J-SAS home

External and custom penetration testing

Find Exploitable Weaknesses Before Attackers Do.

J-SAS offers a focused Standard External Penetration Test and expanded testing tailored to your environment, risks and assurance requirements. Start with a defined external test or broaden the scope where the attack surface requires it.

Choose the right starting point

A Defined Test Or A Tailored Scope.

The standard service addresses a defined external network perimeter. Expanded testing is scoped around the additional systems, applications and testing objectives that matter to your organization.

Standard package

Standard External Penetration Test

A focused external black-box network test for organizations seeking practical security validation and evidence that can support assurance activities.

  • Defined internet-facing network scope
  • Detailed findings and remediation guidance
  • One retest of critical findings
See the standard test

Custom scope

Expanded Penetration Testing

A tailored engagement when the standard external test does not cover the necessary application, system, attack surface or assurance objective.

  • Web-application or combined testing
  • Additional attack surfaces defined through scoping
  • Testing objectives aligned to the actual risk
Explore expanded testing

Standard External Penetration Test

Test The External Perimeter As An Attacker Would See It.

The Standard External Penetration Test is a black-box assessment of a defined internet-facing network environment. Testing begins without internal access or detailed knowledge of the environment and attempts to identify and validate exploitable weaknesses from the outside.

This focused engagement can provide useful evidence for SOC 2, ISO/IEC 27001, customer-assurance and risk-management activities. The appropriate testing scope still depends on your environment, risks and auditor or customer expectations.

What the standard test includes

  • Reconnaissance of the authorized external environment.
  • Enumeration of externally accessible infrastructure within scope.
  • Attempts to exploit validated weaknesses and gain access.
  • Post-exploitation and privilege-escalation testing where applicable.
  • A detailed report with findings, analysis and recommended remediation.
  • One retest of critical findings within the agreed remediation window.

The authorized domains, IP ranges, timing and testing conditions are confirmed before work begins.

Expanded Penetration Testing

Expand The Scope When The Risk Requires It.

Some environments require more than an external network test. J-SAS will define a tailored testing scope around the systems, applications, attack surfaces and assurance requirements that matter to the organization.

The examples shown here are not an exhaustive service catalogue. The final scope is established through a technical scoping conversation and documented authorization.

01

Web-application testing

Evaluate an external web application using testing informed by the OWASP Top 10 and risks specific to the application.

02

Combined testing

Bring external network and web-application testing into one coordinated engagement.

03

Additional attack surfaces

Include other relevant systems, interfaces or exposure points identified during scoping.

04

Defined testing objectives

Shape testing around a customer request, material risk, deployment or assurance objective.

From scope to remediation

A Test Should Lead To Action.

The engagement is structured to produce understandable findings and a practical path forward, not simply a list of scanner output.

01

Confirm the scope

Document the authorized assets, testing objectives, timing, contacts and operating constraints.

02

Perform the testing

Use reconnaissance, enumeration and controlled exploitation techniques appropriate to the agreed scope.

03

Explain the findings

Document the vulnerabilities, supporting analysis and recommended remediation actions.

04

Validate critical fixes

Retest critical findings from the standard engagement within the agreed remediation window.

Documented methodology

A record of the agreed scope and the assessment approach used.

Detailed findings report

Clear analysis of validated weaknesses and the conditions that make them relevant.

Remediation guidance

Recommended actions to reduce risk and address the identified weaknesses.

Understand the difference

Scanning, Penetration Testing And Risk Assessment Are Not The Same.

Each answers a different question. The right choice depends on whether you need broad detection, controlled exploitation or a wider view of risk and controls.

Broad detection

Vulnerability scanning

Uses automated tools to identify potential weaknesses across defined assets. Findings generally require validation and prioritization.

Risk and decisions

Threat and Risk Assessment

Examines the system, threats, controls, evidence and residual risk to support assurance and risk-treatment decisions.

Frequently asked questions

Answers Before You Define The Scope.

A short scoping conversation will confirm whether the standard external test is sufficient or an expanded engagement is more appropriate.

What is an external black-box penetration test?

It tests a defined internet-facing network environment from the perspective of an external attacker, without internal access or detailed prior knowledge of the environment.

Is penetration testing required for SOC 2 or ISO/IEC 27001?

Neither framework makes one universal penetration-testing scope sufficient for every organization. Testing may support risk management, control validation and audit evidence, but the appropriate scope depends on the environment, risks, controls and auditor or customer expectations.

How is penetration testing different from vulnerability scanning?

A scan identifies potential weaknesses, largely through automated tooling. A penetration test uses controlled attack techniques to validate whether weaknesses can be exploited and what impact they could have.

Can expanded testing include more than web applications?

Yes. Web-application and combined network-and-application testing are examples, not limits. Other systems, attack surfaces and testing objectives can be considered and defined during scoping.

What happens if critical findings are identified?

The report explains the finding and recommended remediation. The standard package includes one retest of critical findings completed within the agreed remediation window.

How is the final testing scope determined?

J-SAS confirms the authorized assets, environment, business objective, assurance requirement and operating constraints with you before testing begins.

Start With The Environment You Need Tested.

We will help determine whether the Standard External Penetration Test fits the need or whether the scope should be expanded.

Scope a penetration test

How could J-SAS help your company?

Ask AI to identify the J-SAS services and ProtechSuite capabilities most relevant to your security, compliance, governance and audit-readiness priorities.

Celebrating 12 years of J-SAS
CyberSecure Canada certification mark
AICPA SOC for Service Organizations logo
SOC 2 Type II badge powered by ProtechSuite with J-SAS website reference
Microsoft Partner
© 2026 J-SAS Inc. All Rights Reserved.
Compliance Made Easy: Win Trust, Reduce Risk, Grow Your Business
Privacy Overview