Internal and external network penetration testing

Penetration Testing Servicesin New Jersey and nationwide

Automated network penetration testing that attacks you the way a real intruder would, from the internet and from the inside, then shows you exactly what they could reach.

Scope your penetration test

Tell us what you need tested. We confirm targets, test windows, and written authorization before anything runs.

Internal and external
Network penetration tests
Monthly to annual
Testing programs
Delivered remotely
Across the U.S.

Reports support PCI DSS 11.4, HIPAA, SOC 2, CMMC Level 2, and cyber insurance applications.

Tell us what you need tested
We typically respond within one business day. No obligation.

    Your Name (required)

    Your Email (required)

    Subject

    Your Message

    Prefer to talk? Call (973) 777-7227

    What does On-Site Technology’s penetration testing include?

    On-Site Technology runs automated internal and external network penetration tests that exploit weaknesses the way an attacker would. Tests run monthly, quarterly, semi-annually, or annually; one-time tests can be retested within 30 days. Each engagement includes a report walkthrough and remediation recommendations, and reports support PCI DSS, HIPAA, SOC 2, and cyber insurance. Penetration testing is delivered remotely to businesses across the United States, with deepest engineering capacity in Northern NJ, the NYC metro, Pennsylvania, and South Florida.

    At a glance

    Tests
    Internal and external network
    Method
    Automated, attacker-style exploitation
    Cadence
    Monthly, quarterly, semi-annual, or annual
    Retest
    Within 30 days on one-time tests
    Included
    Report package, walkthrough, remediation recommendations
    Quoted separately
    Remediation carried out by our engineers
    Not covered
    Web applications, APIs, cloud configuration

    How a network penetration test works

    Network penetration testing is an authorized, simulated attack on your internal and external networks that shows what a real attacker could reach. Every test follows the route an intruder takes: get in, steal credentials, climb to administrator, and head for your data. It uses techniques documented in the MITRE ATT&CK framework, and because it is automated, it runs the same way every time, so this quarter’s results compare cleanly with the last.

    InternetYour networkperimeter1Reconnaissance2Discovery3Initial access4Privilege escalation5Lateral movement6Sensitive data

    Step 1

    Reconnaissance

    Public records, DNS, and exposed services show what an attacker can see from outside.

    Step 2

    Discovery

    Host discovery and service enumeration map every system the test can reach.

    Step 3

    Initial access

    Password, man-in-the-middle, and relay attacks show whether a weakness actually opens a door.

    Step 4

    Privilege escalation

    From a foothold, the test tries to become a local or domain administrator.

    Step 5

    Lateral movement

    It moves from system to system, the way ransomware operators do.

    Step 6

    Sensitive data

    It looks for the files and databases an attacker would steal or encrypt.

    Every action is time-stamped in the activity log, so you can also check what your own monitoring caught.

    Scope my test

    Internal and external network penetration testing

    Most compliance programs expect both, because they answer different questions.

    Can someone on the internet get in?

    External test: the view from the internet

    Attacks your internet-facing perimeter the way an outside adversary would.

    Maps exposed services, VPNs, mail, and remote access from public information
    Attempts to exploit what it finds
    Needs nothing installed on-site
    If someone gets in, how far can they go?

    Internal test: the view from a foothold

    Assumes an attacker is already inside, for example after a successful phish.

    Runs from a small device or virtual machine connected to your network
    Password, man-in-the-middle, and relay attacks
    Privilege escalation and lateral movement toward sensitive data

    Segmentation testing

    Confirms that a PCI DSS cardholder data environment, or any sensitive network, is actually isolated from the rest.

    Recurring testing programs

    Retest on a schedule instead of relying on a once-a-year snapshot, so new exposures surface as your network changes.

    Network penetration testing for New Jersey businesses

    On-Site Technology is headquartered in Clifton, NJ and tests networks for businesses across Northern and Southern New Jersey. External tests run remotely. Internal tests use a small device or virtual machine connected to your network, so the test itself needs no one on-site.

    These are the requirements that most often put penetration testing on a New Jersey company’s calendar. The same service is available to businesses anywhere in the U.S.

    Medical practices

    HIPAA Security Rule technical evaluation, and the questions your cyber insurer asks at renewal.

    Retail, hospitality, and anyone taking cards

    PCI DSS Requirement 11.4 internal, external, and segmentation testing.

    Financial services and insurance

    NYDFS 23 NYCRR 500.5 requires annual penetration testing from inside and outside the network for firms licensed in New York, which includes many New Jersey firms.

    Defense suppliers and light manufacturing

    Testing evidence for CMMC Level 2 readiness when you handle CUI.

    Law firms and professional services

    Proof of testing for client security questionnaires and cyber insurance applications.

    Network Penetration Test ReportYour company
    Executive summary

    Findings
    CriticalLocal administrator password reused across workstations
    HighLLMNR and NBT-NS enabled, allowing credential relay
    HighSMB signing not required on file servers
    MediumRemote access service exposed to the internet
    Activity log
    09:02Host discovery started
    09:47Credentials captured by relay attack
    10:31Domain administrator access obtained

    Illustrative example of the report format, not a client result.

    What you receive

    A report package built for executives, engineers, auditors, and cyber insurance underwriters, plus a person to walk you through it.

    Executive summary

    A plain-language risk summary for leadership: what matters most to the business and what to do about it.

    Technical findings report

    Affected systems, supporting evidence, the risk created, and step-by-step remediation guidance for each finding.

    Activity log

    Every action the test performed, time-stamped, so you can compare it with what your alerting caught.

    Report walkthrough

    An On-Site Technology engineer reviews the results with your team and answers questions.

    Remediation recommendations

    Prioritized, so the first fixes close the most risk.

    Remediation by our engineers

    Available as a separate engagement, quoted on its own and not included in the test.

    Penetration testing vs vulnerability scanning

    A scan lists what might be wrong. A penetration test shows what an attacker could actually reach. A consultant-led test goes deeper on web applications and business logic, at a higher cost.

    AttributeVulnerability scanAutomated pen testWhat On-Site Technology deliversConsultant-led pen test
    What it doesLists potential weaknessesExploits weaknesses the way an attacker wouldTesters exploit weaknesses by hand
    Proves real impact No Yes, including privilege escalation and lateral movement Yes
    Web apps and business logic Not covered Not covered; network testing only Covered when scoped
    Testing cadenceContinuous or weeklyMonthly, quarterly, semi-annual, or annualUsually annual, because of cost
    ConsistencySame checks every runSame methodology every runVaries with the tester
    Relative costLowestModerateHighest
    Remediation help None Walkthrough and prioritized recommendations; fixes available from our engineersReport delivered; fixes are typically on you

    Need web application or API testing? That calls for a consultant-led engagement, and we flag it during scoping.

    Talk through your options

    How often should you run a penetration test?

    At least once a year, and again after major changes such as a new system, a network redesign, or a merger. PCI DSS v4.0 requires internal and external testing at least every 12 months. Pick the rhythm that matches how fast your network changes.

    Monthly

    For networks that change constantly, and teams that want findings while fixes are still fresh.

    Quarterly

    A common fit for compliance programs that report every quarter.

    Semi-annual

    For stable networks that still want a mid-year check.

    Annual

    The baseline most frameworks expect, including PCI DSS.

    Just need one test? A one-time test can be retested within 30 days to confirm the fixes worked.

    Choose a testing schedule

    Compliance and cyber insurance support

    Reports give auditors, assessors, and underwriters the evidence they ask for. Your auditor or assessor decides what satisfies a specific requirement.

    FrameworkRequirementHow the report helps
    PCI DSS v4.0Requirement 11.4Internal and external penetration testing, including segmentation testing of the cardholder data environment. See PCI DSS compliance.
    HIPAA Security Rule§164.308(a)(8)Technical evaluation evidence, and input to your §164.308(a)(1)(ii)(A) risk analysis.
    CMMC 2.0 Level 2CA.L2-3.12.1Independent network testing evidence for security assessment practices. See CMMC readiness.
    NYDFS 23 NYCRR 500Section 500.5(a)(1)Annual penetration testing from both inside and outside your network boundary, for firms licensed by the New York Department of Financial Services.
    NIST SP 800-53CA-8Supports the penetration testing control, with findings your team can carry into NIST CSF 2.0 reporting.
    SOC 2 and ISO 27001CC7.1 and Annex A 8.8Evidence for vulnerability detection and technical vulnerability management under ISO/IEC 27001:2022.
    Cyber insuranceApplications and renewalsReports you can hand your broker when an application asks whether you test your network and fix what you find. See cyber insurance readiness.

    Why businesses choose On-Site Technology for penetration testing

    A testing vendor hands you a report. A managed IT and security partner tests your network, explains the results, and can fix what it finds.

    Someone walks you through it

    Every engagement includes a report walkthrough with an engineer, so findings reach the people who fund the fixes.

    Engineers who can do the fixes

    Our team can carry out remediation as a separate engagement, then retest to confirm it worked.

    Security operations under one roof

    Testing sits alongside our managed cybersecurity, 24/7 SOC monitoring, and CMMC readiness work.

    A partner since 2001

    Family-owned, headquartered in Clifton, NJ with an office in Ft. Lauderdale, FL, and testing delivered remotely across the U.S.

    Penetration testing FAQs

    The questions businesses ask before every engagement.

    What is network penetration testing?

    Network penetration testing is an authorized, simulated attack on your internal and external networks. It exploits weaknesses the way a real attacker would, then escalates privileges and moves laterally to show what someone could actually reach, so you can fix the paths that matter most.

    What is the difference between a penetration test and a vulnerability scan?

    A vulnerability scan lists potential weaknesses and stops there. A penetration test tries to exploit them, then escalates privileges and moves laterally to show what an attacker could actually reach. Most compliance frameworks, including PCI DSS, expect penetration testing rather than scanning alone.

    How often should we have a penetration test performed?

    At least annually, and again after any significant change such as a new system, a network redesign, or a merger. PCI DSS v4.0 requires internal and external testing at least once every 12 months. We offer monthly, quarterly, semi-annual, and annual testing programs.

    Do you perform both internal and external penetration testing?

    Yes. External testing attacks your perimeter from the public internet. Internal testing simulates an attacker who already has a foothold, such as after a successful phish, using a small device connected to your network. Most compliance programs expect both, because they answer different risk questions.

    Is automated penetration testing as good as a manual test?

    For network testing, automated testing runs the same attack phases every time, which makes results comparable from one test to the next and makes monthly or quarterly testing affordable. A consultant-led manual test goes deeper on web applications and business logic, at a higher cost. Many businesses run automated network testing on a regular cadence and bring in a consultant when an application needs it.

    Do you test web applications, APIs, or cloud environments?

    No. Our penetration testing covers internal and external networks. Web application, API, and cloud configuration testing are separate disciplines that call for a consultant-led engagement.

    Do you provide remediation and retesting?

    Every engagement includes prioritized remediation recommendations and a report walkthrough. Our engineers can also carry out the fixes as a separate engagement, which is quoted on its own and not included in the test. One-time tests can be retested within 30 days, and recurring programs retest on the schedule you choose.

    Can penetration testing support PCI DSS, HIPAA, NIST, CMMC, or cyber insurance requirements?

    Yes, as evidence. Reports support PCI DSS v4.0 Requirement 11.4 including segmentation testing, NYDFS 23 NYCRR 500.5, HIPAA §164.308(a)(8), NIST SP 800-53 CA-8, CMMC Level 2 practice CA.L2-3.12.1, SOC 2 CC7.1, ISO/IEC 27001:2022 Annex A 8.8, and cyber insurance applications. Your auditor or assessor decides what satisfies a specific requirement.

    Do you provide penetration testing services in New Jersey?

    Yes. On-Site Technology is headquartered in Clifton, NJ and tests networks for businesses across Northern and Southern New Jersey. External tests run remotely, and internal tests use a small device or virtual machine connected to your network, so the test itself needs no one on-site.

    Do you deliver penetration testing outside New Jersey?

    Yes. Penetration testing is delivered remotely to businesses across the United States, with deepest engineering capacity in Northern NJ, the NYC metro, Pennsylvania, and South Florida. External tests run from the public internet, and internal tests use a small device connected to your network. On-Site Technology is headquartered in Clifton, NJ with a second office in Ft. Lauderdale, FL.

    How do I choose a penetration testing company?

    Ask four things: what is in scope (internal network, external network, web applications, cloud), whether testing is automated or manual, how retesting works after you fix findings, and who helps with remediation. Also confirm the provider gets written authorization and agrees test windows before anything runs. Our guide to choosing a penetration testing provider goes deeper.

    How much does a penetration test cost?

    Pricing depends on the size of your network, whether you need internal testing, external testing, or both, and how often you want to test. For a broader look at what drives price, see our Complete Guide to Penetration Testing Cost, or request a no-obligation scoping consultation.

    Find out what an attacker could reach on your network

    Serving businesses with 10 to 500 users nationwide, with deepest engineering capacity across NJ, NY, PA, and FL.

    The next step is a short scoping call, followed by a quote and a proposed testing schedule.

    Call (973) 777-7227

    Tell us about your environment
    We typically respond within one business day. No obligation.

      Your Name (required)

      Your Email (required)

      Subject

      Your Message

      Prefer to talk? Call (973) 777-7227