Penetration Testing Services: Free External Test & Source Code Testing
Two tiers, stated plainly. Tier 1 is free: an engineer tests your website and public-facing systems, checks what your public records hand an attacker, and tells you which phishing and scam attempts are likely to work against your people. Tier 2 is source code testing: give us the code, we stand it up in an isolated sandbox and try to break it the way an attacker would. Both end with a prioritized fix list that is yours to keep.
The short answer
A penetration test is an authorized, simulated attack on your business: an engineer tries to get in the way a real attacker would, then documents what worked and what to fix first. NetSys offers two tiers. Tier 1, the free external penetration test, covers what an attacker sees from outside: your website and public-facing systems, exposed logins, what your public records and staff footprint reveal, and which phishing and scam approaches are likely or unlikely to work against your people. Tier 2, source code penetration testing, is for businesses that build or depend on custom software: you hand us the code under NDA, we build and run it in an isolated sandbox that never touches production, and we attack it with static review, dynamic testing of the running app and its APIs, and dependency and secret scanning. Tier 1 costs nothing. Tier 2 is quoted per codebase. Delivered remotely anywhere in the U.S. and on-site across the New York metro, New Jersey, Connecticut, Pennsylvania, Southwest Florida and Palo Alto.
Two tiers. Start with the free one.
Most businesses need to know what the internet can see. Some also ship software and need it broken before a customer or an attacker does. Pick the tier that matches, or start with Tier 1 and let the findings decide.
Free External Penetration Test
What an attacker finds from the outside — and how likely they are to phish their way in.
- Your website and every public-facing system: exposed services, logins, forgotten subdomains
- What your public records reveal: staff names, emails, leaked credentials, vendor relationships
- A likely-versus-unlikely read on phishing, invoice fraud and scam attempts against your people
- A prioritized fix list in plain English, yours to keep
- Remote anywhere in the U.S.; on-site engineer visit in our coverage areas
Source Code Penetration Test
Give us your code. We put it in a sandbox and try to break it.
- Your application and its source code, under NDA, built and run in an isolated NetSys sandbox
- Static code review plus dynamic testing of the running app and its APIs
- Dependency, secret and configuration scanning — the supply-chain paths attackers use
- Findings with severity, reproduction steps and the specific fix, then a retest
- Never touches your production systems; code is deleted when the engagement closes
Most businesses discover their security gaps from an attacker, an insurer or a customer's security questionnaire. The two NetSys tiers exist so you find them first. The free external test answers the question every business has — what does the internet see, and how easily could someone phish us — with a real engineer rather than an automated scan PDF.
The source code tier answers the question software-dependent businesses have and rarely get an honest quote for: if a motivated attacker had our code, what would they break? We find out in a sandbox, on our infrastructure, before anyone finds out in production.
Engineers Break Things. Scanners List Things.
Automated scanners produce hundred-page reports nobody reads. Our engineers demonstrate the handful of attack paths that matter in your environment — how someone would get in, what they could reach, and what stops them — then put the fixes in priority order. For source code, that means a person reading the authentication flow and chasing the business-logic flaw, not a linter counting warnings. You see the exploit reproduced, so the risk stops being theoretical.
The Two Tiers, In Detail
Tier 1: Free External Penetration Test
Everything an attacker sees from outside, tested by an engineer, free.
- Website and public-facing systems: exposed services, remote access, logins, forgotten subdomains
- Public-records reconnaissance: staff footprint, email formats, breached credentials, vendor trails
- Phishing and scam likelihood: which approaches would probably work, and which would probably fail
- On-site demonstration of Wi-Fi and physical entry paths in our coverage areas
Tier 2: Source Code Penetration Test
Give us your code. We put it in a sandbox and try to break it.
- Code received under NDA, built and run in an isolated NetSys sandbox with no path to your production
- Static review for injection, authentication and authorization flaws, and business-logic weaknesses
- Dynamic testing of the running application and its APIs, plus dependency, secret and configuration scanning
- Findings with reproduction steps and fixes, a retest after patching, and code deleted at close
The Report, Both Tiers
A prioritized fix list your leadership and your IT or developers can both act on.
- Findings ranked by real-world risk, not CVE count
- What we found, what an attacker could do with it, the specific step that closes it
- Quick wins separated from the projects that need budget and a maintenance window
- Yours to keep — no obligation to engage us for the fixes
How It Runs, and What It Isn't
Authorized, scoped, safe — and honest about scope.
- Written authorization and agreed scope before anything starts; no production data touched
- Tier 1 delivered remotely nationwide and on-site across NY, NJ, CT, PA, Southwest Florida and Palo Alto
- Tier 2 delivered from our sandbox to businesses anywhere in the U.S.
- Not a weeks-long red-team engagement or a compliance certification audit — deeper work is scoped separately
Why Businesses Choose NetSys for Penetration Testing
Fifteen minutes with a NetSys engineer, not a salesperson, and you will know where your penetration testing stands and what it would take to fix it. Call 845-203-3914 or book the call and we will come back with it in writing.
- Two honest tiers instead of one vague quote: a free external test for every business, sandboxed source code testing for those that ship software
- Engineer-led, not scanner-led — entry paths demonstrated and exploits reproduced, not listed
- The phishing-likelihood read tells you where your people are exposed, not just your servers
- Source code never leaves the sandbox: NDA, isolated infrastructure, no production access, deleted at close
- A prioritized fix list in priority order, yours whether or not you hire us
- The findings double as evidence for cyber-insurance renewals and client security questionnaires
- Run by a firm defending business networks since 1998, with a 100% ransomware recovery record
Measured results from our case studies
Tier 1 and Tier 2, side by side
The honest version of a pricing page. What each tier tests, what you hand over, where it runs, and what you get back:
| Tier 1: Free external test | Tier 2: Source code test | |
|---|---|---|
| What we test | Your website and public-facing systems, what your public records reveal, and how likely phishing and scam attempts are to work | Your application and its source code: static review, dynamic testing of the running app and APIs, dependency and secret scanning |
| What you give us | Written authorization and your domains — no credentials, no production access | Your code under NDA (a repository grant or archive) and a short technical call to scope it |
| Where it runs | Remotely, anywhere in the U.S.; on-site engineer visit across NY, NJ, CT, PA, Southwest Florida and Palo Alto | An isolated NetSys sandbox with no path to your production systems, customers or data |
| What you get | A prioritized fix list plus the phishing-likelihood summary — yours to keep | Findings with severity, reproduction steps and the specific fix, then a retest after you patch |
| Price | Free — no obligation, no sales pressure | Quoted per codebase after the scoping call; no rate card |
| Timeline | One engineer engagement; fix list in days, not weeks | Scoped per codebase and put in writing before we start |
| Afterward | Fix it yourself, with your IT provider, or with us — month to month if it's us | Code and sandbox deleted at close; findings go to you and nobody else |
Neither tier is a weeks-long red-team engagement or a compliance certification audit. If your situation needs one of those, the scoping call is where we say so and point you to the right kind of firm.
Which tier, in thirty seconds
The rule we give callers before any scoping conversation:
- You want to know what the internet sees and how phishable your people are → Tier 1, free, start today.
- You build software, run a customer-facing application, or a client's security questionnaire asks about application testing → Tier 2, scoped per codebase.
- You are not sure → Tier 1. Its findings tell you whether the code deserves a Tier 2.
- An insurer, auditor or enterprise client wants a formal certification-grade assessment → neither; we will say so and refer you.
Where we deliver Penetration Testing
Penetration Testing in Brooklyn, NY · Penetration Testing in New York City · Penetration Testing in Westchester County · Penetration Testing in Fairfield County · Penetration Testing in Nassau County, NY · Penetration Testing in Great Neck, NY · Penetration Testing in Philadelphia — and remotely wherever your systems run. See all locations and service areas.
Penetration Testing FAQs
What is penetration testing?
Penetration testing is an authorized, controlled attack on your own business: an engineer attempts to get into your systems, accounts and applications the way a real attacker would, then documents exactly what worked. Where a vulnerability scan lists known weaknesses automatically, a penetration test proves what a person can reach — a phishable account, an exposed service, a login on a forgotten subdomain, an input in your application that leaks data. The deliverable is a prioritized fix list built from demonstrated entry points, not theoretical ones.
What is the difference between the two tiers?
Tier 1 is the free external penetration test: it covers what an attacker sees from outside — your website and public-facing systems, what your public records reveal about your people, and how likely phishing and scam attempts are to succeed. Tier 2 is source code penetration testing: you hand us your application's code under NDA, we build and run it in an isolated sandbox, and we try to break it with static review, dynamic testing and dependency scanning. Tier 1 is for every business. Tier 2 is for businesses that build or depend on custom software.
How much does a penetration test cost?
Tier 1, the external penetration test, costs $0 — genuinely free, no obligation, and you keep the report. Tier 2, source code testing, is quoted per codebase after a short technical call, because a single web application with two user roles and a platform with six services and a mobile API are not the same job. For context, published industry pricing guides commonly place a single web application test in the five-figure range and price consultant-led engagements by the day; we would rather scope your actual code than quote an average. Either way, the free tier is the honest way to learn what deeper testing your environment justifies before paying anyone.
What does the free external test include?
Four things. Your website and every public-facing system: exposed services, remote access, logins, forgotten subdomains and misconfigurations. Your public records: what staff names, email formats, leaked credentials in breach data and vendor relationships give an attacker to work with. A phishing and scam likelihood assessment: which approaches — a fake invoice, an impersonated executive, a lookalike vendor domain — are likely or unlikely to land, based on what is exposed and what defenses are in place. And the prioritized fix list. In our coverage areas an engineer can also demonstrate the entry paths on-site, including Wi-Fi and physical access.
How does source code testing work, and is our code safe with you?
You provide the code under a signed NDA — a repository grant or an archive. We build and run it in an isolated NetSys sandbox that has no connection to your production systems, customers or data. Then we attack it: static review for the vulnerability classes that matter (injection, broken authentication and authorization, insecure deserialization, business-logic flaws), dynamic testing of the running application and its APIs, and dependency, secret and configuration scanning. Findings come with severity, reproduction steps and the specific fix; we retest once you have patched. When the engagement closes, the code and sandbox are deleted, and the findings go to you and nobody else.
What languages and platforms can you test?
Any codebase we can build and run: web applications, APIs, mobile backends, integrations and internal tools across the common stacks. If your platform is unusual, the scoping call is where we say so honestly — we would rather decline a test than fake one. Bring the repository structure and the deployment model to that call and we will tell you within the hour whether it is a fit.
What is the difference between a penetration test and a vulnerability assessment?
A vulnerability assessment or scan is software listing everything it thinks might be wrong — often hundreds of items, most of them noise, none of them proven. A penetration test is an engineer proving what an attacker could do in your specific environment: which path works, how far it goes, what it reaches. Scans produce inventory. Tests produce evidence. If a provider hands you a scanner export and calls it a penetration test, it is not one — and the same applies to a code test that is just a static-analysis report with the vendor's logo on it.
What is in the penetration testing report?
Every finding gets three things: what we found, what an attacker could do with it, and the specific step that closes it. Findings are ranked by real-world risk rather than raw CVE score, quick wins are separated from the projects that need budget and a maintenance window, and for source code tests each finding carries reproduction steps a developer can follow. The Tier 1 report also includes the phishing-likelihood summary. It is written so leadership and whoever manages your IT or codebase can both act on it without a translator.
How long does a penetration test take?
Tier 1 is fast: a single engineer engagement, a remote assessment plus an on-site visit in coverage areas, with the fix list delivered days later rather than weeks. Tier 2 is scoped per codebase — the size of the application, the number of roles and integrations, and how quickly we can stand it up in the sandbox set the timeline, and we put it in writing before starting. Neither is a multi-week red-team exercise.
Is the free penetration test really free, and is it safe?
Yes to both. Tier 1 costs nothing and carries no obligation; you keep the findings whether or not you hire us. Everything is done with your written authorization and scoped in advance. We demonstrate entry paths without disrupting operations, damaging systems or touching production data — and source code testing never runs against production at all, only in our isolated sandbox.
How often should we run penetration testing?
At minimum after anything that changes your attack surface: an office move, a new location, a network rebuild, a Microsoft 365 migration, a new public-facing application or a major release of one you already run. Businesses under insurer, client or regulator scrutiny often settle into an annual external test, with source code testing tied to release cycles. Raise it during the engagement and we will scope what makes sense for you.
Can we use the results for cyber insurance or a client security questionnaire?
Yes — it is one of the most common reasons businesses book the free tier. The fix list shows what is in place and what is not, which is exactly what carriers and enterprise clients ask about, and a completed source code test is increasingly what software-dependent firms need to show customers. Where the honest answer to a questionnaire item is currently no, the list tells you what it takes to make it yes.
Do you do penetration testing in New York City?
Yes. Our office is at 1 Prospect Park SW in Brooklyn, so on-site Tier 1 tests across the five boroughs are routine, and we run them across Westchester County, the lower Hudson Valley, New Jersey, Connecticut and Pennsylvania, plus Southwest Florida and Palo Alto, California. Tier 2 source code testing runs in our sandbox, so it is delivered to businesses anywhere in the U.S.
Guides on this topic
- Security Assessments & Network Security Reviews
- Dark Web Monitoring — Where the Leaked Credentials Come From
- Cyber Insurance Readiness — What Carriers Ask For
- Business Email Compromise: How Small Businesses Get Hit
- Small Business Cybersecurity: Controls That Stop Attacks
- Free Cybersecurity Self-Assessment — 7 Questions
- IT & Cybersecurity in Brooklyn & New York City
Related services
Start with the free test. Escalate only if the code deserves it.
Tier 1 costs nothing and shows you what an attacker sees from outside. Tier 2 puts your source code in our sandbox and tries to break it. Either way you leave with a prioritized fix list that is yours to keep.
