live hosts, whether both external and internal testing are in scope, and how many locations are involved. Scoping is what determines this, and we would rather size it accurately than quote a week and discover on day three that the estate is twice what was described.
Will penetration testing disrupt our network?
The engagement is designed not to. Testing windows, out-of-scope systems and emergency contacts are agreed before anything starts, and genuinely disruptive techniques such as denial-of-service are excluded unless you explicitly ask for them. Fragile legacy systems can be flagged in scoping for a lighter-touch approach rather than being left to chance.
What do we get at the end of a network penetration test?
A report with an executive summary written in business terms and technical detail an engineer can act on, a live debrief with your team, and a complimentary retest once you have made the fixes. Findings can also land directly in Sable, so remediation is tracked to closure with owners and due dates rather than living in a PDF.
Does a penetration test satisfy our compliance requirements?
It depends on the framework. PCI DSS requires penetration testing explicitly and at defined intervals. SOC 2 and ISO 27001 do not mandate it by name, but auditors routinely expect it as evidence for the relevant controls, and most organisations pursuing either run one. Tell us which framework you are working toward during scoping and the report will be structured to serve as evidence for it.

Find the way in before they do.

Book a network penetration test and see exactly what an attacker could reach across your infrastructure, and how to stop them.