Skip to main content
SurfaceShield Logo
SurfaceShield

Security assessments built around clearly defined scope

SurfaceShield provides separate external, web application, API, internal network, and Active Directory security assessment services. Every engagement is authorized, scoped, evidence-driven, and designed to provide practical remediation guidance rather than automated scanner output alone.

Starting from

External Attack Surface

PKR 40,000

Public-facing infrastructure, domains, services, TLS, DNS, and external exposure.

Starting from

Web Application & API

PKR 80,000

Manual application, API, authorization, business-logic, and server-side validation testing.

Starting from

Internal Network & AD

PKR 100,000

Internal systems, segmentation, privilege boundaries, and Active Directory where included.

Starting from

External + Internal

PKR 180,000

Combined engagement with separately defined external and internal scopes.

External Security

External Attack Surface Assessment

STARTING FROM PKR 40,000

Designed for organizations that want to understand what an attacker can discover and interact with from the public internet.

Request External Assessment
Typical ScopeExternal
✓Public Domain & Subdomain Mapping
✓External Service & Port Discovery
✓DNS Configuration Review
✓Email Security Posture (SPF, DKIM, DMARC)
✓HTTPS & TLS Configuration Review
✓Public Administrative Interface Exposure
✓Technology & Version Disclosure Review
✓External Security Header Review
✓Internet-Facing Misconfiguration Validation
✓Evidence-Backed Technical Reporting
Application Security

Web Application & API Security Assessment

STARTING FROM PKR 80,000

Manual security testing focused on application behavior, authorization boundaries, API exposure, business logic, and server-side controls.

Request Web & API Assessment
Typical ScopeWeb / API
✓Web Application Security Testing
✓API Authorization & Access-Control Testing
✓Authentication Control Review
✓Business-Logic Testing
✓Sensitive Data Exposure Validation
✓Server-Side Input Validation
✓Session & Security Configuration Review
✓Client / Server Trust Boundary Testing
✓Manual Vulnerability Validation
✓Developer Remediation Guidance
Final pricing depends on application complexity, API coverage, authentication roles, asset count, and the agreed testing depth.
Internal Security

Internal Network & Active Directory Assessment

STARTING FROM PKR 100,000

Authorized assessment of the internal environment to identify weaknesses that could enable lateral movement, privilege escalation, unauthorized access, or compromise of business systems.

Request Internal Assessment
Typical ScopeInternal
✓Internal Network Discovery
✓Windows & Linux System Review
✓Internal Service Exposure
✓Administrative Interface Review
✓Network Segmentation Assessment
✓Legacy & Insecure Protocol Review
✓Credential Exposure Assessment
✓Shared Resource Review
✓Privilege Boundary Testing
✓Attack-Path Validation
✓Active Directory Security Assessment Where Included

Internal assessments require separately approved network ranges, systems, credentials where applicable, testing windows, and Rules of Engagement.

Active Directory testing is performed only where AD is present and explicitly included in the agreed scope.

Multi-Surface Engagement

External + Internal Security Assessment

For organizations requiring assessment of both their Internet-facing attack surface and their internal environment. External and internal testing remain separately scoped, with independently defined Rules of Engagement and reporting sections.

STARTING FROM PKR 180,000 • FINAL QUOTE AFTER SCOPING
Standard Engagement Boundaries

Activities requiring separate authorization

Denial of Service Testing
Traffic flooding and intentional production disruption are excluded unless separately authorized under a dedicated test plan.
Destructive Data Modification
Production records are not deleted or altered unless explicitly required, documented, and approved in the Rules of Engagement.
Testing Unowned Systems
Third-party systems and infrastructure are excluded unless the client can provide explicit authorization.
Unapproved Social Engineering
Employee phishing, pretexting, and related social-engineering activities require a separately approved scope.
Physical Security Testing
Physical access attempts are outside standard SurfaceShield assessment scopes.

Every engagement produces actionable evidence

Depending on scope, deliverables include an executive risk summary, technical findings, evidence, reproduction guidance, remediation recommendations, developer or IT remediation guidance, and a defined post-remediation verification retest.

Findings are reported according to demonstrated impact. SurfaceShield does not inflate severity or claim impact that was not validated during the authorized assessment.

Not sure which assessment your organization needs?

Start with a scoping conversation. We will identify the systems that require assessment, define clear boundaries, and provide a proposal before testing begins.