This test assumes the attacker has bypassed external defenses or operates from within the network, evaluating lateral movement possibilities and access to sensitive systems. Essential for SAMA CSF internal security requirements.
What's included
- A realistic internal attack simulation from the position of an adversary who has gained a foothold (an employee, an infected host, or an open network port).
- Testing of Active Directory, privilege escalation and lateral movement across systems and servers.
- Measuring the effectiveness of network segmentation and the isolation of sensitive and cardholder environments.
- Mapping access paths to critical data and systems, exposing failure points before a real attacker does.
Methodology & standards
Scoping session with agreed Rules of Engagement and safe, pre-approved testing windows.
Reconnaissance and asset enumeration aligned to PTES and MITRE ATT&CK.
Controlled, non-destructive-by-default exploitation, with every step evidenced.
Post-exploitation: measuring real business and data impact without affecting production availability.
Deliverables
- Executive summary in risk language for leadership
- Detailed technical report with CVSS scoring
- Proof-of-concept evidence per finding
- Prioritized remediation plan
- Findings walkthrough for the technical team
- A retest to verify closure
Regulatory controls it satisfies
Typical timeline
Typically two to four weeks depending on network size, asset count and the scope of sensitive environments — covering scoping, execution, reporting and a retest.
Common questions
Will testing affect our production environment?
We work within agreed windows and a non-destructive-by-default methodology; any action that could affect availability is coordinated with your team in advance.
How is this different from an automated vulnerability scan?
A scan finds known weaknesses automatically; a penetration test proves they are actually exploitable and measures their real impact on your business.
From the same practice