Home / Continuous / Network

Network

What someone can do once they hold valid credentials. Network tests your services and infrastructure from an authenticated position, which is where unauthenticated testing stops.

What it covers

  • Authenticated testing of network services, using credentials you provide
  • Credentialed configuration review of exposed infrastructure
  • Remote access controls tested from a valid position, including MFA coverage on those paths
  • Segmentation between network zones, where you have authorised it
  • Privileged service access paths and the escalation available from a standard account
  • Directory and authentication service exposure, where in scope

How the work is carried out

A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.

What the tooling handles

  • Keeps authenticated service checks current as configuration drifts
  • Flags permission and configuration change between consultant passes
  • Repeats constrained, non-destructive checks only

What our consultants do

  • Test the services by hand from an authenticated position
  • Work out what a standard credential actually reaches, and chain from there
  • Validate segmentation claims rather than taking the diagram at face value
  • Confirm every finding, and rate it with business context

Every finding in this module is reproduced or confirmed by a consultant before it reaches you.

What you receive

  • Validated findings, each reproduced or confirmed by a consultant
  • A monthly written report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • An assessment of what valid credentials reach, and where that should be tightened
  • Verification of fixes once you have applied them

What is out of scope

  • A full internal red team or lateral movement campaign, which is scoped separately
  • Application-layer authenticated testing, which is the Access module
  • Operational technology and industrial control systems, which we do not test
  • Denial-of-service testing, which is blocked by default
  • Physical access and on-site work

Prerequisites

Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.

  • Credentials for each service and role we are asked to test
  • A named technical contact who can confirm expected behaviour
  • Signed authorisation from someone entitled to grant that access
  • A confirmed asset register, and the Surface and Perimeter modules in place

Next module: Access