Not Every Security Check Needs a Full Penetration Test

perimeter hero blog graphic

What can someone on the outside already see when they look at us

Vulnerability disclosure keeps setting records. NIST has recorded a 263% increase in CVE submissions between 2020 and 2025, and the opening months of 2026 already ran nearly a third ahead of the same period the year before (thanks to Mythos etc). September’s Patch Tuesday alone added close to a thousand new Microsoft CVEs, with Adobe closing another 172 on top, several of them under active exploitation. Every security team feels that curve in its backlog.

The volume is not what decides outcomes, though. Incident response data tells a more useful story: the ten most exploited CVEs of the past twelve months all had patches available, and none were novel zero-days. They were old, known, fixable issues, and they got through because the assets running them were never inside a vulnerability management tool in the first place. Verizon’s 2026 Data Breach Investigations Report backs that up from another angle, the median time to fix a known-exploited flaw has stretched to 43 days, and barely a quarter of vulnerabilities ever get patched at all.

Most conversations about external security start in the same place regardless: someone asks for a penetration test. It is the term everyone knows, so it becomes the default request, even when what the business actually wants is a simpler answer to a simpler question, what can someone on the outside already see when they look at us. That gap, between the volume everyone is drowning in and the narrow, current answer most people actually need, is what led us to build Perimeter.

What Perimeter actually checks

Perimeter is a one-off external vulnerability scan of your public IPs, ranges, and web hosts. It checks open ports and services, matches every fingerprinted version against known CVEs and CISA’s exploited-in-the-wild catalogue, reviews TLS and certificate state, runs an OWASP-style pass against your web applications, and checks for exposed admin interfaces and default credentials. Every automated finding is then reviewed by an analyst, ranked by real exploitability rather than raw scanner score, with false positives removed by hand. It costs €450 per target, takes three days, and needs nothing installed on your side.

The saving is not only in price. A general vulnerability management rollout has to cover everything, every internal system, every endpoint, every piece of infrastructure someone might eventually ask about. Perimeter does the opposite. It stays laser-focused on the one category of asset an outside attacker actually reaches first, your public IPs and web hosts, and answers that one question properly rather than a hundred questions shallowly.

The lighter option, not a replacement

Think of Perimeter as pen-test light, the faster, lighter-touch sibling to a full manual engagement, not a replacement for one. A full penetration test can reasonably run for days or weeks, because it needs that time to chain findings together, pivot between hosts, and attempt privilege escalation. That depth is the point of a manual test, and it is a different purpose entirely from what Perimeter is built to answer. Perimeter does not do any of that. It goes no further than the proof needed to confirm a finding is real. It sees only what an unauthenticated attacker on the public internet can see, so it will not catch flaws in authenticated application logic or in code it cannot reach.

Where a compliance mandate specifically calls for a manual test, that is still the right engagement, and our pen testing team still runs it. Perimeter is where you start when you want a fast, current answer, or when you are not yet ready for the deeper, manual-led work a full test involves. It sits alongside that work as the entry point, not the end point.

Where this fits under NIS2, DORA, and ISO 27001

That question comes up constantly under NIS2, DORA, and ISO 27001, all of which expect organisations to understand their external exposure, without always requiring a full manual test to prove it. Perimeter gives compliance and IT teams evidence they can hand to an auditor or a board on its own terms, and it works equally well as a standalone health check, a pre-renewal review, or a regular point of comparison between full penetration tests.

Find out what the internet already knows

If you want a fast, lighter-touch first look at what the internet can already see when it looks at your organisation, a Perimeter scan takes three days and costs a flat €450 per target. Request a scan, and when you are ready for the deeper, manual-led work, our penetration testing team, led by Terry, is the natural next step.