// 14 · INFRASTRUCTURE SECURITY AUDIT
Infrastructure security audit
An infrastructure security audit is a systematic walk through your network, servers, and network devices at your site, looking for configuration weaknesses before an attacker runs into them. We don’t do it against a generic checklist: we read configurations the way we would exploit them in an attack, because these are exactly the mistakes we get past on tests. The difference from a pentest is in the approach, not the depth: we look inside together with you and with your consent; nothing is broken from outside.
// 01
What the audit covers
The audit goes through the infrastructure layer by layer and asks one thing at each: what would an attacker do with this setting. That is the difference from a generic audit, which only ticks off whether an item matches the standard.
Default and weak passwords on network devices hand an attacker the device without a single exploit: they log in with what the manufacturer left set. A flat network without segmentation, that is, without division into separate sections, means a path from one compromised workstation leads everywhere, which is exactly what lateral movement goes after. A management interface exposed to the internet is an entry point from outside, because whatever is visible from the internet gets tried by attackers continuously. And missing hardening, that is, tightening the configuration by switching off what isn’t needed, leaves open services and default settings as room for privilege escalation.
That comes with an inventory of hardware and software, because without a list of what actually runs on the network there is no way to say what is at risk. We walk through the configurations together with you, not from a scanner export: we look at the specific settings of your devices, not at a tool’s generic messages.
// 02
Why an audit from people who attack
A classic security audit is done against a list: item by item, checking whether a setting matches the recommendation. The problem is that the list doesn’t know what is exploitable in your environment. A configuration that looks fine on paper can, combined with another, be a way in, and a formal finding may mean nothing.
We read configurations from the other side. A practitioner who gets past these settings on tests and in red team operations now goes through them with you from the same side of the table. That practitioner knows which default password gets tried first, where a flat network lets an attacker go everywhere, and which exposed interface an attack aims at first. Priority goes to what is actually dangerous, not to what merely disagrees with a generic recommendation.
It also means a remediation order by real impact, not by the alphabet in the report. A finding that lets someone take over the domain goes to the top; cosmetics can wait. This angle is what a generic IT audit firm doesn’t have: it doesn’t know the attack from the inside, so it grades form, not risk.
// 03
Audit or penetration test?
An audit and a penetration test answer different questions and differ in approach, not in quality. The audit is a review: we look into the configurations together with you and with your consent, go through the settings, and tell you where the weaknesses are. Nothing is broken from outside.
A penetration test is adversarial: it simulates an attacker who tries to get in alone and without hints. The glossary covers when to choose an audit and when a pentest. If you want to verify the weaknesses by attack rather than just see them, the next step is the infrastructure test, where the audit turns into an attack.
// 04
It is not an ISO or compliance audit
This audit is technical, not for certification. We don’t assess your compliance with a standard and we don’t issue any certificate. We look at how the devices are configured and what an attacker can do with that, not at whether your policies are written correctly.
A certificate under ISO/IEC 27001 is issued only by an accredited certification body, not by us. The glossary explains that a certification audit under ISO 27001 is a different service with its own rules. Our technical audit shows the real state of the infrastructure, but it doesn’t replace the evidence for the auditor.
// 05
How the audit runs
We start with scoping: on a call we clarify what is in scope, how large the infrastructure is, and what you expect from the audit. From that comes a plan. Then we come to you, because we do the audit in person on site, not through a remote questionnaire. Together we walk the environment, go through where each device physically sits, write down the hardware and the software, and analyze the network right there with you. It is an inventory in the literal sense, except that we attach each item’s settings to it straight away. Then we go through those together, because you know them best.
We go inside together and with your consent, not to break in. The physical building from an attacker’s point of view, that is, break-in attempts or tailgating (walking in behind an employee), is the job of the physical penetration test: it also works at your site, but unannounced and from the attacker’s position.
The deliverable is a report of weaknesses, each with what it means for an attacker and how to close it, plus a remediation roadmap ordered by impact. The audit is a systematic walk through the entire infrastructure with a documented deliverable. When you need to decide just one thing, say a segmentation design, targeted advice instead of a full audit is faster.
// 06
What you get
Documentation of the hardware and software, a report of configuration weaknesses, and a proposed fix. In the report every item has a description, the impact from an attacker’s point of view, and a specific remediation step. For weaknesses that can be chained into a way in, we describe the whole chain, so it is clear why it belongs at the top.
The proposed fix is written so you can work from it: what to do now, what in the next step, and what is cosmetic. The goal isn’t a list to tick off but a more secure infrastructure.
// 07
What the audit costs
The price is on request, because it follows the size of the infrastructure: the number of devices, the size of the network, and how much is in scope. A flat fee for everyone makes no sense; a small network and a multinational environment aren’t the same thing. We give you the specific figure after scoping, once it is clear how much there is.
The scope and what makes up the price are broken down under audit effort by the size of the infrastructure. A no-obligation scoping call tells you what you’re getting into before you commit to anything.
// 08
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 09
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
We’ll go over the scope together.
Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.