What is it?
This assessment focuses on the organisation’s internal environment—servers, workstations, network devices, and internal applications. It seeks to uncover misconfigurations, outdated software, or weak access controls that could enable attackers already inside the perimeter to move freely.
What could happen?
If the internal network is not well-secured, a single compromised endpoint can lead to widespread breaches. Attackers can escalate privileges, access sensitive databases, and disrupt critical operations, resulting in regulatory failures, reputational harm, and financial losses.
What to do about it?
Foundational: Conduct basic internal vulnerability scans and tighten permissions on critical shares and services.
Outcome: Immediate reduction in easily exploitable misconfigurations.
Enhanced: Employ network segmentation, implement role-based access controls, and regularly review Active Directory settings. Consider periodic internal penetration tests to uncover subtle weaknesses.
Outcome: A more controlled, less permissive internal environment.
Comprehensive: Integrate continuous network monitoring and anomaly detection, combined with just-in-time privilege allocation. Establish a zero-trust model that verifies all internal communications.
Outcome: A resilient internal environment that minimises lateral movement and insider threats.