Overview
Ransomware groups rarely need zero-days. They get in through an unpatched VPN appliance, an exposed remote desktop service or a phished laptop — and then move laterally through flat networks and over-privileged accounts until they reach domain admin and your backups.
Our external tests map and attack everything you expose to the internet. Our internal tests start from an assumed-breach position — a standard user on a corporate device — and show the path an attacker would take to your most critical systems.
For organisations with offices, warehouses or plants, we also assess wireless networks and VoIP systems, which are frequently overlooked entry points.
What's included
Our approach
- DiscoveryAsset discovery and service enumeration across agreed IP ranges and domains.
- Vulnerability analysisCombining scanning with manual validation to remove false positives.
- Exploitation & escalationSafe exploitation and privilege escalation toward agreed objectives.
- Lateral movementDemonstrating realistic paths to crown-jewel systems and data.
- Report & retestAttack narrative, prioritised fixes and verification of remediation.
What you receive
- External exposure map
- Internal attack path narrative
- Segmentation test results (PCI DSS)
- Active Directory hardening recommendations
- Retest report and attestation letter
Standards & frameworks
- PTES
- NIST SP 800-115
- PCI DSS 11.4
- MITRE ATT&CK
- CIS Controls
Frequently asked questions
Can internal testing be done remotely?
Yes. We provide a pre-configured virtual machine or small device that connects securely back to our testers, avoiding travel costs.
How often should network tests be performed?
At least annually and after significant infrastructure change. PCI DSS requires internal and external testing at least every 12 months and after significant changes.
Will you take down our network?
No. We avoid disruptive techniques unless explicitly agreed and coordinate testing windows for fragile systems.