Network and infrastructure penetration testing: see what your firewall can't
We assess the security of your internal and perimeter network using real attack techniques. We identify misconfigurations, lateral movement paths and entry points that automated scanners miss.
The problem: most breaches start on the internal network
Once an attacker gets past the perimeter —through phishing, a vulnerable VPN or a compromised supplier— they need to move across your network to reach valuable assets. On poorly segmented networks, without granular access control or with unreviewed legacy configurations, that lateral movement can take minutes. And if your Active Directory sits on the same network as your employee WiFi, the problem is even greater.
What network pentesting covers
- Network reconnaissance and active asset mapping
- Segmentation analysis and firewall policy review
- Assessment of network devices (routers, switches, VPN gateways)
- Lateral movement testing between subnets
- Exposure analysis of corporate Wi-Fi and BYOD networks
- Review of insecure protocols (Telnet, SNMPv1/v2, FTP, etc.)
- Unauthorised access testing from the guest network
- Analysis of NAT rules and inbound access from the Internet
Network audit methodology
- Scope definition: We agree on IP ranges, included segments, testing windows and rules of engagement so as not to affect operations.
- Passive and active reconnaissance: We identify assets, exposed services and network topology using controlled footprinting techniques.
- Vulnerability analysis: We combine specialised tools (Nessus, OpenVAS) with manual review to eliminate false positives.
- Controlled exploitation: We attempt to exploit the vulnerabilities found to demonstrate real impact: access to subnets, credential capture, access to resources.
- Post-exploitation and lateral movement: Once inside a segment, we assess how far an attacker can reach: pivoting, network privilege escalation, access to critical systems.
- Reporting and remediation: We deliver a report with evidence, per-finding impact and a prioritised remediation plan.
What you receive on completion
- Inventory of assets discovered on the network
- Topology map with identified attack paths
- Technical report with evidence (screenshots, logs, exploits)
- Classification of findings by severity (CVSS)
- Executive report for IT leadership and management
- Segmentation and hardening recommendations
When do you need this service?
- Before a NIS2, ISO 27001 or ENS compliance audit
- After company acquisitions or mergers with unaudited legacy networks
- When your team suspects there has been an unconfirmed intrusion
- Before opening new network segments or migrating to hybrid cloud
- As part of the annual offensive security programme
Frequently asked questions
Can network pentesting disrupt my services?
Under normal conditions, no. We agree on the scope and exclude disruptive actions. The more aggressive tests are scheduled within maintenance windows. If you operate 24/7, we define windows outside peak hours.
What is the difference between an internal and a perimeter audit?
The perimeter audit analyses what an external attacker sees from the Internet: open ports, exposed services, DMZ configuration. The internal audit simulates an attacker already inside —a malicious employee, a stolen credential— and that is where the most critical findings appear.
How often should I audit the network?
At least once a year, and whenever there are significant changes to the infrastructure: new sites, a change of provider, a cloud migration or an expansion of the corporate WiFi network.
What network size can be audited?
We audit everything from networks of 20 hosts to enterprise environments with thousands of devices. The scope and price are tailored to the real size of your infrastructure.