Network Security
External & internal — Assessment and exploitation of your network attack surface — the internet-facing edge that anyone can reach, and the internal network an intruder reaches next. External work establishes what you are exposing; internal work establishes how far someone gets once they are inside, and whether you would notice.
Is this the right engagement?
- You have internet-facing infrastructure — VPN, mail, remote access, or exposed management interfaces
- You do not have a reliable inventory of what you expose to the internet
- You want to know what an intruder achieves after a single compromised laptop or credential
- You need an independent network test for a compliance programme or a customer requirement
Deliverables
- Attack-surface inventory of every asset we could attribute to you — often including assets you did not know about
- Attack-path narrative showing how far an intruder gets, step by step, with the evidence at each step
- Technical findings with affected hosts, severity, and remediation guidance
- Executive summary framed around business impact rather than CVE counts
- Detection-gap observations: which of our actions should have alerted, and did not
- Live technical debrief and one bounded remediation retest
Engagements in this solution
Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.
External Attack Surface Assessment
ESTIMATE ONLINEDiscovery, validation and prioritized findings across domains, public IPs and cloud-facing assets. Breadth over full exploitation — the fastest way to learn what you are exposing.
External Infrastructure Pentest
ESTIMATE ONLINEManual validation and exploitation of your external attack surface — VPN and mail gateways, virtual hosts, and exposed management interfaces.
Internal Network Penetration Test
ESTIMATE ONLINEAssumed-access testing from inside the network: directory attacks, credential abuse, lateral movement and privilege escalation toward domain or environment control.
Wireless Penetration Test
CUSTOM SCOPEAssessment of wireless authentication, segmentation and rogue-access exposure across your sites.
How the work is run
The same sequence runs underneath every engagement in this solution — specialised here for network security.
Scope & authorize
In-bounds ranges, domains, sites and excluded systems agreed in writing, with escalation contacts named before testing begins.
Discover & attribute
External discovery across domains, subdomains, public IPs and cloud-facing assets, attributing what is genuinely yours.
Test & exploit
Manual validation and exploitation of exposed services, then — for internal work — directory, credential and lateral-movement attack paths.
Escalate
Chaining toward domain or environment control, stopping at the agreed objective rather than at the first finding.
Report & brief
Attack-path narrative plus prioritized technical findings, walked through live with the teams who own the network.
Remediate & retest
One bounded retest validates fixes against every reported finding.
What to expect, and when
Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.
| Stage | Duration | What happens |
|---|---|---|
| Scope & authorize | 2–5 business days | Targets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched. |
| Test & exploit | 3–14 business days | Manual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged. |
| Report & brief | 3–5 business days | Findings report delivered, then walked through live with the engineers and the executives who own the risk. |
| Remediate & retest | Within 30 days | One bounded retest validates fixes against every reported finding. |
| Total | 3–6 weeks | From signed authorization to retest report, for a standard scope. |
What you can hold us to
Commitments that are checkable, not adjectives.
The report shows the route from foothold to objective, not a scanner's inventory of open ports.
You learn which of our actions your tooling caught, and which it missed.
If we find something critical mid-engagement, you hear about it that day — not in the final report.
Availability-impacting techniques are excluded unless separately authorized in writing.
One bounded remediation retest is part of the engagement.
Before you ask us
Do you need to be on-site for internal testing?
Usually no. Most internal engagements run from a managed device or jump host you provision. On-site work is scoped separately.
What is assumed access?
We start from the position of an intruder who already has a foothold — a compromised laptop or a standard user credential — because that is the realistic starting point.
How is this different from an attack-surface assessment?
The assessment tells you what you are exposing, broadly and quickly. The pentest exploits it to establish what an attacker achieves.