Better to Be Broken Into on Purpose
Scoped penetration testing that attempts what a real attacker would attempt — external perimeter, internal network, identity, and the people — then documents exactly how far it got.
45 min · Free · No commitment
A vulnerability scan is not a penetration test
Automated scanners produce long lists. They are useful, and they are also indiscriminate — a scanner will report four hundred findings without knowing which three of them chain together into actual access. Nobody in a small business has the hours to work a list of four hundred items.
What matters is whether someone can get in, and how far they can travel once they have. Answering that requires a person who will pick up a low-severity finding, notice it exposes a service account, and follow it through to your file server. Scanners do not reason. Attackers do.
Facet MSP scopes testing to what you actually need to know, agrees the rules of engagement in writing, tests strictly within them, and hands you a report that separates what is genuinely exploitable from what is merely present. Remediation guidance is specific, and a retest is included.
Testing scoped to the question you have
External Perimeter Testing
Everything reachable from the internet: public services, remote access, mail and web infrastructure. This is the surface an opportunistic attacker meets first, and where the highest-value findings usually turn out to live.
Internal Network Testing
Simulating what happens after one machine falls. Can someone move laterally, escalate privileges, reach your backups, or read your finance share? Assumed-breach testing answers the question that actually decides whether an incident becomes a disaster.
Microsoft 365 & Identity Testing
Conditional access gaps, legacy authentication still quietly enabled, over-permissioned accounts, and application consent grants nobody has ever reviewed. Identity is where most real attacks now happen, and it is frequently the least tested surface in the building.
Social Engineering
With your written authorization, we test whether a plausible phone call or email can obtain a credential or a payment change. Findings are always reported as process failures, never as named individuals to be disciplined.
Written Rules of Engagement
Scope, timing, escalation contacts, and explicitly out-of-bounds systems all agreed before anything begins. You always know exactly what we are permitted to do, and who to call to stop it immediately.
Prioritized, Reproducible Findings
Each finding includes the steps to reproduce it, the realistic impact, and a specific remediation. Severity reflects exploitability in your environment, not a generic score copied out of a vulnerability database.
Remediation Retest
After you fix what we found, we test the fixes. A report with no retest tells you what was wrong several months ago; a retest tells you where you actually stand today.
You find out before someone else does
- You know what is genuinely exploitable, not merely present
- Findings arrive with reproduction steps and specific fixes
- Lateral movement paths get closed before an attacker walks them
- Auditors and insurers get the report format they ask for
- Fixes are verified by retest rather than assumed
- Testing stays inside boundaries you agreed in writing
Scoped honestly, reported plainly
We tell you if you are not ready to be tested.
If you have no EDR, no enforced MFA, and unpatched servers, a penetration test will simply confirm that expensively. We will say so and point you at the cheaper fixes first.
Findings are ranked by exploitability, not scanner score.
A medium-severity finding that chains into domain access outranks a high-severity one nobody can reach. The report reflects your environment, not a database default.
Social engineering findings name processes, not people.
If someone hands over a credential, that is a process and training gap. Reporting it as an individual failure destroys trust and fixes nothing.
Penetration testing questions
How is this different from the free cyber risk assessment?
The assessment establishes a baseline from outside observation plus your answers, and it costs nothing. A penetration test is a paid, hands-on engagement where we actively attempt to gain access within an agreed scope. Most businesses should do the assessment first — it often reveals cheaper fixes that should come before testing.
Will testing break something?
Testing carries some risk, which is exactly why scope and rules of engagement are agreed in writing first, why disruptive techniques are excluded unless you explicitly authorize them, and why you hold an escalation contact who can stop the test immediately. We schedule around your business hours where it matters.
How often should we test?
Annually is the common baseline, plus after any significant change — a migration, a new public-facing application, an office move, a merger. Some client contracts and compliance frameworks dictate the interval, and where they do, that governs.
Do we need this for compliance?
It depends on the framework. SOC 2 auditors generally expect evidence of some testing program; certain contracts and CMMC levels are considerably more prescriptive. We will read the actual requirement with you rather than guessing, because scoping to the wrong standard wastes real budget.
Who does the testing?
Testing is delivered by qualified testers under a scoped engagement, with Facet MSP owning the scoping, the remediation plan, and the retest. If we are also your MSP, we say so plainly — and we will tell you when an independent tester is the right call for your auditor.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.