Infrastructure & Network Penetration Testing

External perimeter testing shows what an attacker can reach. Internal testing shows what happens next — and for most organisations, that second answer is the uncomfortable one.

Scope options
External, internal, or both
AD analysis
Included on internal tests
Delivery
Remote or onsite
Onsite coverage
West Midlands & Shropshire

External infrastructure testing

Everything reachable from the internet: firewalls, VPN concentrators, mail gateways, remote access portals, exposed management interfaces and the services you forgot were published. We enumerate your actual perimeter rather than the one in your asset register, because those two things are rarely the same.

Typical findings include unpatched edge devices, VPN portals without multi-factor authentication, management interfaces exposed to the world, expired or misconfigured TLS, and services running on non-standard ports that never made it into anybody's documentation.

Internal infrastructure testing

This is where most organisations learn something genuinely uncomfortable. We start from the position of an attacker who already has a foothold — a compromised laptop, a phished user, a contractor's device — and establish what they could reach from there.

Active Directory attack paths

Almost every organisation running Windows has an AD attack path from standard user to Domain Admin. Usually several. Kerberoasting, AS-REP roasting, unconstrained delegation, ACL misconfigurations, credentials in Group Policy Preferences, over-privileged service accounts and nested group membership nobody has audited since the domain was built.

We map these paths and, critically, tell you which single change breaks the most of them at once. Fixing everything is unrealistic; fixing the three things that collapse most of the graph is achievable.

Lateral movement and segmentation

Whether your network segmentation does what you believe it does. Can a compromised workstation reach the finance server, the backup infrastructure, the building management system, the manufacturing network? Segmentation that exists only in a Visio diagram is a common and expensive discovery.

Credential exposure

Passwords in scripts, on file shares, in scheduled tasks, in SYSVOL, reused between local admin accounts across every workstation. Weak service account passwords that fall to offline cracking in minutes.

Onsite or remote

Internal testing can be delivered remotely via a device we ship to you, or onsite. We are based in Albrighton, so onsite work across the West Midlands, Shropshire, Staffordshire and Birmingham involves no travel premium and no overnight costs — which for a two or three day internal test is a meaningful difference against a provider travelling from London.

Common questions

Should we test externally, internally, or both?

If you have never tested, external first — it is the exposure an opportunistic attacker finds without any prior access. But ransomware operators overwhelmingly get in via phishing or a compromised credential and then move internally, so internal testing reflects the more realistic scenario. Most organisations should do both, with internal at least annually.

Do you need to come to our site?

Not necessarily. We can ship a preconfigured device that connects back to us, which works well and costs less. Onsite is preferable where physical access, wireless testing or segregated networks are in scope. Being based in Shropshire, onsite work across the West Midlands is straightforward for us.

Will this affect our production systems?

Infrastructure testing is conducted carefully with agreed rules of engagement. We do not run denial-of-service testing unless explicitly scoped, and we agree in advance any fragile systems to exclude — legacy manufacturing equipment and medical devices being the usual candidates. We stay contactable throughout.

What about our OT or manufacturing network?

Operational technology needs a different approach and considerably more caution; conventional scanning can disrupt industrial control systems. We will discuss this specifically during scoping and typically recommend passive assessment and architecture review at the IT/OT boundary rather than active testing on the OT side.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.