SOLUTION

Network Security

External & internal — Assessment and exploitation of your network attack surface — the internet-facing edge that anyone can reach, and the internal network an intruder reaches next. External work establishes what you are exposing; internal work establishes how far someone gets once they are inside, and whether you would notice.

WHO THIS IS FOR

Is this the right engagement?

  • You have internet-facing infrastructure — VPN, mail, remote access, or exposed management interfaces
  • You do not have a reliable inventory of what you expose to the internet
  • You want to know what an intruder achieves after a single compromised laptop or credential
  • You need an independent network test for a compliance programme or a customer requirement
When it is notIf you need continuous external monitoring rather than a point-in-time assessment, a quarterly attack-surface review is the better fit — and it is cheaper than a full pentest.
WHAT YOU RECEIVE

Deliverables

  • Attack-surface inventory of every asset we could attribute to you — often including assets you did not know about
  • Attack-path narrative showing how far an intruder gets, step by step, with the evidence at each step
  • Technical findings with affected hosts, severity, and remediation guidance
  • Executive summary framed around business impact rather than CVE counts
  • Detection-gap observations: which of our actions should have alerted, and did not
  • Live technical debrief and one bounded remediation retest
METHODOLOGY

How the work is run

The same sequence runs underneath every engagement in this solution — specialised here for network security.

Scope & authorize

In-bounds ranges, domains, sites and excluded systems agreed in writing, with escalation contacts named before testing begins.

Discover & attribute

External discovery across domains, subdomains, public IPs and cloud-facing assets, attributing what is genuinely yours.

Test & exploit

Manual validation and exploitation of exposed services, then — for internal work — directory, credential and lateral-movement attack paths.

Escalate

Chaining toward domain or environment control, stopping at the agreed objective rather than at the first finding.

Report & brief

Attack-path narrative plus prioritized technical findings, walked through live with the teams who own the network.

Remediate & retest

One bounded retest validates fixes against every reported finding.

TIMELINE

What to expect, and when

Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.

StageDurationWhat happens
Scope & authorize2–5 business daysTargets, objectives and rules of engagement agreed in writing. Authorization signed before anything is touched.
Test & exploit3–14 business daysManual testing mapped to real attacker tradecraft. Findings are exploited and chained, not just flagged.
Report & brief3–5 business daysFindings report delivered, then walked through live with the engineers and the executives who own the risk.
Remediate & retestWithin 30 daysOne bounded retest validates fixes against every reported finding.
Total3–6 weeksFrom signed authorization to retest report, for a standard scope.
HOW WE WORK

What you can hold us to

Commitments that are checkable, not adjectives.

Attack paths, not port lists

The report shows the route from foothold to objective, not a scanner's inventory of open ports.

Detection feedback included

You learn which of our actions your tooling caught, and which it missed.

Named escalation contacts

If we find something critical mid-engagement, you hear about it that day — not in the final report.

Non-destructive by default

Availability-impacting techniques are excluded unless separately authorized in writing.

Retest included

One bounded remediation retest is part of the engagement.

QUESTIONS

Before you ask us

Do you need to be on-site for internal testing?

Usually no. Most internal engagements run from a managed device or jump host you provision. On-site work is scoped separately.

What is assumed access?

We start from the position of an intruder who already has a foothold — a compromised laptop or a standard user credential — because that is the realistic starting point.

How is this different from an attack-surface assessment?

The assessment tells you what you are exposing, broadly and quickly. The pentest exploits it to establish what an attacker achieves.

See a price range in two minutes.

Select your scope in the estimator and get an indicative range, an outline timeline and what is included — no call required.

Choose which optional cookies BNO Security Group may use. You can update this choice at any time.

Necessary cookiesRequired for security, core features, and consent storage.
Always active
Analytics cookiesHelp us understand site traffic and improve the website.
Advertisement cookiesSupport relevant campaign measurement and advertising.