{"id":46807,"date":"2026-05-06T14:57:26","date_gmt":"2026-05-06T09:27:26","guid":{"rendered":"https:\/\/www.getastra.com\/blog\/?p=46807"},"modified":"2026-05-26T12:56:43","modified_gmt":"2026-05-26T07:26:43","slug":"remote","status":"publish","type":"post","link":"https:\/\/www.getastra.com\/blog\/penetration-testing\/remote\/","title":{"rendered":"Remote Penetration Testing in 2026: A CTO &amp; CISO Guide\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Your presence here, reading this, insinuates that something is nagging at you. Maybe it&#8217;s the Ivanti headline you saw last week or the fact that half your engineering team works from caf\u00e9s, co-working spaces, and home offices you&#8217;ve never set foot in. Maybe it&#8217;s the audit coming up and that one checklist item about remote access controls you&#8217;ve been putting off.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No, you&#8217;re not being paranoid. We have numbers that justify your burgeoning anxiety.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Verizon&#8217;s 2025 DBIR, exploitation of VPNs and edge devices jumped almost 8x in a single year, from 3% to 22% (vulnerability-driven breaches). In fact, IBM&#8217;s 2024 Cost of a Data Breach Report calculated that remote work breaches cost an average of <strong>$173,074 more<\/strong> per incident. This is why remote penetration testing exists\u2026to help you sleep a little better by finding the cracks before someone else does.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide walks you through what remote pentesting covers, how it differs from the annual network pentest you&#8217;re probably already doing, what attack paths it uncovers, and, most importantly, how to decide whether you need one, what to ask a vendor, and how to prepare.\u00a0So shall we?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_Remote_Pentesting_in_a_Remote_Work_Security_Context\"><\/span>What is Remote Pentesting in a Remote Work Security Context?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At its simplest, remote pentesting means hiring someone to attack your remote systems that hybrid employees use every day, so they tell you exactly how they got in and make sure no one else does.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such an &#8220;attack surface&#8221; includes your:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>VPN<\/li>\n\n\n\n<li>Single sign-on (SSO) portal<\/li>\n\n\n\n<li>Cloud accounts<\/li>\n\n\n\n<li>SaaS apps<\/li>\n\n\n\n<li>Laptops your team takes home<\/li>\n\n\n\n<li>Authentication rules that decide who gets to access what.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Traditional pentests just plug into your office network and test from inside, your LAN, so to speak. Remote pentesting, on the other hand, is a much larger and longer-hand test from where attackers actually sit today: on the internet, targeting the same login pages and VPN portals your employees use from their mattresses and breakfast tables.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But how and why does this matter? In a sentence, the way attackers break in today has fundamentally changed.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CrowdStrike&#8217;s 2025 Global Threat Report found that 79% of initial access attacks are &#8220;malware-free&#8221;, meaning attackers don&#8217;t even bother with viruses anymore. They just log in, using stolen passwords, social engineering, or session cookies pulled from a compromised laptop. Your firewall never sees them because, to the firewall, they look like your employees.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Secondly, under the hood, a good remote pentest follows the four-phase structure laid out in<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/115\/final\" target=\"_blank\" rel=\"noreferrer noopener\"> NIST SP 800-115<\/a> (the US government&#8217;s official penetration testing methodology) and maps its attack simulations to the <a href=\"https:\/\/www.getastra.com\/blog\/security-audit\/mitre-atlas\/\">MITRE ATT&amp;CK framework<\/a>. The latter is an encyclopedia of known attacker techniques, maintained by the nonprofit MITRE Corporation. Don\u2019t worry, you don&#8217;t need to memorize either; you just need to know if your testing vendor uses them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_do_Remote_Work_Environments_Expand_the_Attack_Surface\"><\/span>Why do Remote Work Environments Expand the Attack Surface?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every remote employee is effectively a tiny branch office of one. They&#8217;re on a home network you don&#8217;t control. They may be on a personal device you don&#8217;t manage. They&#8217;re connecting through infrastructure that sits on the public internet, 24\/7, waiting for anyone with a working exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3 things make this even worse.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">First, identity is the New Perimeter<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft tracks over 600 million identity attacks every single day. When your perimeter is a login page instead of a firewall, you lose visibility into traffic flow, which means you now have to monitor every login from everywhere, all the time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Second, Home Networks are a Wild Territory<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">NordLayer sourced a study that uncovered an uncomfortable reality: 68% of remote workers admitted to using unsecured public Wi-Fi for work. Moreover, research from the Insider Risk Index found that 1 in 2 home-network IoT devices had critical vulnerabilities. So even a smart TV in your employee&#8217;s living room is a potential first link in a chain of events that ends up in a customer database breach.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Third, SaaS Sprawl has gone Nuclear.&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On average, an enterprise runs over 340 SaaS applications, and ~48% of them aren&#8217;t even managed by IT. And if you don&#8217;t even know an app exists, how can you even patch, monitor, or revoke access to it when an employee leaves?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IBM grouped those three under multi-environment breaches (on-prem, cloud, and remote work) and reported that these breaches <a href=\"https:\/\/www.ibm.com\/think\/insights\/whats-new-2024-cost-of-a-data-breach-report\" target=\"_blank\" rel=\"noreferrer noopener\">cost over $5 million on average and took 283 days to contain<\/a>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s 9 months of an attacker wandering around before anyone notices!<\/p>\n\n\n\n<style>\n.ctaSaasCheckWrap{\n  padding:35px;\n  border: 6px;\n  background-image: url('https:\/\/cdn-blog.getastra.com\/2025\/08\/0737b9ac-deepblue-bg.png');\n  background-size: cover;\n  background-repeat: no-repeat;\n  position: relative;\n  background-position: right;\n  height: 275px;\n  border-radius: 10px;\n  margin: 20px 0px;\n}\n.pentestHeadingDB{\n  color: #fff;\n  font-size: 24px;\n  font-weight: 600;\n  max-width: 450px;\n}\n.ctaSaasCheckWrapHead {\n    display: flex;\n    align-items: center;\n    grid-gap: 1rem;\n}\n.ctaOneDB {\n    display: flex;\n  align-items: center;\n  padding: 1rem 1.5rem;\n  border-radius: 12px;\n  background-color: #FCBB2F;\n  text-decoration: none;\n  grid-gap: .5rem;\n  color: #000!important;\n  font-size: 18px;\n  font-weight: 500;\n  min-height: 3.75rem;\n  max-height: 3.75rem;\n  box-shadow: 0 4px 4px #00000014, 0 0 0 1px #c08e24, inset 0 -4px #0000003d;\n}\n.ctaTwo {\n    text-decoration: none;\n    background-color: #24BC94;\n    color: #ffffff !important;\n    padding: 10px 25px;\n    border-radius: 6px;\n    font-weight: 600;\n}\n.spanBoldBlue {\n    color: #3078FE;\n    font-weight: 700;\n}\n.ctaSaasCheckWrapImg{\n  position: absolute;\n  bottom: 0px;\n  right: 10px;\n  height: 250px;\n  width: 240px;\n}\n@media(max-width: 768px){\n}\n@media(max-width: 576px){\n   .pentestHeading{\n      font-size: 28px;\n    }\n   .ctaSaasCheckWrapImg{\n     display: none;\n   }\n}\n<\/style>\n\n<div class=\"ctaSaasCheckWrap\">\n<p class=\"pentestHeadingDB\">Leverage Astra Security&#8217;s modern, agentless, multi-cloud, offensive remote pentesting capabilities today.<\/p>\n<div class=\"ctaSaasCheckWrapHead\">\n  <a class=\"ctaOneDB\" href=\"\/contact-us\">Get started at $7!<\/a>\n<\/div>\n<img decoding=\"async\" class=\"ctaSaasCheckWrapImg\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/08\/96ad3cf0-girlcta.png\" alt=\"character\" \/>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_are_the_Key_Risks_of_Remote_Employees_and_Distributed_Access\"><\/span>What are the Key Risks of Remote Employees and Distributed Access?<a href=\"https:\/\/www.getastra.com\/contact-us\"><\/a><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Below, we explain how you can remotely work risk to a non-technical board member via 4 patterns you\u2019d want in your back pocket:<\/em><\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Stolen Credentials at Industrial Scale.&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Infostealer&#8221; malware harvested over 548 million passwords and 17 billion session cookies in 2024 alone. These are small programs that sit quietly on a laptop and copy saved passwords and browser session cookies, and all it needs is just one password belonging to a remote worker with VPN access, and voila, the attacker walks right in through the front door.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Moreover, 46% of compromised systems with valid corporate credentials were personal BYOD laptops, basically devices your security team never even touched.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Amplified Insider Risk<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Insider threats have increased 58% since remote work took off, and 83% of organizations saw at least one insider incident in the past two years. Most of these aren&#8217;t malicious, but they&#8217;re just people taking shortcuts because working from home makes the &#8220;secure&#8221; way quite inconvenient.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Shadow IT Everywhere<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Around 67% of Fortune 1000 employees use unapproved SaaS apps, which also gives rise to shadow API, and as per Salt Security, over 68% of organizations were not aware they had shadow APIs. But so what?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where IBM found<a href=\"https:\/\/www.ibm.com\/think\/insights\/whats-new-2024-cost-of-a-data-breach-report\" target=\"_blank\" rel=\"noopener\"> that shadow data was involved in 35% of breaches<\/a>, which pushes up your costs by ~16%. That\u2019s what.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/07\/51bcc866-preventing-shadow-api-exposure.png\" alt=\"Preventing Shadow API Exposure\" class=\"wp-image-32641\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><a href=\"https:\/\/www.getastra.com\/blog\/api-security\/shadow-api\/\"><\/a>MFA Fatigue<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Multi-factor authentication is still your best defense, but attackers, too, have adapted. With nearly 50% of security incidents in Q1 2024 involving MFA weaknesses, and most of them involved users simply tapping &#8220;approve&#8221; on a push notification they didn&#8217;t expect, because the 47th prompt at 2 a.m. wears anyone down. This human-error element means that attackers are no longer breaking MFA, but going around it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Systems_are_Included_in_Remote_Work_Pentesting_Scope\"><\/span>What Systems are Included in Remote Work Pentesting Scope?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you scope a remote pentesting engagement, the list of systems to include is longer than most people expect:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>VPN gateways and SSL VPN appliances<\/strong>: the boxes that let remote workers tunnel into your network (Ivanti Connect Secure, Fortinet FortiGate, Cisco AnyConnect, Palo Alto GlobalProtect, SonicWall SMA)<\/li>\n\n\n\n<li><strong>Identity and SSO providers<\/strong>: Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, and Ping Identity, along with the login protocols they use (SAML, OIDC, and OAuth)<\/li>\n\n\n\n<li><strong>Remote desktop infrastructure,<\/strong> RDP gateways, Citrix Virtual Apps, VMware Horizon, Windows 365<\/li>\n\n\n\n<li><strong>Zero Trust Network Access (ZTNA) enforcement points<\/strong>: the newer alternative to VPNs that grants access to one app at a time, instead of opening the whole network<\/li>\n\n\n\n<li><strong>Cloud environments<\/strong>: AWS, Azure, and GCP account permissions, storage buckets, and network rules<\/li>\n\n\n\n<li><strong>SaaS app configurations<\/strong>: Microsoft 365, Google Workspace, Slack, Salesforce (sharing settings, admin roles, connected third-party apps)<\/li>\n\n\n\n<li><strong>Endpoint security<\/strong>: whether your EDR (&#8220;endpoint detection and response&#8221;, the modern replacement for antivirus) is actually running on every laptop<\/li>\n\n\n\n<li><strong>Email security gateways<\/strong> <strong>and phishing defenses<\/strong><\/li>\n\n\n\n<li><strong>Split tunneling rules<\/strong>: configurations that decide which traffic goes through your VPN and which goes straight to the internet<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">What you can do, as per <a href=\"http:\/\/www.pentest-standard.org\/index.php\/Main_Page\" target=\"_blank\" rel=\"noreferrer noopener\">Penetration Testing Execution Standard (PTES)<\/a> (an open framework most reputable testers follow), is formally document all of this in a &#8220;pre-engagement&#8221; document before any testing starts. It&#8217;s boring paperwork, but it saves your weekend.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Astra&#8217;s <\/em><a href=\"https:\/\/www.getastra.com\/lp\/pentest-services?extn&amp;utm_adgroup=&amp;utm_term=Astra%20Pentest&amp;utm_campaign=Bing_Search_AllGeo_Brand&amp;utm_source=bing&amp;utm_medium=cpc&amp;hsa_acc=8352936176&amp;hsa_cam=532271450&amp;hsa_grp=1360098457833019&amp;hsa_ad=&amp;hsa_src=o&amp;hsa_tgt=kwd-85007339851244&amp;hsa_kw=Astra%20Pentest&amp;hsa_mt=e&amp;hsa_net=adwords&amp;hsa_ver=3&amp;msclkid=95cab58de2f8193934e2dc517997beb5&amp;utm_content=Brand%20Exact#why\"><em>Pentest as a Service (PTaaS)<\/em><\/a><em> bakes retesting into every engagement, and our methodology blends automated scans with manual techniques, enabling you to remediate real-world vulnerabilities faster.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Attack_Paths_in_Remote_Work_Infrastructure\"><\/span>Common Attack Paths in Remote Work Infrastructure<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even when attackers freestyle, they follow well-worn playbooks. Below are 4 paths that show up most often in remote-work breaches, and the ones your pentest ought to try to probe.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Path 1: Exploit the VPN, Then Spread<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers look for unpatched VPN appliances here. They exploit it and land inside your internal network. Once inside, they can travel across any machine that uses the same remote tools your IT team uses (RDP, SMB, SSH). In case you missed it, this is the same path LockBit ransomware affiliates took when they<a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-325a\" target=\"_blank\" rel=\"noreferrer noopener\"> exploited &#8220;Citrix Bleed&#8221; (CVE-2023-4966)<\/a> to breach Boeing, ICBC, and DP World around late 2023.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Path 2: Steal credentials, Log in Through SSO<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Besides phishing, attackers can just buy credentials from an infostealer dump on a criminal forum. Using this, they sign into your SSO portal just like any other employee. CrowdStrike reports that valid account abuse drove 35% of all cloud incidents in 2025, making it the single most common cloud intrusion technique.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Path 3: Compromise the laptop, Pivot to the Cloud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once the malware sits inside a remote worker&#8217;s device, they have access to the session cookies the browser stores for every logged-in SaaS app, and can use them to impersonate the user without ever typing a password and\/or triggering any MFA prompt. Yeah, MFA isn\u2019t the last stop as you thought. MFAs couldn\u2019t protect over 84% of the SaaS incident responses they handled. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Path 4: Brute-force RDP, Deploy Ransomware<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos found that 90% of cyberattacks they responded to in 2023 involved abuse of the Remote Desktop Protocol. With over 3.5 million RDP ports exposed to the public internet, this remains the easiest path to a ransomware payday.<a href=\"https:\/\/www.getastra.com\/contact-us\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Remote_Access_Security_Testing_Methodology_step-by-step\"><\/span>Remote Access Security Testing Methodology (step-by-step)<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No one may ask you to run the tests yourself, but knowing what a good methodology looks like helps you evaluate remote pentesting vendors when you look for one. Below is a rigorous layman-styled remote pentest process divided into 4 phases.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 1: Scope and Reconnaissance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The tester sits down with you, defines exactly what&#8217;s in scope, and then goes hunting for everything about your organization that&#8217;s publicly visible. Domain names, exposed servers, employee email patterns, VPN portal URLs, etc., basically anything and everything a real attacker would find, mostly by googling for just 20 minutes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 2: Vulnerability Discovery<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The tester scans your in-scope systems for known weaknesses. They cross-reference what they find against the CISA Known Exploited Vulnerabilities (KEV) catalog, a list of the vulnerabilities actively exploited by attackers maintained by the US government. The KEV catalog added 245 new vulnerabilities in 2025 alone. If your VPN firmware appears on it and you haven&#8217;t patched, that&#8217;s the finding that goes in red.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1365\" height=\"609\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2025\/05\/1f3e71db-astra-soc-2-vulnerability-scanning-reporting.png\" alt=\"Astra Vulnerability Scanning &amp; Reporting\" class=\"wp-image-39176\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 3: Exploitation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s where a good pentester earns its fee, or rather, the red team. The tester actually tries to break in using the same techniques a real attacker would; password spraying, credential stuffing, VPN exploits, MFA bypass attempts, session hijacking, etc.. Once inside, they try to move laterally, escalate privileges, and exfiltrate (fake) data, just to show you the extent of damage an attacker could cause.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 4: Report and Retest<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This involves developing a document that lists every finding (ranked by its severity) how it was exploited, and exactly how to fix it. <\/p>\n\n\n\n<div data-wp-interactive=\"core\/file\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!state.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/cdn-blog.getastra.com\/2026\/02\/3edd5b4f-sample-pentest-report-astra-pentest.pdf\" type=\"application\/pdf\" style=\"width:100%;height:600px\" aria-label=\"Embed of Astra&apos;s Sample Report.\"><\/object><a id=\"wp-block-file--media-65db733f-0ef6-4842-849a-fd136a1a0065\" href=\"https:\/\/cdn-blog.getastra.com\/2026\/02\/3edd5b4f-sample-pentest-report-astra-pentest.pdf\" target=\"_blank\" rel=\"noopener\">Astra&#8217;s Sample Report<\/a><a href=\"https:\/\/cdn-blog.getastra.com\/2026\/02\/3edd5b4f-sample-pentest-report-astra-pentest.pdf\" class=\"wp-block-file__button wp-element-button\" aria-describedby=\"wp-block-file--media-65db733f-0ef6-4842-849a-fd136a1a0065\" download target=\"_blank\" rel=\"noopener\">Download<\/a><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A good report will always map the findings to compliance requirements, such as the PCI DSS Requirement 8 (authentication), ISO 27001 Annex A 6.7 (remote working controls), HIPAA \u00a7164.312(e) (transmission security), etc. And post repairs, the tester attacks again to verify whether the fix works or not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Testing_VPNs_Zero_Trust_access_and_Remote_Authentication_Systems\"><\/span>Testing VPNs, Zero Trust access, and Remote Authentication Systems<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Amongst edge devices, VPN appliances were the most targeted category in 2024-2025, with the numbers painting an alarming picture. So to help you understand what your pentester should be checking for, below we\u2019ve provided a quick tour of the CVEs (&#8220;Common Vulnerabilities and Exposures&#8221; &#8211; standardized IDs for security bugs) that sort of transformed this landscape.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ivanti Connect Secure <\/strong>produced a cascade of zero-day exploits that allowed unauthenticated remote code execution across 28,000+ exposed instances by chaining CVE-2024-21887 (CVSS 9.1) with CVE-2023-46805. The severity was such that it even breached CISA&#8217;s own systems. This was followed by CVE-2025-0282 and CVE-2025-22457. The latter was initially misclassified as low-risk, but then a China-linked group weaponized it with custom backdoors, highlighting its true severity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Next,<strong> <\/strong><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\"><strong>Fortinet&#8217;s FortiGate<\/strong>\u00a0suffered from a pre-authentication flaw (CVE-2023-27997, &#8220;XORtigate&#8221; (CVSS 9.2)) that<\/span> bypassed MFA entirely. Months after the patch was shipped, Bishop Fox found that 69% of the 490,000 exposed FortiGate SSL VPN interfaces were still unpatched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thinking of these as mild one-off cases? Palo Alto&#8217;s GlobalProtect was hit with a perfect 10\/10 breach that granted root access without authentication (CVE-2024-3400 (CVSS 10.0)), and ransomware groups hacked into <strong>SonicWall<\/strong>&#8216;s CVE-2024-53704 (CVSS 9.8) when barely days had passed of its POC going public.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Zscaler&#8217;s 2025 VPN Risk Report, VPN-related CVEs increased by 82.5% between 2020 and 2024, and 92% of surveyed organizations fear that VPN vulnerabilities will lead to a ransomware incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What about Zero Trust? If you&#8217;re migrating toward it, <strong>63% of organizations have at least partially adopted Zero Trust per Gartner<\/strong>; your pentest should evaluate whether your implementation actually lives up to the name.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The core idea behind <a href=\"https:\/\/www.getastra.com\/blog\/security-audit\/nist-penetration-testing\/\">NIST SP 800-207<\/a>, Zero Trust Architecture, is &#8220;never trust, always verify&#8221;: every request is checked, every session is re-evaluated, and no one gets implicit network access just because they&#8217;re already inside. In practice, many Zero Trust rollouts have gaps. That&#8217;s what the testing is for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the authentication front, your tester ought to try MFA bypass techniques, including &#8220;push fatigue&#8221; (bombarding a user until they accept) and &#8220;adversary-in-the-middle&#8221; attacks, where a fake login page sits between you and the real one and captures your session cookie in real time. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Endpoint_and_Device_Security_Testing_for_Remote_Employees\"><\/span>Endpoint and Device Security Testing for Remote Employees<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The laptop your employee uses at home is where remote work security is won or lost. Microsoft&#8217;s recent report found that over 90% of ransomware attacks that reached the encryption stage originated on unmanaged devices. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you&#8217;re evaluating endpoint coverage in your remote pentest, here are the questions to ask:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Is EDR actually running on every device?<\/strong> Not &#8220;was it installed 6 months ago&#8221;, is it running <em>right now<\/em>, reporting back, and up to date?<\/li>\n\n\n\n<li><strong>What about BYOD?<\/strong><a href=\"https:\/\/jumpcloud.com\/blog\/byod-statistics\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Over 80% of organizations permit personal devices for work<\/a>, but only 39% enforce formal Mobile Device Management (MDM). If an employee uses a personal MacBook to check corporate email, is that MacBook meeting your security baseline? How would you know?<\/li>\n\n\n\n<li><strong>Are device posture checks enforced?<\/strong> A &#8220;posture check&#8221; verifies that a device is patched, encrypted, and running EDR before letting it connect. Many organizations buy tools that do this, but never turn the enforcement on, so non-compliant devices connect anyway.<\/li>\n\n\n\n<li><strong>What happens when a device is lost or the employee leaves?<\/strong> Can you remote-wipe? Revoke tokens? Kill active sessions?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If these questions make you wince, that&#8217;s the exact feedback your remote pentest is designed to surface, that too in writing, ranked by severity, with remediation steps.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Cloud_and_SaaS_Exposure_in_Remote_Work_Environments\"><\/span>Cloud and SaaS Exposure in Remote Work Environments<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Your <a href=\"https:\/\/www.getastra.com\/blog\/cloud\/cloud-security-architecture\/\">cloud accounts<\/a> and SaaS apps are where your data actually lives now and increasingly, where breaches happen. IBM found that 45% of data breaches now occur in cloud environments, with CrowdStrike observing that cloud-conscious intrusions rose 37% year-over-year in 2025.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The single biggest cause? Misconfiguration. Either someone set permissions incorrectly, left a storage bucket public, or granted an app more access than it needed. Cloud Security Alliance ranked misconfiguration the #1 cloud security threat, with 43% of enterprises failing a cloud security audit in the past year. Failing this means you\u2019re 10x more likely to experience a breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SaaS makes things worse (SaaS breaches surged 300% year-over-year between 2023 and 2024, with time to full compromise condensing down to <strong>9 minutes<\/strong>) because of <strong>OAuth grants<\/strong>. Every time you click &#8220;Sign in with Google&#8221; or approve a third-party app to read your calendar, you&#8217;re creating an OAuth grant \u2014 a persistent permission that works even if you change your password.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An average enterprise has over 5,000 active OAuth grants floating around, with security teams aware of &lt;10% of them. A good remote pentesting vendor here has multiple duties:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Audit cloud permission policies\u00a0<\/li>\n\n\n\n<li>Check storage buckets for public exposure<\/li>\n\n\n\n<li>Enumerate every OAuth grant that connects your SaaS tenants to third parties<\/li>\n\n\n\n<li>Test for cross-account misconfigurations that trivialize lateral movement\u00a0<a href=\"https:\/\/www.getastra.com\/contact-us\"><\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Remote_Pentesting_vs_Traditional_Network_Pentesting\"><\/span>Remote Pentesting vs Traditional Network Pentesting<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before you spend a budget line on this, here&#8217;s an honest comparison because some of what you already do may overlap, but some of it definitely doesn&#8217;t.<\/p>\n\n\n\n<div id=\"tablepress-426-scroll-wrapper\" class=\"tablepress-scroll-wrapper\">\n<table id=\"tablepress-426\" class=\"tablepress tablepress-id-426 column1-color tablepress-responsive\">\n<thead>\n<tr class=\"row-1\">\n\t<th class=\"column-1\">Dimension<\/th><th class=\"column-2\">Traditional network pentest<\/th><th class=\"column-3\">Remote pentesting<\/th>\n<\/tr>\n<\/thead>\n<tbody class=\"row-striping row-hover\">\n<tr class=\"row-2\">\n\t<td class=\"column-1\">Primary target<\/td><td class=\"column-2\">Internal network, servers, network devices<\/td><td class=\"column-3\">VPNs, SSO, cloud, SaaS, endpoints<\/td>\n<\/tr>\n<tr class=\"row-3\">\n\t<td class=\"column-1\">Tester position<\/td><td class=\"column-2\">On-site or plugged into internal network<\/td><td class=\"column-3\">Over the internet, as an external attacker would be<\/td>\n<\/tr>\n<tr class=\"row-4\">\n\t<td class=\"column-1\">What defines the perimeter<\/td><td class=\"column-2\">Firewall<\/td><td class=\"column-3\">Identity (who is logging in, from where, on what device)<\/td>\n<\/tr>\n<tr class=\"row-5\">\n\t<td class=\"column-1\">Key attack vectors<\/td><td class=\"column-2\">Network pivoting, local exploits<\/td><td class=\"column-3\">Credential abuse, VPN exploits, OAuth token theft, phishing<\/td>\n<\/tr>\n<tr class=\"row-6\">\n\t<td class=\"column-1\">Endpoint scope<\/td><td class=\"column-2\">Managed corporate devices<\/td><td class=\"column-3\">Managed + BYOD + unmanaged devices<\/td>\n<\/tr>\n<tr class=\"row-7\">\n\t<td class=\"column-1\">Cloud\/SaaS coverage<\/td><td class=\"column-2\">Usually minimal<\/td><td class=\"column-3\">Central focus<\/td>\n<\/tr>\n<tr class=\"row-8\">\n\t<td class=\"column-1\">Compliance mapping<\/td><td class=\"column-2\">PCI DSS Req 11.3, SOC 2<\/td><td class=\"column-3\">SOC 2, ISO 27001 A.6.7, HIPAA \u00a7164.312, PCI DSS Req 4\/8<\/td>\n<\/tr>\n<tr class=\"row-9\">\n\t<td class=\"column-1\">Typical cadence<\/td><td class=\"column-2\">Annual<\/td><td class=\"column-3\">Continuous or quarterly<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<!-- #tablepress-426 from cache -->\n\n\n\n<h3 class=\"wp-block-heading\">In Other Words&#8230;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">Traditional pentests evaluate what happens\u00a0<em>after<\/em>\u00a0an attacker is inside, while Remote pentests evaluate how, why, when, and where an attacker can\u00a0<em>get<\/em>\u00a0inside in the first place, via the same doors your employees use every day.<\/span>\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your workforce is more than 20% remote, you almost certainly need both, and if you&#8217;ve had to patch a VPN or SSO portal this last year, you need a remote pentest ASAP!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Secondly, cadence matters too. Verizon&#8217;s 2025 DBIR found that the median time between a new CVE being published and its mass exploitation of edge devices is now less than one full day. An annual pentest leaves you exposed for up to 364 days, so it doesn\u2019t make any sense. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s where the <a href=\"https:\/\/www.getastra.com\/ptaas\">Pentest as a Service models<\/a> come in, and they\u2019re becoming increasingly popular because they provide continuous testing rather than a once-a-year snapshot, all at a reasonable price.<a href=\"https:\/\/www.getastra.com\/contact-us\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Prepare_for_a_Remote_Work_Pentest\"><\/span>How to Prepare for a Remote Work Pentest?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One piece of advice before we dive in, the prep you do here in the last 2 weeks before kickoff largely influences the value you get out of the engagement.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Write Down Every Remote Access Pathway<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">List your VPN concentrators (make, model, firmware version), your identity providers, your cloud tenants, your SaaS apps with corporate data, and your remote desktop gateways. If you can&#8217;t list them, that&#8217;s your first finding. NIST SP 800-46 Rev. 2 provides a complete taxonomy you can use as a starting point for a checklist.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Clearly Lay Down the Rules of Engagement<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Testing a production VPN concentrator is not risk-free. Make sure you agree in writing on testing windows, credential attack rate limits, a POC for when criticalities are found mid-test, and the social engineering scope.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Give your Tester Context, it\u2019ll Save you Days<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Network diagrams, identity provider configurations, conditional access policies, and cloud permission policies. The more context you provide upfront, the less time your tester spends on reconnaissance and the more they spend actually finding vulnerabilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Decide Whether to Tell Your SOC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some organizations brief their security operations team that testing is happening (reduces false panic). Others don&#8217;t, so they can evaluate detection and response capabilities at the same time. Both are valid, given you know your teams and their triggers well enough.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Know Your Compliance Controls&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The tester needs to be aware if you\u2019re certifying against SOC 2, ISO 27001, HIPAA, or PCI DSS. They\u2019ll map findings cleanly to audit controls. Trust us, this is much more useful than the generic CVSS scores when you&#8217;re in front of an auditor.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1365\" height=\"595\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2025\/09\/8107b865-ad_4nxezgt4-vjj4t0kbkhyu-uzk2d_4yd1f98uamgld2ttlbttgmwmp_u5p8cnq7prdapspezmrxatynd0pcchk0ydy3bxl-vcgbfs7e8q7_equgyrraobwq6idzo9aenq6sfzzsj0wxq.png\" alt=\"Compliance framework mapped risk and scoring\" class=\"wp-image-41199\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Vulnerabilities_Found_in_Remote_Work_Setups\"><\/span>Common Vulnerabilities Found in Remote Work Setups<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After hundreds of remote pentesting engagements across the industry, patterns in the findings begin to emerge. Seeking a head start on remediation, things you could fix <em>this week<\/em> without waiting for a pentest, below we summarize where you begin:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Outdated VPN firmware.<\/strong> Verizon found only 54% of edge device vulnerabilities get fully remediated, with a median remediation time of 32 days. If you do nothing else after reading this article, check your VPN firmware version against the CISA KEV catalog today.<\/li>\n\n\n\n<li><strong>Missing or weak MFA.<\/strong> 99.9% of compromised accounts lacked MFA, and even where MFA is turned on, many organizations haven&#8217;t moved to phishing-resistant methods like hardware keys or FIDO2\/WebAuthn (modern, cryptographic authentication that can&#8217;t be intercepted by fake login pages).<\/li>\n\n\n\n<li><strong>Excessive OAuth grants.<\/strong> Long-lived tokens granting SaaS apps read\/write access to corporate email, abandoned integrations from former employees, approvals granted three years ago and never reviewed.<\/li>\n\n\n\n<li><strong>Split tunneling leaks.<\/strong> Corporate traffic routing through unmonitored home networks because someone misconfigured a VPN rule.<\/li>\n\n\n\n<li><strong>Device posture checks are not enforced.<\/strong> The policy exists. The enforcement doesn&#8217;t.<\/li>\n\n\n\n<li><strong>Exposed RDP ports.<\/strong> Still, 3.5 million of them are on the public internet. Still being brute-forced every day.<\/li>\n\n\n\n<li><strong>Local admin privileges on remote workstations.<\/strong> Making credential harvesting and persistence far easier than it should be.<\/li>\n\n\n\n<li><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Remote_Work_Pentesting_Checklist_for_Security_Teams\"><\/span>Remote Work Pentesting Checklist for Security Teams<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Save this section. Use it while defining the scope of an engagement or evaluating a remote pentesting vendor&#8217;s proposal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">VPN and Remote Access Gateway Testing<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0Verify VPN firmware is current and not in the<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\"> CISA KEV catalog<\/a><\/li>\n\n\n\n<li>\u00a0Test for authentication bypass, command injection, and buffer overflow<\/li>\n\n\n\n<li>\u00a0Assess SSL\/TLS cipher and protocol strength<\/li>\n\n\n\n<li>\u00a0Validate split tunneling rules and DNS leak prevention<\/li>\n\n\n\n<li>\u00a0Confirm session timeout and forced re-authentication<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identity and Authentication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0Password spray and credential stuffing against SSO portals<\/li>\n\n\n\n<li>\u00a0MFA bypass testing (push fatigue, adversary-in-the-middle, token replay)<\/li>\n\n\n\n<li>\u00a0Conditional access policy validation (device, location, risk)<\/li>\n\n\n\n<li>\u00a0Account lockout and brute-force protections<\/li>\n\n\n\n<li>\u00a0Credential reuse checks against leaked password databases<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Endpoint and Device<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0EDR deployment and health verification on managed + BYOD<\/li>\n\n\n\n<li>\u00a0Device posture enforcement test (can a non-compliant device connect?)<\/li>\n\n\n\n<li>\u00a0Disk encryption, screen lock, local admin restrictions<\/li>\n\n\n\n<li>\u00a0Cached credentials and token persistence after VPN disconnect<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Cloud and SaaS<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0IAM policies audited for least privilege (AWS\/Azure\/GCP)<\/li>\n\n\n\n<li>\u00a0OAuth grants and third-party SaaS integrations are enumerated<\/li>\n\n\n\n<li>\u00a0Storage bucket permissions checked for public exposure<\/li>\n\n\n\n<li>\u00a0Security group and network segmentation rules validated<\/li>\n\n\n\n<li>\u00a0SaaS admin configurations (sharing, external collab) reviewed<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Network and Lateral Movement<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0External scan for exposed RDP, SSH, and management interfaces<\/li>\n\n\n\n<li>\u00a0Segmentation between remote access zones and sensitive systems<\/li>\n\n\n\n<li>\u00a0Simulated lateral movement from a compromised remote endpoint<\/li>\n\n\n\n<li>\u00a0Logging and alerting on anomalous remote access patterns<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Compliance and Reporting<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0Findings mapped to SOC 2 \/ ISO 27001 \/ HIPAA \/ PCI DSS controls<\/li>\n\n\n\n<li>\u00a0Audit log retention meets regulatory requirements<\/li>\n\n\n\n<li>\u00a0Remediation steps documented with severity and business impact<\/li>\n\n\n\n<li>\u00a0Retest scheduled to verify fixes<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_can_Astra_Security_Help\"><\/span>How can Astra Security Help?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Astra&#8217;s cloud-native platform enables fully remote penetration testing with no on-site visits. Certified pentesters collaborate via Slack\/MS Teams while the autonomous Attack AI engine continuously runs 15,000+ test cases, detecting vulnerabilities as code ships across distributed teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remote teams get instant visibility without scheduled audits. Autonomous scanning adapts to your release cycle with daily\/weekly\/monthly scans, and CI\/CD integrations (GitHub, GitLab, Jenkins) trigger automated security testing alongside development workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key Features:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Fully <a href=\"https:\/\/www.getastra.com\/autonomous-pentesting\">autonomous pentesting<\/a> &amp; vulnerability scanning, no on-site pentesting required<\/li>\n\n\n\n<li>Real-time collaboration with certified experts via Slack\/MS Teams<\/li>\n\n\n\n<li>CI\/CD integrations automate security testing in remote workflows<\/li>\n\n\n\n<li>Attack AI continuously runs 15,000+ test cases without manual intervention<\/li>\n\n\n\n<li>AI-assisted remediation speeds up fixes for distributed teams<\/li>\n\n\n\n<li>Multi-region cloud support (AWS, GCP, Azure) for global infrastructure<\/li>\n<\/ul>\n\n\n\n<style>\n.ctaSaasCheckWrap{\n  padding:35px;\n  border: 6px;\n  background-image: url('https:\/\/cdn-blog.getastra.com\/2025\/08\/0737b9ac-deepblue-bg.png');\n  background-size: cover;\n  background-repeat: no-repeat;\n  position: relative;\n  background-position: right;\n  height: 275px;\n  border-radius: 10px;\n  margin: 20px 0px;\n}\n.pentestHeadingDB{\n  color: #fff;\n  font-size: 24px;\n  font-weight: 600;\n  max-width: 450px;\n}\n.ctaSaasCheckWrapHead {\n    display: flex;\n    align-items: center;\n    grid-gap: 1rem;\n}\n.ctaOneDB {\n    display: flex;\n  align-items: center;\n  padding: 1rem 1.5rem;\n  border-radius: 12px;\n  background-color: #FCBB2F;\n  text-decoration: none;\n  grid-gap: .5rem;\n  color: #000!important;\n  font-size: 18px;\n  font-weight: 500;\n  min-height: 3.75rem;\n  max-height: 3.75rem;\n  box-shadow: 0 4px 4px #00000014, 0 0 0 1px #c08e24, inset 0 -4px #0000003d;\n}\n.ctaTwo {\n    text-decoration: none;\n    background-color: #24BC94;\n    color: #ffffff !important;\n    padding: 10px 25px;\n    border-radius: 6px;\n    font-weight: 600;\n}\n.spanBoldBlue {\n    color: #3078FE;\n    font-weight: 700;\n}\n.ctaSaasCheckWrapImg{\n  position: absolute;\n  bottom: 0px;\n  right: 10px;\n  height: 250px;\n  width: 240px;\n}\n@media(max-width: 768px){\n}\n@media(max-width: 576px){\n   .pentestHeading{\n      font-size: 28px;\n    }\n   .ctaSaasCheckWrapImg{\n     display: none;\n   }\n}\n<\/style>\n\n<div class=\"ctaSaasCheckWrap\">\n<p class=\"pentestHeadingDB\"> If annual feels slow and continuous feels expensive: Astra&#8217;s PTaaS is worth a look.<\/p>\n<div class=\"ctaSaasCheckWrapHead\">\n  <a class=\"ctaOneDB\" href=\"\/contact-us\">Get started at $7!<\/a>\n<\/div>\n<img decoding=\"async\" class=\"ctaSaasCheckWrapImg\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/08\/96ad3cf0-girlcta.png\" alt=\"character\" \/>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Final_Thoughts\"><\/span>Final Thoughts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Remote penetration testing isn&#8217;t a luxury or a nice-to-have anymore. It&#8217;s the test that matches the way your workforce actually works and the way attackers actually attack. VPN exploits are up 8x. Credential-driven intrusions are the new normal. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cloud and SaaS breaches are accelerating at double-digit rates year over year. And the tools most organizations rely on to catch these (perimeter firewalls and annual network pentests) weren&#8217;t built for any of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The good news: you don&#8217;t have to solve it all at once. Start by answering three questions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do you know every system your remote employees use to access corporate data?\u00a0<\/li>\n\n\n\n<li>Do you know the current patch status for each of them?\u00a0<\/li>\n\n\n\n<li>Do you know what an attacker could reach if a single employee&#8217;s laptop got compromised tomorrow?\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If any of those answers is &#8220;not really,&#8221; that&#8217;s your starting point, and a remote pentest is the fastest way to turn those unknowns into a written, actionable plan.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FAQs\"><\/span>FAQs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1778054923637\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can we do remote pentesting without disrupting production?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes. A professional remote pentest is designed to be non-disruptive. Pre-engagement planning defines safe testing windows, credential attack rate limits, and which systems are off-limits (like live payment processing). The tester simulates attacks without causing actual damage; they prove they <em>could<\/em> exfiltrate data rather than actually doing it.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1778055708572\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What&#8217;s the typical cost of a remote pentest?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>It varies by scope. A focused VPN + SSO assessment might run $8K\u2013$15K. A comprehensive remote work pentest covering VPN, cloud, SaaS, endpoints, and lateral movement typically ranges $25K\u2013$50K+. Continuous PTaaS models (monthly or quarterly) offer better ROI than annual tests.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Your presence here, reading this, insinuates that something is nagging at you. Maybe it&#8217;s the Ivanti headline you saw last week or the fact that half your engineering team works from caf\u00e9s, co-working spaces, and home offices you&#8217;ve never set foot in. Maybe it&#8217;s the audit coming up and that one checklist item about remote &#8230; <a title=\"Remote Penetration Testing in 2026: A CTO &amp; CISO Guide\u00a0\" class=\"read-more\" href=\"https:\/\/www.getastra.com\/blog\/penetration-testing\/remote\/\" aria-label=\"Read more about Remote Penetration Testing in 2026: A CTO &amp; CISO Guide\u00a0\">Read more<\/a><\/p>\n","protected":false},"author":114,"featured_media":46818,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[722],"tags":[],"class_list":["post-46807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-penetration-testing"],"_links":{"self":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/46807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/users\/114"}],"replies":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/comments?post=46807"}],"version-history":[{"count":1,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/46807\/revisions"}],"predecessor-version":[{"id":46819,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/46807\/revisions\/46819"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media\/46818"}],"wp:attachment":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media?parent=46807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/categories?post=46807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/tags?post=46807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}