Sophos Firewall Penetration Testing
A Sophos Firewall is only as safe as what your team leaves reachable on its WAN interface. We test device access settings, VPN permissions, rule base and Sophos Central management. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
A Sophos Firewall sits at the network edge, so its admin console, VPN service and Sophos Central relationship carry more risk than any single rule inside the policy base.
Why Sophos Firewall risk sits in configuration, not Sophos’s engine
The web admin console, CLI console and User Portal are the interfaces that matter most, and each is controlled separately from the rule base through Device Access rather than firewall rules. Sophos’s own documentation is direct here: it advises against allowing access to the web admin console, CLI console or User Portal from the WAN zone, and warns that services sharing a port can become reachable again even after you turn access off for the zone you thought controlled them. We test exactly which zones each service is turned on for, not what the design intends.
Administrator access is role-based: Sophos Firewall ships a super-administrator profile alongside narrower Security, Audit and Crypto administrator roles, and who holds each one matters as much as the profile itself. The same logic applies to VPN access. Remote-access SSL VPN through the Sophos Connect client and site-to-site IPsec connections both extend a level of trust to whoever holds the credential, so we test whether every admin and VPN account actually carries multi-factor authentication rather than a password alone.
If the firewall is registered to Sophos Central, called Sophos Fusion in current documentation, that account can reach and open the firewall’s web admin console directly once management is approved, which makes the Central account as sensitive as the device itself. Firmware and pattern updates are signed and integrity-checked before they install, but that protects the update, not the decision to leave a device running an old version, or the rule base built up underneath it. Where VPN access sits behind the same firewall, our dedicated VPN penetration testing covers the client and server sides of that connection in more depth.
SCOPE
What we pen test on a Sophos Firewall deployment
Web Admin Console and User Portal Exposure
The web admin console (HTTPS) and User Portal are the two interfaces an administrator or remote user reaches directly, and Sophos’s own guidance is not to allow either of them access from the WAN zone. We test exactly which zones each service is turned on for in Device Access, not what the design intended.
Local Service Access Beyond the Admin Interfaces
Device Access governs more than the admin console: DNS, Ping, SNMP, the wireless protection service and other local services each carry their own zone and port setting outside the rule base entirely. We test every local service against the zone it is actually turned on for, and check for a shared port that reopens a service you meant to keep closed elsewhere.
Administrator Profiles and Role Boundaries
Sophos Firewall ships default profiles built for different jobs, a super administrator with full privileges plus narrower Security, Audit and Crypto administrator roles. We test whether every administrator was actually given the narrowest profile their job needs, and whether the default admin account still carries full super-administrator rights long after other accounts were created.
Multi-Factor Authentication on Administrator Accounts
An admin account without multi-factor authentication is a single password away from full device control, whichever profile it holds. We confirm MFA is enforced for every administrator with console or User Portal access, not only the default account.
Firewall Rule Base Review
The rule base is yours, built up over however long the device has been in service, and it is where NAT exceptions, temporary allowances and rules nobody remembers the reason for tend to collect. We test for rules broader than the traffic they were written for, shadowed rules that never fire, and NAT or DNAT entries that expose an internal host further than intended.
SSL VPN and Remote Access Permissions
Remote access SSL VPN reaches your network through the Sophos Connect client and whichever groups and firewall rule you configured between the VPN zone and LAN. We test who that VPN is actually open to, whether the traffic it allows matches what those users need, and whether a full-tunnel configuration was chosen where a scoped one would do.
IPsec Site-to-Site VPN Configuration
Site-to-site IPsec connections, whether host-to-host, subnet-to-subnet or route-based, extend a level of trust to whatever sits on the other end. We test the subnets each connection actually exposes, the strength of the pre-shared key or certificate in use, and whether a compromised partner site could reach further into your network than the connection was meant to allow.
Multi-Factor Authentication on VPN Access
MFA on the VPN matters as much as MFA on the admin console, since a remote-access VPN with a stolen password is a route straight onto the internal network. We test whether MFA is actually enforced for every VPN user and group, not just offered as an option during setup.
Sophos Central Management Relationship
A Sophos Firewall registered to Sophos Central, known as Sophos Fusion in current documentation, can be reached and its web admin console opened directly from that account once management is approved. We test who holds that access, whether it is protected as tightly as direct access to the device itself, and what a compromised account would let someone do to your firewall.
Firmware and Pattern Patch State
Firmware and pattern updates are signed and integrity-checked before they install, but that only protects the update itself, not the decision to leave a device on an old version. We check the firmware and pattern version against the vendor’s current release, and which administrator profiles hold the rights to push an update.
OUR PROCESS
Sophos Firewall Penetration Testing: From Scope to Attestation
Scope and Access
We agree the device model and firmware version, which admin profiles and VPN test accounts we need, and whether the rule base, Sophos Central relationship and any site-to-site IPsec peers are in or out of scope.
Configuration and Rule Mapping
We map Device Access settings, admin profile privileges, the rule base and VPN configuration against Sophos’s own best-practice guidance before any manual testing starts.
Hands-On Testing
A CREST-certified tester manually works through device access exposure, rule base weaknesses, VPN permissions and the Sophos Central management relationship, chaining findings where one weakness leads to another.
Report and Retest
You receive a technical report with CVSS-scored findings and reproduction steps, a walkthrough call, a free retest once fixes are live, and an attestation letter for your auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Sophos Firewall pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Sophos Firewall Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Sophos Firewall For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Sophos Firewall Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Sophos Firewall?
We need read access to the web admin console for the profile being tested, plus a valid VPN account for every SSL VPN or IPsec connection in scope. If demonstrating a finding safely would need a firmware or rule change, we agree that with you in advance rather than making changes ourselves.
Does testing touch live traffic or affect production?
Testing is largely configuration review and controlled probing against the device, not a denial-of-service exercise against your live traffic. Where a check could affect production, such as a rule change or a VPN reconnect, we agree the timing and method with you first.
How long does a Sophos Firewall test take?
A single device sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff. A deployment with several devices, a wider rule base or more Sophos Central-managed sites moves into a broader scope with more testing days.
Do you test physical appliances, virtual instances and Sophos Central-managed devices the same way?
Yes. Whether Sophos Firewall runs on a physical appliance, as a virtual machine, or in the cloud, the device access, rule base and VPN checks are the same. Where the firewall is registered to Sophos Central, we also test what that management relationship exposes.
What is out of scope for a Sophos Firewall test?
We test your configuration and deployment, not Sophos’s own firmware code or its intrusion prevention and threat engines. Devices, servers and applications sitting behind the firewall are also out of scope for this test and covered separately by our wider network or application testing.
Does Sophos have a customer penetration-testing policy we need to follow?
Sophos publishes a Service Description for penetration tests it performs as its own service, which is separate from a customer testing their own Sophos Firewall deployment. We confirm Sophos’s current testing terms for your specific setup during scoping rather than assume none apply.
Do you need our rule base or configuration export, or is this black-box?
Testing is black-box against the live device by default. A grey-box option, where we review your rule base export, admin profile list and VPN configuration alongside testing, is available if you want faster or deeper coverage.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Sophos Firewall test
A Sophos Firewall is only as safe as what your team leaves reachable on its WAN interface. We test device access settings, VPN permissions, rule base and Sophos Central management. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.



