External network testing
We attack your internet-facing systems the way a remote adversary would — exposed services, VPNs, email and web infrastructure, and anything else reachable from outside your walls.
Penetration testing
Automated scans flag theoretical issues. A penetration test proves what an attacker could really do with them — chaining weaknesses together to reach your data, your systems, and your money. Gryphon runs focused, manual-led penetration tests for Minneapolis and Twin Cities organizations, then hands you a clear plan to fix what matters.
Why it matters
Most organizations already run vulnerability scans, and scans are useful — but they produce long lists of "potential" issues with no sense of which ones actually put the business at risk. A penetration test answers the question leadership actually cares about: if someone tried to break in today, would they get to anything that matters?
Our testers work the way real attackers do. They don't stop at a flagged vulnerability; they exploit it, escalate, and pivot — turning a minor misconfiguration and a reused password into a path to your file server or your finance system. Then they show you exactly how they did it, so the fix is obvious and the priority is clear.
What it covers
We size each engagement to your environment and your reason for testing — not a one-size package. Common scopes include:
We attack your internet-facing systems the way a remote adversary would — exposed services, VPNs, email and web infrastructure, and anything else reachable from outside your walls.
From an assumed-breach foothold, we test how far an attacker moves once inside: privilege escalation, lateral movement, credential theft, and the path to your most sensitive data.
Hands-on testing of your applications and portals for authentication flaws, access-control gaps, injection, and business-logic issues that scanners miss.
Assessment of your wireless networks and segmentation — rogue access points, weak authentication, and guest-to-corporate crossover.
Controlled phishing and pretext testing to measure how your people and your defenses respond to the tactics that cause most real breaches.
Configuration and identity review of your cloud and Microsoft 365 tenant — the misconfigurations and over-permissioned accounts attackers now target first.
How it works
No surprises, no black box. You know what we are testing, when, and what to do with the results.
We define targets, timing, off-limits systems, and a direct line of communication before any testing begins.
We map your real attack surface — the systems, services, and accounts an attacker would find and target.
We safely validate findings, chain weaknesses together, and show how far an attacker could actually get.
You get an executive summary plus a technical report with severity, evidence, and reproduction steps — then a live walkthrough with your team.
We help prioritize and fix what matters, then retest to confirm the gaps are closed.
What you get
Every engagement is built to drive decisions and fixes, with proof behind every finding.
Common reasons to test
Many Minnesota organizations come to us because a requirement forces the question — CMMC and NIST SP 800-171, a SOC 2 or PCI audit, a HIPAA obligation, a cyber-insurance application, or a customer's vendor-security review. Others simply want an honest, outside answer before an attacker provides one. Either way, a penetration test turns "we think we're secure" into evidence — and a plan.
Because Gryphon also delivers cybersecurity services, managed IT, and vCISO guidance, we don't stop at the report. We can help you close the findings and keep them closed.
FAQ
A vulnerability scan is automated and produces a list of potential issues. A penetration test is led by a person who validates those issues, chains them together, and demonstrates what an attacker could actually reach — so you spend remediation effort on real, exploitable risk instead of theoretical noise.
Most small and mid-sized engagements run one to two weeks from kickoff to readout, depending on scope — the number of external hosts, internal network size, and how many web applications are in play. Scoping is quick; we size the effort to your environment before you commit.
Testing is planned around your business. We agree rules of engagement up front — targets, timing, off-limits systems, and a communication path — and we stop and call you immediately if we find anything that puts production or safety at risk.
Annually is the common baseline, and many compliance frameworks and cyber-insurance policies expect it. You should also test after a major change: a new application, a network redesign, a merger or acquisition, or a move to the cloud.
An executive summary your leadership can act on, a technical report with each finding rated by severity and backed by evidence and reproduction steps, prioritized remediation guidance, and a live readout with your team. We can also retest to confirm the fixes actually closed the gaps.
Yes. Because Gryphon also delivers managed IT, cybersecurity, and vCISO services, we can help remediate findings — not just hand you a report and walk away. If you have an internal team, we work alongside them.
Next step
Talk with an advisor about your current environment, risk, support model, and business priorities.