By EJN Labs · 6 Jul 2026 · 8 min read
The NCSC has published fresh guidance, “Defending against China-nexus covert networks of compromised devices”, warning that state-linked attackers are quietly compromising internet-facing edge devices (VPN gateways, routers and firewalls) to build covert networks they can route their operations through. If your organisation runs any perimeter or remote-access kit exposed to the internet, you are in scope. The practical answer is simple: find and fix the weaknesses on your external attack surface before an attacker does. The fastest, most reliable way to do that is external network penetration testing of every internet-facing device and service you own.
This article narrows in on one thing. Not your internal estate, not generic threat headlines, but the external attack surface: the edge devices that sit between your network and the internet, and how external infrastructure penetration testing exposes the exact gaps these covert networks rely on.
What the NCSC warning actually says
The NCSC warning says China-nexus threat actors are building “covert networks” out of compromised internet-connected devices, often routers, firewalls and VPN appliances at the network edge. These hijacked devices are chained together to relay and disguise malicious traffic, making the real source far harder to trace.
Rather than attacking a target directly from their own infrastructure, the actors first take over large numbers of small devices owned by unrelated organisations and individuals.
Two points matter for UK businesses. First, your edge devices are valuable to an attacker even if you do not consider yourself a target, because a compromised appliance is useful purely as a stepping stone. Second, the initial compromise usually relies on well-known weaknesses: unpatched firmware, exposed management interfaces, default or weak credentials, and end-of-life hardware that no longer receives security updates. None of this is exotic. It is the ordinary hygiene of the internet-facing perimeter, and it is exactly what an external test is built to surface.
Why edge devices are the soft underbelly of your external attack surface
Edge devices are the soft underbelly because they are designed to be reachable from the internet, which is precisely what makes them attractive to attackers. Each one is a permanent, advertised foothold that an adversary can probe at leisure, around the clock, from anywhere.
The exposure is inherent to the job each device does. A VPN gateway has to accept connections from remote workers, a firewall has to present services to the outside world, and a router has to route.
The risk is compounded by how these devices are managed in practice. Firmware updates lag behind vendor advisories. Administrative panels get left exposed “temporarily” and never locked down. Legacy appliances stay in service years past their support date because replacing them is disruptive. Forgotten test systems, shadow IT and decommissioned services that were never actually switched off all widen the surface. Most organisations cannot produce an accurate, current inventory of what they expose to the internet, which means they cannot properly defend it.
Who does this affect? Any organisation with a perimeter. Small and mid-sized businesses are squarely in the firing line, because attackers harvesting devices for a covert network are not picky about brand names or sector. If your kit is reachable and vulnerable, it is a candidate, and the absence of a dedicated security team often makes smaller organisations easier to compromise.
How external network penetration testing addresses edge-device exposure
External network penetration testing addresses edge-device exposure by assessing your organisation strictly from the attacker’s vantage point, the public internet, with no internal access. CREST-certified testers map everything you expose, then attempt to exploit it the way a real adversary would, safely and with your explicit permission.
The discipline is sometimes called external infrastructure penetration testing, and the two names describe the same engagement.
A scoped external engagement typically covers:
- Attack-surface discovery: enumerating every internet-facing IP address, hostname, service and device, including the forgotten ones, so you finally have an accurate catalogue of your real exposure.
- Edge-device assessment: checking VPN gateways, firewalls and routers for missing patches, vulnerable firmware, exposed management interfaces and known exploitable weaknesses.
- Authentication and access testing: probing for default credentials, weak passwords and remote-access services that should never face the open internet.
- Validation, not just scanning: a tester confirms which findings are genuinely exploitable, so you prioritise real risk instead of drowning in automated noise.
The output is a prioritised, evidence-based picture of exactly how an attacker could gain a foothold, plus a clear remediation plan to close those gaps. That is the difference between a vulnerability scan and a penetration test: a scan lists possibilities, while a test demonstrates impact and tells you what to fix first. You can see the full methodology on our external infrastructure penetration testing service page.
How to respond now
You do not need to wait for a test to start reducing risk. Practical steps to take this week:
- Build an honest inventory. List every device and service reachable from the internet. If you cannot, that gap is itself the first finding.
- Patch the perimeter first. Prioritise firmware and security updates for VPN gateways, firewalls and routers, and apply vendor advisories promptly rather than on the next quarterly cycle.
- Close exposed management interfaces. Administrative access to edge devices should never be open to the whole internet. Restrict it to known addresses or place it behind a VPN.
- Retire end-of-life kit. Hardware that no longer receives security updates is a standing liability. Replace it or isolate it.
- Validate with an external penetration test. Confirm from the outside in that your assumptions hold and that nothing has slipped through.
Steps one to four reduce your exposure. Step five proves it, and catches the things you did not know to look for.
What it costs and how EJN Labs helps
Cost depends on scope: the number of internet-facing IP addresses and devices, the complexity of your perimeter, and how much validation and retesting you need. As a guide, external infrastructure penetration testing typically falls within these 2026 UK ranges: £3,500 to £6,500 for a focused engagement, £6,500 to £12,000 for a mid-sized estate, and £12,000 to £22,000 for a large or complex external footprint. Our day rate is £1,100 to £1,400, and every tester on your engagement is senior or principal and CREST-certified.
Because pricing is scope-dependent, the figures above are starting points, not quotes. EJN Labs scopes each engagement to your actual exposure, so you pay for the work you need and nothing you do not. You can review our published rates on the transparent pricing page, read the full approach on our external infrastructure penetration testing page, and when you are ready, request a scoped CREST pen testing quote for an exact price.
Frequently asked questions
What is external network penetration testing?
External network penetration testing is a security assessment carried out from the public internet, with no internal access, that identifies and safely exploits weaknesses in your internet-facing devices and services. It tells you how an attacker could gain a foothold from the outside, and exactly what to fix first.
Do I need external infrastructure penetration testing if I only have a few internet-facing devices?
Yes, even a single exposed VPN gateway, firewall or router is a viable target, so a small estate still needs external infrastructure penetration testing. The covert networks described by the NCSC are built by harvesting devices indiscriminately, regardless of who owns them.
A small external estate is quick to test and quick to fix, which makes this one of the highest-value security exercises a smaller organisation can run.
How much does external network penetration testing cost in the UK?
£3,500 to £6,500 is the typical 2026 UK cost for a focused external network penetration test, rising to £6,500 to £12,000 for a mid-sized estate and £12,000 to £22,000 for a large or complex external footprint, based on a day rate of £1,100 to £1,400.
The final figure depends on how many devices and services you expose, so we provide an exact price once the scope is agreed.
How is an external test different from an internal network penetration test?
An external test attacks your internet-facing perimeter as an outsider with no prior access, while an internal test starts from an assumed foothold inside the network and measures what an attacker could reach from there. The difference is the starting position: outside the perimeter versus already within it.
That internal foothold might be a compromised laptop or a malicious insider. Both assessments are valuable, but the edge-device threat highlighted in the NCSC guidance is an external-facing problem, which makes external testing the right place to start.
How often should we test our external attack surface?
At least annually, and after any significant change to your perimeter, such as deploying a new VPN appliance, opening a new service or replacing a firewall. Because internet-facing kit is exposed continuously, many organisations pair an annual test with ongoing attack-surface monitoring.
Can a penetration test confirm whether my edge devices are already compromised?
Not with certainty, because a penetration test targets exploitable weaknesses rather than active intrusions. Testers do, however, frequently surface indicators of prior compromise along the way, such as unexpected configurations or unexplained exposed services, which can reveal that an edge device may already have been breached.
If we find evidence during testing that a device may already be compromised, we flag it immediately and recommend incident response.




Leave a Reply