Penetration Testing

We scrutinize your security systems to help you understand your biggest weaknesses and how those weaknesses could affect your business.

Our penetration testing turns buzzwords into valuable insights. Learn More

EXTERNAL PENETRATION TESTING

External network penetration testing is performed from the perspective of a remote attacker outside of the organization’s perimeter.

The goals of an external penetration test include:

  • Identify vulnerabilities and misconfigurations in public-facing systems such as web servers and login portals, focusing on unpatched or out of date software, faulty code, privilege level escalation and much more. 
  • Evaluate the effectiveness of external security controls such as routers, firewalls, and intrusion detection systems (IDS).
  • Identify internal assets that have been mistakenly exposed to remote access.

INTERNAL PENETRATION TESTING

Internal penetration testing is performed from the perspective of an attacker that already has access to the organization’s internal network infrastructure. This allows the organization to measure the potential impact of a perimeter breach or insider threat situation.

The goals of an internal penetration test include:

  • Evaluate the effectiveness of internal security controls, such as MDR/XDR and other advanced security control systems.
  • Perform segmentation testing and assess whether it is possible to exfiltrate data from the corporate environment by bypassing data loss prevention (DLP) controls.
  • Demonstrate the effects of an insider threat situation or perimeter breach.

PHYSICAL PENETRATION TESTING

Physical security testing is performed from the perspective of an attacker looking to exploit any security weaknesses of an organization. This creates an opportunity to evaluate the true security needs of the physical perimeter defense.

The goals of a physical security test include:

  • Pinpoint key security gaps (including the evaluation of security cameras, security lighting, door access systems, HVAC vulnerabilities, etc.).
  • Test security protocols used by staff (key cards, door codes, security guard procedures).
  • Real-world testing approach, including ConvergentDS professionals on site covertly.
FAQ

Penetration Testing

What type of penetration test do I need and how much does it cost?

The type of penetration test you need depends on your environment and what the MPA Best Practices or your studio client requires. For most media and entertainment vendors, an external network penetration test is the starting point — but your specific setup may require additional test types. ConvergentDS will advise on the right scope during an initial call.

The main types relevant to M&E vendors are:

External network penetration test. Tests your internet-facing systems — firewall, VPN, web portals, cloud-hosted infrastructure — from the perspective of a remote attacker. Required by MPA control PS-4.2 for vendors with data centre or cloud infrastructure. Typical cost start at $3,000 for 1 externally facing IP address.

Internal network penetration test. Simulates an attacker who has breached your perimeter or represents an insider threat, testing lateral movement, segmentation, and data access controls. Relevant for vendors handling pre-release content across internal networks. This does not have to be undertaken by an independent third party but ConvergentDS offers this as a managed service to support its customers. Typical costs start from $7,000 depending on network size and complexity.

Web application / cloud application test. Tests the security of web-based applications, SaaS platforms, and APIs — required for vendors covered by MPA application security controls. Each environment can vary and a scoping call will be needed to ensure the pricing is reflective of the work needed depending on the number of application roles, endpoints, and integrations.

For most single-site vendors with standard internet connectivity, an external network penetration test covering internet-facing and remote access infrastructure will satisfy the core MPA requirements. Larger organisations with complex internal networks or bespoke applications will typically need a combination of test types.

All ConvergentDS penetration tests are delivered by qualified professionals and produce a comprehensive report with findings, exploitation evidence, business impact assessment, and prioritised remediation guidance. Results can be used directly as evidence in your TPN assessment or studio audit.

Costs above are indicative market ranges. ConvergentDS provides fixed-price quotes based on your specific scope — contact us at info@convergentds.com for a no-obligation scoping conversation.

Where Can I Get a Penetration Test

Convergent provides network IP infrastructure and web application penetration tests for many vendors going through an assessment. We have a highly qualified test team experienced in M&E workflows. Test are conducted at competitive prices so please contact info@convergentds.com for more information. Convergent provides managed services for vulnerability scanning, which is also an MPA best practice guideline.

Still have questions?
Contact us
Consent Preferences