We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    Network Penetration Testing: Infrastructure and Perimeter

    Manual testing of your perimeter, internal network, identity layer and cloud infrastructure by OSCP-certified testers, from first foothold to domain admin.

    Most serious breaches follow the same route: a foothold on the perimeter or a phished workstation, a weak identity configuration, lateral movement, and domain-wide access within days. Vulnerability scanners catch missing patches; they do not catch the Kerberos delegation misconfiguration, the shared local administrator password or the flat network that turns one compromised laptop into a company-wide incident. Our network penetration tests find that path before an attacker does, and report it in a form your engineers can act on and your auditor can file.

    What is network penetration testing?

    Network penetration testing is a hands-on assessment of your infrastructure from an attacker's perspective. From the internet we attack what you expose: VPNs, remote access, mail, web servers, cloud consoles. From inside, starting as a standard user or a compromised account, we map the network, exploit misconfigurations, escalate privileges through Active Directory or Entra ID and move laterally toward the systems that hold your data. The result is not a list of open ports. It is the path an attacker would take, with evidence, and the controls that would have stopped them.

    Key Capabilities

    Perimeter Assessment

    Everything exposed to the internet: VPNs, remote access, mail, web servers, cloud consoles and forgotten subdomains, tested as an outside attacker.

    Internal Assumed-Breach Testing

    Starting from a workstation or a compromised account, we measure how far an attacker gets and how fast.

    Active Directory and Entra ID

    Kerberoasting, delegation, ACL abuse, password reuse, legacy protocols and hybrid identity paths to domain admin.

    Segmentation and Lateral Movement

    We test whether your segmentation holds, from out-of-scope segments into the systems that matter, as PCI DSS 11.4.5 requires.

    Cloud and Hybrid Infrastructure

    IAM, network exposure and misconfiguration in AWS, Azure and Google Cloud, and the links between cloud and on-premises.

    Wireless and Remote Access

    Wi-Fi, VPN and remote-access gateways tested for the weaknesses that give an attacker an internal position.

    Who needs network penetration testing?

    Organisations with an on-premises or hybrid estate and an Active Directory or Entra ID identity layer; teams meeting PCI DSS Requirement 11.4, ISO 27001, DORA Article 24 and 25 or NIS2 evidence requirements; companies after a merger, a cloud migration or an incident; and anyone whose last infrastructure test was a scan. If a compromised laptop could become a company-wide incident, this is the test that shows how.

    How a Network Penetration Test Works

    01

    Scoping and Rules of Engagement

    We agree IP ranges, test positions, windows, exclusions, escalation contacts and the frameworks the report must serve.

    02

    Discovery and Mapping

    Network discovery, service identification and fingerprinting, so the attack surface is known before exploitation starts.

    03

    Vulnerability Analysis

    Findings from tooling are validated by hand; false positives are removed and chains are identified.

    04

    Exploitation and Privilege Escalation

    We gain access, escalate privileges and document each step with evidence.

    05

    Lateral Movement and Objectives

    From the first foothold toward the agreed objectives: domain admin, the data store, the critical application.

    06

    Report, Debrief and Retest

    Attack path narrative, findings with severity and remediation, a debrief with your team, and a retest after fixes.

    How We Work

    Manual exploitation by OSCP-certified testers, with tooling for discovery and coverage. We follow NIST SP 800-115 and PTES, agree rules of engagement before any packet is sent, escalate critical findings the same day and reproduce every finding with evidence. The report tells the story of the attack path and maps each finding to the framework you name.

    What you receive

    Signed rules of engagement and a written scope with test positions
    Attack path narrative from first foothold to objective, with evidence
    Findings with CVSS severity, root cause and prioritised remediation
    Active Directory or Entra ID hardening recommendations
    Segmentation test results where in scope (PCI DSS 11.4.5)
    Retest of remediated findings with a dated verification appendix

    Network Penetration Testing FAQ

    The questions IT and security leaders ask us most often before commissioning an infrastructure test, answered straight.

    What is a network penetration test?

    A network penetration test is a manual security assessment of your infrastructure: the systems exposed to the internet (the perimeter), the internal network, the identity layer (Active Directory or Entra ID) and the cloud or hybrid environment behind it. Our testers map the infrastructure, find and exploit vulnerabilities and misconfigurations, escalate privileges and move laterally toward the systems that matter. The answer you get: how far an attacker gets, from outside and from inside, and what stops them.

    What is the difference between a perimeter test and an internal test?

    A perimeter test looks from the internet at everything you expose publicly: VPNs, mail servers, web servers, cloud consoles, remote access. An internal test starts from a position inside the network, such as a standard workstation or a compromised account (assumed breach), and measures how far an attacker gets from there. Most organisations need both; the choice and the order are decided together during scoping. Our guide to external versus internal penetration testing explains the difference in detail.

    Do you test Active Directory and Entra ID?

    Yes, it is the core of almost every internal test. Kerberoasting, delegation misconfigurations, weak ACLs, password reuse, legacy protocols and paths to domain admin are the route ransomware groups take. For hybrid environments we include the link to Entra ID, conditional access and synchronisation, because the weakest link is often in the transition.

    How long does a network penetration test take?

    A perimeter test for a mid-sized organisation typically needs two to five testing days; an internal assumed-breach test four to ten, depending on network size, segmentation and the complexity of the identity layer. The report follows within a week of the last testing day. During scoping we put the day count in writing, including the retest.

    Will a network penetration test disrupt operations?

    Not when it is run properly. We agree rules of engagement in advance: testing windows, excluded systems, maximum scan rates, and the rule that destructive exploits are used only with explicit permission. Critical findings are escalated the same day, so you never have to wait for the report to close an open door.

    Does the test align with PCI DSS, ISO 27001, DORA and NIS2?

    Yes. PCI DSS Requirement 11.4 requires internal and external penetration testing with segmentation testing; ISO 27001 A.8.8 and DORA Articles 24 and 25 expect a tested network behind critical functions; NIS2 asks for evidence that measures work. We scope the test so the report maps each finding to the framework you name.

    How much does a network penetration test cost?

    Every test is quoted on scope; there is no fixed price list. The drivers are the number of hosts and networks, the test positions (perimeter, internal, both), the complexity of the identity layer, reporting requirements and whether a retest is included. After a scoping call you receive a written proposal within a few working days with the day count and the named lead tester. Our cost guide explains the maths.

    Ready to test your infrastructure?

    Named, certified testers, agreed rules of engagement and a report that shows the attack path, not just the port list.