Skip to content

Home Expertise / Penetration testing

PEN / PEN-02

Internal and assumed-breach penetration testing

An assessment of what an attacker could reach after gaining an initial internal foothold, examining excessive privileges and weak separation.

WHEN IT HELPS

A focused response
to a defined need.

CISO or infrastructure owner; flat networks, shared accounts, a recent incident or validation of segmentation work.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-02

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Agreed starting point and test accounts
  • paths to critical assets
  • bounded segmentation and privilege testing

Deliverables

  • Documented attack paths
  • associated business impacts
  • controls to prevent observed progression

Acceptance evidence

Each confirmed path is reproducible within authorised limits and linked to a verifiable control that breaks it.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Where does testing start? Which assets are excluded? Are detection teams informed?

IMPORTANT BOUNDARIES

An assumed-breach scenario does not necessarily test initial phishing or malware prevention.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A services company assumes one user workstation is compromised. Project: test access to shares and administration systems. Target outcome: identify ineffective boundaries and targeted corrections without using real customer data.

Scenario 02

A manufacturer tests from the office network. Project: assess separation from production networks. Target outcome: evidence of isolation or actionable gaps; stop before risky interaction with industrial controllers.

Technology and reference context

Customer directories, networks and systems; context-specific attack-path mapping.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.