Network penetration testing
Two questions, two engagements. What can someone reach from the internet — and what could they reach afterwards, from inside, once one employee clicks the wrong link.
Perimeter testing
Everything reachable from the internet, tested from the position of an attacker with no prior access and no credentials.
- Attack surface discovery beyond the asset list you gave us
- Service enumeration, version analysis and known exposure review
- VPN, remote access and edge device configuration
- Credential attacks against exposed authentication surfaces
- Shadow IT and forgotten infrastructure still resolving publicly
Typical effort: 3–6 days
Assumed-breach testing
We start where a successful phish ends: a standard user account on a standard workstation. Then we find out how far that goes.
- Network protocol attacks — LLMNR, NBT-NS, mDNS poisoning and relay
- Credential harvesting from shares, scripts and memory
- Lateral movement and privilege escalation to administrator
- Segmentation validation between security zones
- Access to the data that actually matters, demonstrated
Typical effort: 5–10 days
Which do you need? If you have never tested, start external — it is the surface attackers reach without any help. If you have tested the perimeter before, or you handle sensitive data internally, the internal test almost always finds more. Ransomware operators do not stop at the perimeter, and neither should your assurance.
Proving your network boundaries hold
PCI-DSS requires segmentation testing at least annually for in-scope environments. The same exercise is worth doing whether or not a standard requires it.
Boundary verification
We attempt to reach the protected zone from every other zone, using every protocol permitted, and document exactly what gets through.
Scope reduction evidence
Where segmentation holds, the report evidences it — which is what keeps systems out of your compliance scope and your audit cost down.
Failure paths documented
Where it does not hold, you get the specific rule, route or trust relationship responsible, not a generic finding.
What we need from you
- IP ranges and hostnames in scope, with explicit exclusions
- Written authorisation covering every range listed
- Third-party authorisation where infrastructure is hosted or managed by someone else — we will tell you when this applies
- Network access for internal testing: a device on the network, a VPN account, or a shipped testing appliance
- A standard user account for assumed-breach engagements, at the privilege level a normal employee holds
- An escalation contact reachable throughout the testing window
Hosted and managed infrastructure
If your systems sit with a hosting provider, cloud platform or managed service provider, your contract with them may require notification or approval before testing. We will identify this during scoping, but the authorisation itself has to come from you. We do not test infrastructure without documented permission covering it.
Find out how far one compromised account goes.
Book a scoping call and get a fixed-price quote within two working days.