NETWORK AND INFRASTRUCTURE PENTEST

Identify and address security vulnerabilities in your network and infrastructire with CREST-approved penetration testing.

Trusted by leading organisations

Wise, a financial technology company
Jojo Maman Bebe, a baby clothing retailer and part of Next Plc
Pluxee, a Software as a Service (SaaS) company and part of Sodexo
Block, an IT Managed Services company
StoreFeeder, an e-commerce company and part of the Royal Mail Group
Unicard
Oddballs Apperal
Kyloe Partners, a recruitment technology company

Network and infrastructure penetration testing detects vulnerabilities in an ICT network or infrastructure. It looks at different entry points into the system and uses them to determine how cyber attackers can exploit them.

As the world increasingly moves online, the risk of your systems and data being breached or compromised increases. Network and infrastructure penetration testing is essential to find and fix any weaknesses in your systems before a cyber incident occurs.

During a network and infrastructure assessment, our consultants will conduct a simulated attack scenario mimicking attacks carried out in the wild.

These can generally be broken into two forms, an internal network assessment and an external infrastructure assessment.

What is a network and infrastructure penetration test?
What is an internal network penetration test?

Internal assessments are conducted within your network perimeter. They aim to uncover what an attacker may achieve if they breach your external network’s defences and gain access to your internal network.

Internal network assessments can be designed to mimic the level of access someone may achieve by entering your premises and plugging into the network. They can also replicate the level of access granted to employees or be used to assess the damage of insider threats, such as rogue employees.

During an internal assessment, our highly experienced testers will seek to move laterally across a network, compromising machines along the way. They will try to escalate their privileges to effectively take over the network. Our consultants use tried and tested techniques alongside custom methods to achieve these goals, accurately mimicking the actions taken by real hackers. During this phase, typical activities include:

  • Determining the controls in place to protect access to sensitive information
  • Finding insecure systems and services
  • Finding and exploiting software having publicly disclosed vulnerabilities
  • Reviewing active directory permissions to find weaknesses that could enable the escalation of privileges
  • Compromising user accounts
  • Intercepting passwords in use on the network
What is an internal network assessment part 2

Internal testing provides a comprehensive assessment of the ICT network within your network perimeter. It can accurately simulate the actions that may occur following a security breach. It provides valuable insight into how effective your defences are against potential attacks.

As the level of access granted is often equivalent to employee access levels or those visiting a building, it can provide meaningful insight into the risks posed by insider threats.

The main benefits of internal network testing include:

  • Gain a comprehensive review of the internal configuration of your network
  • Determine the impact of a potential breach on your business
  • Assess your existing defences and controls
  • Discover weaknesses that could be used during a breach or compromise
  • Gain insight into the risk posed by insider threats
  • Comply with regulatory requirements which mandate regular pentesting
  • Understand how attackers can move through your internal infrastructure and compromise essential services
  • Recommendations to reduce the risk in case of a breach

Book your pentest

What is an external infrastructure assessment?

External assessments examine a network’s perimeter defences to identify and exploit weaknesses in the system from outside the organisation.

Our team will simulate an attack on the external and public-facing infrastructure. This may cover web and mail servers, virtual private networks (VPNs) and file servers.

We’ll scan your public network ranges for open ports, then analyse detailed information about those hosts to find potential weaknesses that may be exploited. This can include unpatched or outdated software, or weak login or security credentials. Once potential vulnerabilities are identified, our team will try to use them to gain access to the hosts and any data they hold.

Your external network perimeter is the first line of defence against attackers. External testing focuses on identifying and exploiting weaknesses in your network’s publicly accessible infrastructure.

Without any credentials, our team will assess your network security posture and its configuration, simulating an attack by a real adversary.

The goal is to detect any misconfigurations and uncover the fundamental weaknesses hackers could use to gain access to your network or valuable data stored on your systems. The main benefits of external infrastructure testing include:

  • Assess systems at the edge of your network perimeter (such as web servers, file shares, mail servers etc.)
  • Assess the configuration of the network perimeter (such as VPNs and firewalls)
  • Discover publicly available information that attackers could leverage
  • Discover public-facing assets
  • Harden your external facing security posture
  • Detect vulnerabilities visible to attackers
  • Ensure regulatory compliance

Request a quote

As well as network and infrastructure pentests, our team provides the following penetration testing services:

Cloud penetration testing

Cloud penetration testing

Cloud pentesting detects misconfigurations that may expose systems or data. We test environments hosted on AWS, Google Cloud, and Azure to ensure your cloud services remain secure against attacks.

Vulnerability Assessment

Vulnerability assessment

Our vulnerability assessments evaluate systems to identify, classify, and prioritise weaknesses. We analyse infrastructure at scale, ensuring vulnerabilities are found and resolved before attackers exploit them.

Penetration testing services

All penetration testing services

Our penetration testing services support businesses with regulatory or commercial testing needs, and those prioritising cyber security. We deliver independent technical assurance for systems and applications.

Our experienced and CREST-certified penetration testing team has the required level of expertise to provide an accurate and comprehensive penetration testing service.

Our consultants will work closely with you to determine the most appropriate testing and clarify any questions you may have.

Our communication-focused client-first approach ensures that our consultants are always on hand to answer any questions you may have. We pride ourselves on establishing and building strong and collaborative long-term relationships with our clients.

Connect with us

Certified by the industry,
trusted by you

Our cyber security consultants are equipped with industry-leading certifications, reflecting our deep technical expertise and unwavering commitment to protecting your future. These qualifications enable us to provide clear, actionable insights and trustworthy guidance, ensuring your organisation remains secure in an ever-changing landscape.

CREST
The UK Cyber Security Council (UKCSC)
The Cyber Scheme
Offensive Security
TCM Security

Frequently asked questions

What is a network and infrastructure penetration test?

Network and infrastructure penetration testing is one type of penetration testing that involves simulating real-world cyberattacks against your internal systems, servers and network components to identify security vulnerabilities.

Network testing focuses on finding weaknesses in your network architecture, such as firewalls, routers and access controls.

Infrastructure testing assesses internal devices, servers and systems that support business operations.

What steps are involved in a network and infrastructure penetration test?

Once the scope and testing limitations have been agreed upon, our CREST-accredited pentester(s) follow a structured approach. The key phases typically include reconnaissance, scanning for vulnerabilities, exploitation, post-exploitation and reporting. This ensures thorough coverage of your network and infrastructure to identify and address security weaknesses.

How long does a network and infrastructure pentest take?

This depends on the agreed-upon scope of the penetration test. Factors include the size of the network under review, whether it’s an internal or external network, and whether any pentesting is performed from an authenticated perspective.

How much does a network and infrastructure pentest cost?

The cost of network and infrastructure penetration testing typically ranges from £5,000 to £15,000. This depends on factors such as the number of systems in scope, the technologies within the environment to be assessed, and any specific objectives of the assessment.

What is CREST?

CREST is an international not-for-profit accreditation and certification body representing and supporting the technical information security market. Companies can become a CREST member and apply for CREST-accredited services. The application requires a rigorous assessment of companies’ processes, data security and service methodologies to ensure they’re executed to best practice standards.

Why should I use a CREST-approved pentesting company?

Working with a CREST-approved penetration testing provider ensures you’re in safe and experienced hands. You should have the confidence that your penetration test is thorough and comprehensive. Your provider must conduct a technically accurate test that covers the required scope of your IT controls to ensure your primary security concerns are assessed.

Who conducts a network and infrastructure pentest?

Our highly skilled CREST-registered penetration testers simulate attacks on your ICT networks and infrastructure using the same tools and techniques as those employed by real-world malicious adversaries.

When should I get a penetration test?

Network environments are never static and are constantly changing. New software, hardware, users and authentication methods can all increase your network’s attack surface. This creates more opportunities for hackers to exploit. When coupled with the continuous emergence of new vulnerabilities, there’s never been a better time to schedule a consultation. Our skilled consultants have extensive knowledge of compliance and regulatory requirements, from data protection and GDPR to ISO 27001 and PCI DSS. We’ll be able to determine the network and infrastructure approach best suited to your needs.

Will a pentest disrupt our services?

Our skilled pentesters follow strict guidelines and legal and technical standards to ensure minimal disruption to your business while performing a penetration test.

Is Sentrium a CREST-approved provider?

Yes! Sentrium is a CREST-approved penetration testing provider. We’re proud to provide services that achieve CREST’s extremely high standard of quality and professionalism, which is recognised internationally.

What happens after the penetration test?

The pentester(s) assigned to your project will compile a detailed report containing the identified vulnerabilities, what risks they pose and recommendations on how to remediate them. Once we’ve delivered the report, our team will be available for a conference call to discuss the report in detail and answer any questions you may have.

In their words

Sentrium have extensive knowledge of security and penetesting, and have provided us with many valuable insights. We are grateful for their exemplary work and dedication to giving a top quality service.

Director, Manufacturing

Sentrium is a trusted partner we have used for several years. Their services are second-to-none, and the team's communication, specialised knowledge, and flexibility are commendable.

IT Manager, Software Development

Working with Sentrium Security on our penetration testing was a pleasure. Their services were comprehensive, well organised, and delivered with professionalism. They get a 5/5 from us.

Chief Information Security Officer (CISO), Telecommunications

Sentrium surpassed our expectations. They identified vulnerabilities and provided recommendations that were very easy to follow. Their commitment to quality is apparent, and we gladly recommend them.

Chief Operating Officer, Financial Services

We engaged Sentrium for our annual pentesting. Their team demonstrated great skills, I was surprised to find they discovered some issues our previous company had missed! I will use them again next year.

Head of IT Security, International E-commerce

I'm impressed with the speed and quality of services provided by Sentrium. Great communication and a flexible, professional and approach throughout. I'll certainly be using Sentrium again in the future!

Head of Technology Risk & Security, Financial Services

Sentrium has been really helpful in improving our cyber security. They keep in mind our budget and explain things clearly. Cyber security went from being an enigma to something we can tackle with confidence!

Project Manager, Charity Sector

Adam and James have been great to work with. Very clear communication from start to finish making the process very easy to complete whilst taking the time to understand our needs and queries.

Director, Software as a Service (SaaS) Company

Ready to discover your security gaps?

Get in touch