The starting point
Management knew the sector's regulatory framework would demand more of them — operational resilience, risk management, demonstrable controls — and did not want to walk into that conversation blind. The request was clear: "tell us where we really stand, no make-up, and in what order to fix it." They weren't after a certificate yet, but a reliable baseline to build on.
The scope deliberately left out the industrial/OT side in this first phase — documented as such — and focused on external exposure and the internal corporate network, where most of the immediate risk sat and where remediation was most actionable in the short term.
How we approached it
Two fronts in parallel:
- External audit — discovery of the real attack surface (domains, subdomains, exposed services, forgotten assets), contrasted with what the team believed it had published, and validation of the exposure. It surfaced services no one remembered exposing, an admin panel reachable from the internet, and corporate credentials in third-party public breaches.
- Internal audit — from the corporate network, a review of segmentation, configuration and Active Directory security (privilege-escalation paths, service accounts with excessive permissions, password policies, delegations), system hardening and patch management.
The underlying finding was structural: the internal network was practically flat — a compromised machine at one site could reach critical systems at another — and Active Directory had accumulated years of permissions granted and never revoked. None of this was delivered as a 200-line list, but grouped by risk and by root cause.
Results
2
fronts audited in parallel: external exposure and internal corporate network
3
remediation phases prioritised by risk and effort, with owners
1
single risk dashboard that management and technical teams share and understand
The deliverable wasn't just the report: it was a phased plan the internal team could start executing the following week, with quick-containment measures (close what was exposed, rotate leaked credentials, isolate the admin panel) separated from the structural ones (segment the network, clean up Active Directory) that need a project. The company then faced its regulatory roadmap knowing exactly where it started from.
What made it work
- The real attack surface almost never matches what an organisation thinks it has: the first job is discovering the forgotten.
- Internally, a flat network and an unmaintained Active Directory are the pattern that most often turns a minor incident into a major one.
- A risk-prioritised, executable plan is worth more than an exhaustive report nobody knows where to start with.
Frequently asked questions
What's the difference between a security audit and a pentest?
A pentest answers "can someone get in this way?": it tries to exploit vulnerabilities within a specific scope. An audit answers "where do we stand and what do we fix first?": it assesses exposure, configuration and controls broadly, and prioritises. If you haven't had a serious assessment in years, the audit is usually the first step; a pentest makes more sense once there's a baseline to test against.
What does an internal and external security audit include?
The external side covers discovery of the real attack surface — domains, subdomains, exposed services, forgotten assets, credentials in public breaches — and validation of that exposure. The internal side, from the corporate network: segmentation, configuration and Active Directory security (escalation paths, service accounts, delegations), system hardening and patch management. The scope is agreed in writing, including what's left out.
How long does an audit like this take?
For a mid-sized organisation — several sites, a few hundred employees — an internal and external audit typically takes three to six weeks, with both fronts running in parallel. This engagement took four weeks. Network size, number of sites and the depth of the Active Directory review are what move the timeline most.
What happens with the findings after the audit?
You don't get a flat list of 200 findings: they're grouped by risk and root cause and turned into a phased remediation plan, with quick-containment measures separated from the structural ones that need a project, and owners assigned. The goal is for your team to start executing the following week, not to file a report away.
Related services
Do you know your real exposure?
An internal and external audit gives you the honest baseline before any compliance project. We tell you where you stand and in what order to fix it.