Agree the boundaries
We work from your network documentation to list every boundary that is meant to hold, and what is meant to cross it.
A focused test that proves the boundaries you rely on actually hold — cardholder environments, OT networks, management planes — with an allowed-and-denied path matrix your auditor can read.
Segmentation is a control that quietly decays. Rules get added for a project and never removed, a new route makes two zones neighbours, and a boundary that passed last year no longer exists in practice.
We test each boundary from both sides and record exactly what got through, producing the evidence a PCI assessor, an auditor or your own architecture team needs.
Typically three to five days for a defined set of boundaries.
We work from your network documentation to list every boundary that is meant to hold, and what is meant to cross it.
Each boundary is tested in both directions from a position inside each zone.
Every permitted and blocked path is captured as evidence, not summarized from a configuration file.
Where something crosses that should not, we show the route and what it makes possible.
You get the matrix, the findings and a retest after the rules are corrected.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
Rules added for a project years ago and never withdrawn
Management networks reachable from general user space
Backup, monitoring or vendor links quietly bridging two zones
Egress wide open from a segment that should talk to almost nothing
A boundary enforced by routing convention rather than by a control
Missing something on this list? Bring it to the call — we scope around what you have.
See everything you expose to the internet the way an attacker sees it.
Read moreKnow what an attacker could reach once they’re inside your network.
Read moreKeep Wi-Fi and wireless from becoming the way in, at every site you operate.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.