// 14 · INFRASTRUCTURE SECURITY AUDIT

Infrastructure security audit

An infrastructure security audit is a systematic walk through your network, servers, and network devices at your site, looking for configuration weaknesses before an attacker runs into them. We don’t do it against a generic checklist: we read configurations the way we would exploit them in an attack, because these are exactly the mistakes we get past on tests. The difference from a pentest is in the approach, not the depth: we look inside together with you and with your consent; nothing is broken from outside.

// 01

What the audit covers

The audit goes through the infrastructure layer by layer and asks one thing at each: what would an attacker do with this setting. That is the difference from a generic audit, which only ticks off whether an item matches the standard.

Default and weak passwords on network devices hand an attacker the device without a single exploit: they log in with what the manufacturer left set. A flat network without segmentation, that is, without division into separate sections, means a path from one compromised workstation leads everywhere, which is exactly what lateral movement goes after. A management interface exposed to the internet is an entry point from outside, because whatever is visible from the internet gets tried by attackers continuously. And missing hardening, that is, tightening the configuration by switching off what isn’t needed, leaves open services and default settings as room for privilege escalation.

That comes with an inventory of hardware and software, because without a list of what actually runs on the network there is no way to say what is at risk. We walk through the configurations together with you, not from a scanner export: we look at the specific settings of your devices, not at a tool’s generic messages.

// 02

Why an audit from people who attack

A classic security audit is done against a list: item by item, checking whether a setting matches the recommendation. The problem is that the list doesn’t know what is exploitable in your environment. A configuration that looks fine on paper can, combined with another, be a way in, and a formal finding may mean nothing.

We read configurations from the other side. A practitioner who gets past these settings on tests and in red team operations now goes through them with you from the same side of the table. That practitioner knows which default password gets tried first, where a flat network lets an attacker go everywhere, and which exposed interface an attack aims at first. Priority goes to what is actually dangerous, not to what merely disagrees with a generic recommendation.

It also means a remediation order by real impact, not by the alphabet in the report. A finding that lets someone take over the domain goes to the top; cosmetics can wait. This angle is what a generic IT audit firm doesn’t have: it doesn’t know the attack from the inside, so it grades form, not risk.

// 03

Audit or penetration test?

An audit and a penetration test answer different questions and differ in approach, not in quality. The audit is a review: we look into the configurations together with you and with your consent, go through the settings, and tell you where the weaknesses are. Nothing is broken from outside.

A penetration test is adversarial: it simulates an attacker who tries to get in alone and without hints. The glossary covers when to choose an audit and when a pentest. If you want to verify the weaknesses by attack rather than just see them, the next step is the infrastructure test, where the audit turns into an attack.

// 04

It is not an ISO or compliance audit

This audit is technical, not for certification. We don’t assess your compliance with a standard and we don’t issue any certificate. We look at how the devices are configured and what an attacker can do with that, not at whether your policies are written correctly.

A certificate under ISO/IEC 27001 is issued only by an accredited certification body, not by us. The glossary explains that a certification audit under ISO 27001 is a different service with its own rules. Our technical audit shows the real state of the infrastructure, but it doesn’t replace the evidence for the auditor.

// 05

How the audit runs

We start with scoping: on a call we clarify what is in scope, how large the infrastructure is, and what you expect from the audit. From that comes a plan. Then we come to you, because we do the audit in person on site, not through a remote questionnaire. Together we walk the environment, go through where each device physically sits, write down the hardware and the software, and analyze the network right there with you. It is an inventory in the literal sense, except that we attach each item’s settings to it straight away. Then we go through those together, because you know them best.

We go inside together and with your consent, not to break in. The physical building from an attacker’s point of view, that is, break-in attempts or tailgating (walking in behind an employee), is the job of the physical penetration test: it also works at your site, but unannounced and from the attacker’s position.

The deliverable is a report of weaknesses, each with what it means for an attacker and how to close it, plus a remediation roadmap ordered by impact. The audit is a systematic walk through the entire infrastructure with a documented deliverable. When you need to decide just one thing, say a segmentation design, targeted advice instead of a full audit is faster.

// 06

What you get

Documentation of the hardware and software, a report of configuration weaknesses, and a proposed fix. In the report every item has a description, the impact from an attacker’s point of view, and a specific remediation step. For weaknesses that can be chained into a way in, we describe the whole chain, so it is clear why it belongs at the top.

The proposed fix is written so you can work from it: what to do now, what in the next step, and what is cosmetic. The goal isn’t a list to tick off but a more secure infrastructure.

// 07

What the audit costs

The price is on request, because it follows the size of the infrastructure: the number of devices, the size of the network, and how much is in scope. A flat fee for everyone makes no sense; a small network and a multinational environment aren’t the same thing. We give you the specific figure after scoping, once it is clear how much there is.

The scope and what makes up the price are broken down under audit effort by the size of the infrastructure. A no-obligation scoping call tells you what you’re getting into before you commit to anything.

// 08

How we classify findings

Vulnerability severity classification
SeverityCVSS
Critical9.0 – 10.0
High7.0 – 8.9
Medium4.0 – 6.9
Low0.1 – 3.9

// 09

Frequently asked questions

An inventory of hardware and software, a joint walk through the configurations of network devices, and a proposed fix. For every weakness we say what an attacker would do with it, not just whether it matches a standard: a default password means taking over the device, a flat network means lateral movement, an exposed management interface means an entry point from outside. The deliverable is a report with a remediation order by impact.

In approach. The audit is a review: we go through the configurations together with you and with your consent, and nothing is broken from outside. A penetration test simulates an attacker who tries to get in alone and without hints. The audit tells you where the weaknesses are; a pentest also verifies them by attack. The glossary entry covers the definitional difference and when to choose which.

No. This is a technical configuration audit built on offensive expertise, not certification against a standard. We don’t assess compliance with policies and we don’t issue a certificate; that is for an accredited certification body. We show you how the devices are configured and what an attacker can do with that, which is a different question from a document for the auditor.

It’s on request, by the size of the infrastructure. The number of devices and the size of the network drive the price, so a flat fee for everyone makes no sense. You get the specific figure after the scoping call, once it is clear how much is in scope. Scoping carries no obligation.

// INCLUDED WITH EVERY ENGAGEMENT

Free one-time data leak check

With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.

How continuous leak monitoring works

// NEXT STEP

We’ll go over the scope together.

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.