Internal Infrastructure Penetration Testing

Internal infrastructure penetration testing

Find out what an attacker could do once they're inside.

Assume-breach testing from within your network, including Active Directory, delivered to a recognised methodology by a Cyber Scheme Team Leader qualified tester.

Cyber Scheme Team Leader qualified Active Directory covered Free retest once fixed
Assume breach

The real question is what happens after the first click

Perimeters get bypassed. Someone clicks a phishing link, a laptop is lost, a contractor plugs in a device. The damage is decided by what an attacker can do next, once they already have a foothold inside.

We test from that starting point. Given a normal position on your network, we see how far an attacker could move, whether they could escalate from an ordinary user to domain-wide control, and what sensitive data or systems they could reach. Then we give you a prioritised list of the paths to close first.

Scope

What we test for

Active Directory

Active Directory attack paths

The misconfigurations and weaknesses that let an attacker climb from an ordinary account to domain-wide control, including weak Kerberos settings, over-privileged accounts and well-known escalation paths.

Movement

Lateral movement and privilege escalation

How far a foothold spreads: moving between systems, escalating privileges, and turning a single compromised device into control of many.

Credentials

Credential exposure and harvesting

Passwords and tokens cached, reused or left in the open, and how an attacker would gather and reuse them across your estate.

Segmentation

Network segmentation

Whether the boundaries between your networks actually hold, or whether a foothold in one area quietly reaches everything else.

Patching

Internal patching and services

Unpatched internal systems and weakly configured services that a scanner outside your perimeter would never see.

Data

Sensitive data on shares

File shares and internal stores holding sensitive data that far more people can reach than should, a common and quiet source of exposure.

Delivered to a recognised standard

Tested by a qualified infrastructure tester, not a scanner with a logo

Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards. Our lead tester is also a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

In practice that means industry-standard tooling for breadth, then manual testing and the chaining of issues to work out what an attacker could really achieve inside your network, and a report you can act on.

Deliverables

A report you can act on, and a retest to prove it worked

The report

Written for the board and the technical team

  • An executive summary in plain English
  • Each finding risk-rated, with evidence and step-by-step reproduction
  • Specific, practical remediation advice, not generic boilerplate
Afterwards

A debrief and a free retest

  • A walkthrough of the findings if it helps your team
  • A retest once you have fixed the issues, to confirm the fixes hold
  • Included as standard, not sold as an add-on
How it works

Straightforward from first email to retest

  1. Tell us about your network

    A short enquiry, answered by a tester rather than a sales team.

  2. A quick scoping call

    15 to 30 minutes on your estate, your sites, and whether Active Directory is in scope.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

  4. Testing and reporting

    Agreed rules of engagement, testing to a recognised methodology, then a report you can act on.

  5. A free retest

    Once you have fixed the findings, we confirm the fixes hold at no extra cost.

From our Insights

More on penetration testing

ISO 27001

Working towards ISO 27001?

ISO 27001 does not mandate an annual penetration test, but it is risk-based, and testing is often the clearest way to show that technical vulnerabilities are being found, understood and managed.

We provide independent testing that supports an ISO 27001 programme, scoped to your risks rather than a generic checklist, with a report that feeds straight into your risk register and remediation plan.

Does ISO 27001 require penetration testing?
Where testing fits

The most relevant Annex A controls

  • A.8.8: management of technical vulnerabilities
  • A.8.29: security testing in development and acceptance

Independent testing provides evidence that these controls work in practice, not just on paper.

Common questions

Internal infrastructure testing, answered.

What is internal infrastructure penetration testing?

It answers a different question from an external test: not can someone get in, but what could they do once they are in. Working from inside your network, as if a laptop had been phished or a rogue device plugged in, we see how far an attacker could move, what they could reach, and whether they could take control.

What do you actually test?

Lateral movement and privilege escalation, Active Directory weaknesses, credential exposure and harvesting, network segmentation, unpatched internal systems and services, weak internal service configuration, and sensitive data left accessible on file shares. We chain issues together the way a real attacker would to establish genuine impact, not just a list of individual findings.

Do you test Active Directory?

Yes, and for most organisations it is the heart of an internal test. We look at the misconfigurations and weaknesses that let an attacker escalate from an ordinary account to domain-wide control: weak Kerberos and authentication settings, over-privileged accounts, credential exposure, and the well-known attack paths that lead to a full compromise if they are not closed off.

Who carries out the testing?

An experienced, senior tester runs your engagement from scoping to report, with no hand-off to a junior halfway through. Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and our lead tester is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

How do you run the test without disrupting us?

We agree the rules of engagement in writing first, avoid genuinely destructive techniques, and can work from a supplied device or a connection into your network. Testing can be scheduled around your quiet periods, and we stay in contact throughout so there are no surprises.

What do we get at the end?

A clear report written for both your board and your technical team: an executive summary, then each finding with a risk rating, the evidence, step-by-step reproduction, and specific remediation advice. Once you have fixed the issues we retest to confirm the fixes hold, at no extra cost.

How much does internal infrastructure testing cost?

There is no fixed public price, because it depends on scope: the size of your internal estate, the number of sites and whether Active Directory is involved. Tell us about your environment on a short scoping call and we will come back with a fixed-price quote, typically within 48 hours.

Get a quote

Find out what your internal test would cost

Tell us about your internal network and we'll recommend an appropriate scope and provide a no-obligation quotation.

  1. We read your enquiry

    A real tester, not a sales team, so the first reply is already useful.

  2. A short scoping call

    15 to 30 minutes to understand your estate and what you need to prove.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

Not sure whether you need internal, external or both? Tell us what you're trying to achieve and we'll help you scope it.