Analysis

Internal Attack Surface Review

What can an attacker see and reach once they are on your internal network? You receive a portable assessment sensor, connect power and network — and we map your internal attack surface in a controlled manner, without an on-site visit. Independent, and with no software installed on your side.

In short

The Internal Attack Surface Review maps what an attacker can see and reach on your internal network. You receive a portable sensor, connect power and network — we handle the rest remotely. You get a report with technical observations, a risk assessment and concrete recommendations. No software installation, no operational impact, fixed price after a free pre-analysis. Unlike a penetration test, we map in a controlled way — without active exploitation.

What the review covers

  • Host discovery, MAC/vendor and network topology
  • Open ports, service versions and CVE matches
  • AD enumeration via LDAP and SMB shares
  • WiFi landscape and IPv6 exposure
  • Poisoning risk assessment

What you get

  • Report with technical observations and risk assessment
  • Concrete recommendations
  • No software installation on your side

Out of scope

  • Not a full penetration test
  • No credentialed scanning or active exploitation
  • No guarantee of covering every network segment
Clients who trust Sekuritet
  • Unilite
  • Cadpeople
  • Kunde & Co
  • Bitcoin Suisse
  • Mercantec
  • Dagrofa
  • Laursens Realskole
  • Zug Kommune
  • Altid Vikar
  • Adeo Datacenter
  • A&O Kreston
  • Numarics
  • Geelmuyden Kiese
The assessment we received deserves a 10 out of 10 without hesitation.
Ionela Dumitrescu · Production Manager, responsible for IT and Digitalisation · Unilite A/S · More client testimonials →

80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →

How it works

01

Free pre-analysis

We agree the scope and give you a fixed price. No obligation, no surprises.

02

Connect the sensor

You receive a portable assessment sensor and connect power and network — that is your entire effort.

03

Controlled analysis

We map your internal attack surface remotely — controlled and without operational impact.

04

Report & plan

Technical observations, risk assessment and prioritised recommendations — and the sensor is returned.

Frequently asked questions

Do you need to come on-site?

No. You receive the portable sensor by mail, connect power and network — and we work remotely. The sensor is returned after the engagement.

Is the sensor safe to have on our network?

Yes. The sensor performs only the agreed, controlled measurements, communicates encrypted, and is removed from the network as soon as data collection is complete.

How is this different from a penetration test?

The review maps what an attacker can see and reach — without actively exploiting anything. A penetration test goes one step further and attempts controlled compromise of selected targets.

What does an Internal Attack Surface Review cost — and why isn't the price listed here?

Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.

First step

Ready to have your security verified by an independent third party?

A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.

Get a free pre-analysis