External Infrastructure & Cloud Security Assessment
Independent assessment of your external-facing network and cloud configuration. Up to 20 external IPs/hosts, one cloud environment (AWS/Azure/GCP) configuration review, IAM misconfigurations, perimeter services. Signed Attestation Letter included.
Quick Answer
Independent security assessment of your external-facing infrastructure and one cloud environment. Scope: up to 20 external IPs/hosts, AWS/Azure/GCP configuration review, IAM misconfigurations, perimeter services (mail, DNS, VPN). Combines automated discovery with manual validation of high-severity findings, delivered as an executive summary plus detailed technical report with CVSS v3.1 severity scoring and a prioritised remediation plan. One free retest of critical/high findings within 30 days. This is a network/cloud-perimeter assessment, not a web-application penetration test — for testing a web app or API itself, see our four Penetration Testing tiers.
Why You Need This
Web application penetration testing (our four tiers, from €539) covers your application code and API surface — it does not cover the external network perimeter or your cloud provider's configuration. Misconfigured cloud IAM roles, exposed management ports, weak perimeter services, and unpatched external hosts are a distinct and common source of real breaches, and most compliance frameworks that require "regular security testing" expect this surface to be tested too, not just the application layer.
This is the right fit when you need evidence of external network/cloud testing for GDPR Article 32, ISO 27001 Annex A.8.8/A.8.20, or NIS2 Article 21, when your last external network assessment is more than 12 months old, or when a customer's vendor security questionnaire asks specifically about infrastructure/cloud testing rather than application testing.
What this is not: it does not cover internal network testing (assumed-breach, Active Directory attack paths) or web-application exploitation — those require a different scope and are quoted individually on request.
Who Requires This From You
- GDPR Article 32 — Regular testing of the effectiveness of technical measures
- ISO/IEC 27001:2022 Annex A.8.8 — Management of technical vulnerabilities
- ISO/IEC 27001:2022 Annex A.8.20 — Network security
- NIS2 Article 21 — Cybersecurity risk-management measures
What You Get
Assessment scope
- Up to 20 external IPs/hosts
- One cloud environment configuration review (AWS, Azure, or GCP)
- IAM misconfiguration review
- Perimeter services (mail, DNS, VPN)
Deliverables
- Executive summary for leadership (risk overview, business impact)
- Technical report with evidence, CVSS v3.1 severity scoring
- Prioritised remediation roadmap with effort estimates
- Signed Attestation Letter
- One free retest of critical and high findings within 30 days
What Happens If You Don't
Our Process
Pricing & Delivery
€699 fixed price — up to 20 external IPs/hosts, one cloud environment. Additional hosts or a second cloud environment quoted on request. Internal network / Active Directory assessment is a separate scope, quoted individually.
Frequently Asked Questions
Is this a penetration test?
No — this is a Security Assessment, the same honesty distinction we make with our €539 Vulnerability Assessment tier. It combines automated discovery with manual validation, not full manual exploitation. If your requirement specifically names "penetration test" for this scope, contact us to scope a manual engagement.
Does this cover my web application too?
No. This assessment covers your external network perimeter and cloud configuration only. For the application/API itself, choose one of our four Penetration Testing tiers (from €539).
What cloud providers are covered?
AWS, Google Cloud Platform (GCP), and Microsoft Azure. One environment is included in the €699 price; a second is quoted on request.
Do you also test internal networks / Active Directory?
Not as part of this fixed-price assessment — internal/assumed-breach testing is a different scope with different tooling. Contact us to discuss it individually.
Is the retest really included?
Yes — one retest of critical and high-severity findings within 30 days, at no extra cost.
