Infrastructure Penetration Testing
Pentest People offer consultant-led Infrastructure Penetration Testing to provide a thorough and independent examination of your corporate infrastructure and systems to identify software and conﬁguration based security vulnerabilities.
There are two components to delivering Infrastructure Penetration Testing and these are Internal and External assessments. It is commonplace to combine these into a single test that covers both the internal and external components of the network.
Download & view our digital Infrastructure Penetration Testing Data Sheet>>
Infrastructure Penetration Testing can be performed Internally within your corporate network or Externally over the Internet
Internal Penetration Test
An Internal Penetration Test is performed by a qualified Pentest People security consultant who is onsite within your corporate network.
This type of assessment looks for security issues and vulnerabilities on the inside of your corporate network with the same physical access as a member of staff or other types of employee who has access to the building.
This assessment provides a very comprehensive view of the configuration of your corporate network devices and servers from a security viewpoint of an insider, connected to your network.
External Penetration Test
An External Penetration Test is performed by a Pentest People security consultant whilst remote from your corporate network.
This type of assessment is concerned with assessing the external, Internet-facing infrastructure of your corporate network. This could be your Firewall, VPN endpoints, Web Servers and Mail Servers etc..
The level of access to these resources would be the same as an external hacker trying to break into your corporate environment so this assessment provides you with a real risk indicator as to your external security posture.
Remote Internal Testing
Traditionally, Infrastructure Penetration Tests have been conducted onsite where a Pentest People Consultant would visit your office and physically connect to the network infrastructure to perform the assessment.
Pentest People are offering a Remote Infrastructure Penetration Test where the whole engagement is performed without the need to visit the customer site.
The client can either download a Virtual Machine image that can be installed within the corporate network or be shipped a standalone network appliance.
Both solutions create a secure channel to the Pentest People Operations Centre where the assigned consultant can then command the image or appliance in the same way as they would if they had their laptop on site.
All data collected during the test is held securely at our ISO27001 Operations Centre allowing the consultant to perform the assessment and upload the results to SecurePortal for delivery to the customer.
What Are The Risks?
IT Security and the associated terminology is a mainstream issue for all businesses due to the reliance business places on its IT systems combined with the prevalence of attacks.
IT Security issues have become commonplace in todays society with almost weekly coverage in the news regarding the latest data breaches with the larger attacks attracting substantial financial penalties.
Various forms of compliance exist that mandate regular Penetration Testing as a required standard and the risks of not doing anything are widely publicised.
How Can We Help?
Pentest People can help alleviate the risks associated with IT Security issues by performing regular Internal and External assessments of your corporate infrastructure to identify if any issues exist and to give you an ability to remediate these before an attacker could exploit them.
Pentest People are accredited to CREST and UK NCSC CHECK standards and can provide infrastructure testing against all types of IT infrastructure used within your organisation
Test allows access to SecurePortal
Until now, the traditional deliverable from a Penetration Test engagement has been a lengthy 100+ page PDF report.
Pentest People have developed a solution to this issue where you interact with your vulnerabilities within the SecurePortal.
Constantly updating Vulnerability Information to stay in touch with the emerging threat landscape.
Receive overview and trend data of all of the current security issues you face in your organisation. All viewable on an interactive dashboard.
Rest assured that your assessments are performed by qualified Security Consultants.
Our specialised team of security consultants hold industry qualifications such as CHECK Team Member & Team Leader, CCIE, CISSP and CEH.
Understand the Internal and External security issues you face through a very thorough assessment from a qualified security consultant.
- Identify Security Vulnerabilities within your organisation allowing you to proactively remediate any issues that arise
- Improve your security posture, allowing you to reduce the threat of a cyber attack occurring against your business
- Comply with various regulatory bodies who mandate regular Penetration Testing be performed within your infrastructure
- Be able to prove to your supply chain that you are taking the necessary precautions to ensure your strong security posture
- Be able to focus efforts on important security issues by identifying the high-risk items identified in the Penetration Testing report
An Infrastructure Penetration Test is a full consultant-led assessment of the security of your external and internal infrastructure.
Pentest People use industry-leading methodologies and tools to identify the latest software and configuration vulnerabilities for all devices on your network.
An Internal Penetration Test is where a consultant would be placed within your corporate environment and connected to your internal network looking for security issues from the inside.
An External Penetration Test is where a consultant looks for security issues from the outside of your network, generally over the public Internet.
A Vulnerability Scan is performed by a software tool that scans the network and checks available services for known vulnerabilities.
A Penetration Test takes this one step further and uses a consultant to check for vulnerabilities that an automated scanner cannot find as well as to manually confirm any identified vulnerabilities.
The deliverable from this service is a full Penetration Test Report that is uploaded to our SecurePortal and available for you to interact with.
This differs from the competition in the way this is delivered and we believe this is a much clearer way to work with an manage the results of the assessment.