Request Assessment
Methodical Security Inspection

Find the gaps before the attackers do.

Methodical penetration testing and vulnerability assessments. We combine a hacker's perspective with an auditor's rigor to secure your perimeter and protect critical assets.

Ethical
Pen Testing
HA
High assurance
Gap
Vulnerability Scan
Scope
Boundary Audits
Ethical Hacker
Penetration Tester
Security Auditor
Security Auditor
Boundary Specialist
Vetted Assessment Suitability
High assurance background
Formal verification experience
U.S. Navy Submariner Veteran
Clear technical reporting
Who I Am

The path from 600 feet under the ocean to your perimeter.

I started my career in the weapons department of U.S. Navy Trident submarines. Serving on the Lafayette class USS Casimir Pulaski (SSBN 633) and the USS Ohio (SSBN 726), I helped maintain Trident C-4 strategic missiles and weapons systems. I was responsible for systems where a single failure didn't generate a ticket, it put 130 lives at risk. From treadmills to nuclear weapons and everything in between, that's where I learned what security actually means. Not as a compliance checkbox, but as an operational discipline that keeps people safe.

U.S. Navy Enlisted Submarine Warfare Insignia (Silver Dolphins)
Submarine Warfare Qualified: systems walkthroughs and board review

For the next two decades, I took that discipline into enterprise technology around Seattle: building, securing, and transforming infrastructure across industries. I know the difference between what looks good on paper and what holds up when someone actually checks the environment.

"PwnInspect is built to think like an attacker and report like an auditor. We inspect your boundaries and identify vulnerabilities before they can be exploited."
What We Offer

Methodical vulnerability inspections.

We simulate real world attacks to identify security weaknesses in network, application, and cloud boundaries.

Perimeter
External Penetration Testing

Identify vulnerabilities in your external facing systems, firewalls, and APIs. We test if attackers can breach your initial defenses.

Containment
Internal Vulnerability Audits

Simulate a breached perimeter or rogue insider to evaluate lateral movement potential, access control effectiveness, and domain security.

Execution
Red Team Simulations

Multi layered simulation attacks designed to evaluate your security operations, detection capability, and incident response under pressure.

Trust
Boundary Verification

Ensure your operational security boundaries and sensitive data flow systems conform to compliance and documented security controls scope requirements.

Our Method

The auditor minded testing approach.

We don't just hand you automated scanner logs. We run targeted manual tests and document findings in a format that directly maps to regulatory control objectives.

01
Boundary Mapping & Recon
Determine target scope & inventory

Establish the exact target boundaries. We gather OSINT, map system entry points, and catalog all active hosts and network pathways.

Scope Mapping Reconnaissance System Boundary
02
Vulnerability Analysis
Scan, analyze, and verify findings

Use automated scanners and manual verification tools to locate configuration flaws, weak passwords, and unpatched software across your infrastructure.

Vulnerability Scan Manual Verification Flaw Discovery
03
Exploitation & Pivot
Simulate real attacker operations

Attempt to gain access to systems using identified vulnerabilities. We safely test credential strength, lateral movement, and verify how far an attacker could penetrate.

04
Audit ready reporting
Practical remediation steps

Deliver a detailed report outlining the path of compromise, business risk level, and specific remediation steps mapped directly to framework control requirements.

The Report

What a penetration test report actually contains.

A penetration test report has two audiences, and a good one serves both. The executive summary is written for leadership: it describes what was tested, what was found, the overall risk level, and what needs to change, without requiring technical background to understand. The technical findings section is written for the security team and system administrators: it documents each finding with a CVE reference where applicable, the exact evidence of exploitation (screenshots, captured data, shell access confirmations), the attack chain that led to the finding, and specific remediation steps with enough detail that an engineer can implement them without further research. Reports that blur these two audiences, technical language in the executive section, vague remediation guidance in the findings, are the most common quality problem in commercial penetration testing.

CVSS (Common Vulnerability Scoring System) scores appear in most professional penetration test reports, but they require context to be useful. A CVSS 9.8 (Critical) remote code execution vulnerability on an internet facing server is a different emergency than the same score on an isolated internal system with no network path to sensitive data. Risk ratings in PwnInspect reports account for exploitability, business impact, and compensating controls, so the remediation priority list reflects actual organizational risk, not just the theoretical severity of each finding in isolation. The difference matters when the IT team has three weeks to address findings before the assessment and needs to allocate limited resources to the highest impact remediations first.

Remediation verification is the step that distinguishes a penetration test engagement from a onetime scan. After the initial report is delivered and the organization implements fixes, a verification retest confirms that each finding has been fully addressed and that the remediation hasn't introduced new vulnerabilities. PwnInspect includes a retest as part of every engagement because a fix that resolves the specific exploit technique but leaves the underlying misconfiguration in place is not a complete remediation, and the next auditor or attacker will find it the same way we did.

Modern Threat Surface

External attack surface in the remote work environment.

The shift to remote and hybrid work permanently changed the external attack surface for most organizations. Before 2020, the typical small to medium business had a well defined network perimeter: corporate headquarters, maybe one or two branch offices, a known set of public facing services. Remote work expanded that perimeter to every employee's home network and personal device, and most organizations didn't expand their security controls proportionally. The result is an external attack surface that is measurably larger, less consistently controlled, and less regularly monitored than it was five years ago.

VPN solutions deployed in 2020 to enable remote work were frequently configured under time pressure with minimal security hardening. Split tunnel VPN configurations that allow corporate traffic to route through the VPN while general internet traffic goes directly through the home router leave the VPN client's local network exposed to any attacker that has compromised a site the employee visited on that connection. VPN gateways with known vulnerabilities. Pulse Secure, Fortinet, and Citrix all had critical CVEs disclosed between 2019 and 2022 that attackers exploited heavily in the wild, remain unpatched in organizations that haven't specifically allocated engineering time to firmware updates. PwnInspect's external perimeter scan covers VPN gateway versions and confirms whether known CVEs have been addressed.

Shadow IT, systems and services deployed by employees or business units without IT department involvement, represents one of the fastest growing external attack surface components. A SaaS platform configured by a marketing team with weak password requirements and no MFA is an external facing system with access to organizational data, regardless of whether IT knows it exists. Asset discovery tools that enumerate subdomains, cloud storage buckets, and third party API integrations associated with an organization's domains routinely find assets the IT team isn't aware of, and those unknown assets are the ones that stay unpatched the longest because no one is responsible for maintaining them. PwnInspect's attack surface mapping process includes shadow IT discovery and reports findings back to the organization with full asset inventory context.

The Proof

Vetted credentials and real experience.

PwnInspect maps exploit details to compliance realities. We don't just break in; we tell you exactly what security controls were compromised, helping your team fix them efficiently.

With 20+ years of infrastructure systems experience and background supporting high assurance and regulated environments, Barry Morgan bridges the gap between offensive testing and compliance auditing. Paper certifications have no bearing on operational quality; true qualification is earned through hands on practice. We test for real security, not paper checkmarks.

High assurance background
Background supporting high assurance and regulated environments
Silver Dolphins Insignia
Qualified in submarines
Attained through cross functional systems walkthroughs and a rigorous evaluation board
FTB MT
U.S. Navy Submariner | Weapons Department
USS Casimir Pulaski (SSBN 633) & USS Ohio (SSBN 726) · Trident C-4 systems

Core Competencies

Offensive security
Penetration testing Vulnerability scanning Active exploit verification Red teaming
Verification & Auditing
Formal control frameworks enhanced security controls Scope audit GPO configuration review Remediation roadmaps
Technical Proof
Credential auditing MFA verification Lateral movement checks
The Invitation

Request a Vulnerability Inspection

Let's evaluate your perimeter, test your system boundaries, and identify security weaknesses. Get a professional, audit ready report.

Select all areas where you need assessment or auditing support: