Internal Attack Surface Review
What can an attacker see and reach once they are on your internal network? You receive a portable assessment sensor, connect power and network — and we map your internal attack surface in a controlled manner, without an on-site visit. Independent, and with no software installed on your side.
The Internal Attack Surface Review maps what an attacker can see and reach on your internal network. You receive a portable sensor, connect power and network — we handle the rest remotely. You get a report with technical observations, a risk assessment and concrete recommendations. No software installation, no operational impact, fixed price after a free pre-analysis. Unlike a penetration test, we map in a controlled way — without active exploitation.
What the review covers
- Host discovery, MAC/vendor and network topology
- Open ports, service versions and CVE matches
- AD enumeration via LDAP and SMB shares
- WiFi landscape and IPv6 exposure
- Poisoning risk assessment
What you get
- Report with technical observations and risk assessment
- Concrete recommendations
- No software installation on your side
Out of scope
- Not a full penetration test
- No credentialed scanning or active exploitation
- No guarantee of covering every network segment
- Unilite
- Cadpeople
- Kunde & Co
- Bitcoin Suisse
- Mercantec
- Dagrofa
- Laursens Realskole
- Zug Kommune
- Altid Vikar
- Adeo Datacenter
- A&O Kreston
- Numarics
- Geelmuyden Kiese
The assessment we received deserves a 10 out of 10 without hesitation.
80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →
How it works
Free pre-analysis
We agree the scope and give you a fixed price. No obligation, no surprises.
Connect the sensor
You receive a portable assessment sensor and connect power and network — that is your entire effort.
Controlled analysis
We map your internal attack surface remotely — controlled and without operational impact.
Report & plan
Technical observations, risk assessment and prioritised recommendations — and the sensor is returned.
Frequently asked questions
Do you need to come on-site?
No. You receive the portable sensor by mail, connect power and network — and we work remotely. The sensor is returned after the engagement.
Is the sensor safe to have on our network?
Yes. The sensor performs only the agreed, controlled measurements, communicates encrypted, and is removed from the network as soon as data collection is complete.
How is this different from a penetration test?
The review maps what an attacker can see and reach — without actively exploiting anything. A penetration test goes one step further and attempts controlled compromise of selected targets.
What does an Internal Attack Surface Review cost — and why isn't the price listed here?
Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.
Ready to have your security verified by an independent third party?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Get a free pre-analysis