Skip to content
8bytes

Network security,
stress-tested.

Architecture review, firewall and segmentation audits, Zero Trust assessments, and internal network pentests — across cloud, on-prem, and wireless.

Coverage

What we test.

Network testing across the perimeters and segmentation boundaries that actually matter — both the ones your architecture diagram shows, and the ones it does not.

External perimeter

Public-facing assets, exposed services, VPN endpoints. Service enumeration, exploitation, ingress paths into the internal network.

Internal network

Lateral movement, privilege escalation, Active Directory abuse, Kerberos attacks, credential theft. From foothold to crown jewels.

Wireless

Corporate Wi-Fi, guest network isolation, rogue access points, BYOD enrolment flows, RFID and proximity-based access controls.

Segmentation & Zero Trust

Test the boundaries your architecture promises. East-west segmentation, microsegmentation, conditional-access policy enforcement.

Methodology

How we work.

01

Asset & topology discovery

Map the network as it actually is, not as the diagram says it is. Shadow assets, forgotten subnets, and untracked trust relationships often come out at this stage.

02

Configuration review

Firewall rules, switch ACLs, routing tables, VPN configurations. Identify over-permissive rules and unintended trust paths.

03

Segmentation testing

Verify that the boundaries the architecture promises actually hold under attack. Reach what should be unreachable.

04

Internal pentest

Assumed foothold on a low-trust segment. How far can an attacker get? Active Directory, file shares, jump hosts, hypervisors.

05

Architecture recommendations

Concrete Zero Trust and hardening recommendations prioritised by the attack paths we actually walked.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • Network topology assessment with current-state diagram
  • Firewall and ACL rule audit (over-permissive rules flagged)
  • Segmentation effectiveness report — boundary by boundary
  • Lateral movement paths from each tested foothold
  • Hardening and Zero Trust roadmap with prioritised actions
  • Compliance mapping (PCI DSS segmentation, NIST 800-207) on request

FAQs

Common questions.

01

Do you need full network access?

No. Most engagements start from one or two foothold positions — a guest Wi-Fi connection, a low-trust subnet, or an "attacker workstation" we ship to your office. We escalate from there. Full read access is helpful for the configuration-review phase but not the testing phase.

02

Will testing impact production?

Default posture is non-disruptive. Anything that could cause an outage (active exploitation of fragile services, brute-forcing against rate-limited accounts) is run during agreed windows with your network ops team on standby.

03

Can you assess wireless networks?

Yes — corporate Wi-Fi, guest networks, BYOD enrolment, and RFID-based physical access. Wireless testing typically requires onsite presence or a shipped device on your premises.

04

Do you do internal-only or external-only engagements?

Either. External-only is more common for compliance audits; internal-only is more common when the worry is "what if a phish actually lands". The two together give the most complete picture.

05

How is this different from a cloud audit?

Network security focuses on the connectivity layer — what traffic can flow where, and what crosses trust boundaries. Cloud security focuses on identity and configuration of cloud-managed resources. The two overlap in modern environments but ask different questions.

Get in touch

Want to stress-test your network?

Book a call

Free 30-min scoping call. No commitment.