Network penetration testing.
The perimeter is one phishing email deep. We test what an attacker reaches from outside, and separately what they achieve once they are already inside.
At a glance
- Typical duration
- 1 to 3 weeks depending on host count
- Modes
- External, internal assumed-breach, or both
- Standards
- PTES, NIST SP 800-115, MITRE ATT&CK
- Delivery
- Remote via jump host, or on-site
- Retest
- Included
What we look for.
External testing answers what is exposed. Internal assumed-breach answers the more useful question: given one compromised laptop, how far does an attacker get, and how long does it take. Most organisations are comfortable with the first answer and unprepared for the second.
What we test.
What you receive.
Risk posture in plain language for leadership and the board, with the two or three things that actually matter.
Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.
Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.
A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.
Who needs this.
- Organisations with on-premise or hybrid infrastructure and Active Directory
- Anyone claiming network segmentation for PCI DSS scope reduction
- Companies whose last external scan was an automated one
- Regulated businesses under RBI, SEBI or sectoral cybersecurity frameworks
- Teams that have never validated whether their EDR actually alerts
Frequently asked.
What is assumed breach and why does it matter?
We start from the position an attacker reaches within hours of a successful phish: one standard user account on one workstation. It skips the part you cannot prevent and tests the part you can control, which is how far that foothold travels.
Do you need to be on site?
Usually not. Internal testing is normally delivered through a small virtual machine or jump host inside your network. On-site is available where policy requires it.
Will this set off our security tooling?
We hope so, and we record whether it did. Detection coverage is part of the finding set: an attack path that your team caught in ten minutes is a materially different risk to one that ran unnoticed for three days.
Can you validate our PCI segmentation?
Yes. Segmentation testing is a specific PCI DSS requirement and we will test and document whether the boundary holds, in a form your assessor can use.
Related services.
Your provider secures the cloud. You are responsible for what is in it. We test identity, exposure and blast radius across AWS, Azure and GCP, and we do it against your actual configuration rather than a checklist.
CMP 06Cybersecurity AuditA full-scope review of your security posture against NIST CSF, ending in a prioritised roadmap your board can read and your engineers can execute. Useful when you know something needs to change but not what to do first.
SVC 07Vulnerability AssessmentBroad coverage across a large estate, with every finding manually validated before it reaches your report. This is the lighter option, and we would rather describe it honestly than sell it as something it is not.
Ready to find out what an attacker would find?
Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.