One to three weeks depending on scope, agreed in advance and fixed.
STEP 2 OF 3
Find out how far someone gets
Inside tests, outside tests and application tests, run the way an attacker would run them. Two questions matter: how far does someone get, and how long does it take anybody to notice.
Assessment
A vulnerability list is not an assessment. Anyone can produce one. What decides how bad an incident becomes is the second question — whether a foothold on one laptop reaches the domain controller, and whether anything raised an alarm on the way. That is what we measure, and it is the number that changes people's minds.
What happens
- External testing: what the internet can reach and what it already knows about you
- Internal testing: what a single compromised laptop leads to
- Application testing against the systems your business actually runs on
- Detection check: what your own tooling saw while we were doing it
A technical report your engineers can act on, a summary a board can read, and an honest answer on whether anyone noticed.
When this is the right first move
- You have controls in place and no evidence of whether they work
- A regulation or a customer contract requires testing on a schedule
- Something changed — a merger, a new supplier, a system moved to the cloud
- You want the argument for a budget settled by evidence rather than opinion
And when it is not. Skip it if nothing has been fixed since the last one. Retesting an estate that has not changed produces the same report and teaches nobody anything.
The other steps
This is where most engagements start
The first step costs you half a day and ends in a document you keep whether or not you go further.