Network

Network segmentation test

A focused test that proves the boundaries you rely on actually hold — cardholder environments, OT networks, management planes — with an allowed-and-denied path matrix your auditor can read.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Segmentation is a control that quietly decays. Rules get added for a project and never removed, a new route makes two zones neighbours, and a boundary that passed last year no longer exists in practice.

We test each boundary from both sides and record exactly what got through, producing the evidence a PCI assessor, an auditor or your own architecture team needs.

PCI DSS segmentation testing requirements NIST SP 800-115 PTES

What we test

  • Every boundary you rely on, tested from both directions
  • Cardholder data environment isolation, where PCI DSS applies
  • IT and OT separation, where an industrial environment is in scope
  • Firewall, VLAN and access-list rule validation against intent
  • Jump hosts, bastion and management-plane access
  • Egress filtering and what a compromised host could call out to
  • Wireless, guest and third-party networks touching the protected zone
  • A documented allowed-and-denied path matrix as evidence
How it runs

From scoping call to retest, here’s what happens.

Typically three to five days for a defined set of boundaries.

1

Agree the boundaries

We work from your network documentation to list every boundary that is meant to hold, and what is meant to cross it.

2

Test from both sides

Each boundary is tested in both directions from a position inside each zone.

3

Record what got through

Every permitted and blocked path is captured as evidence, not summarized from a configuration file.

4

Explain the gaps

Where something crosses that should not, we show the route and what it makes possible.

5

Report, readout and retest

You get the matrix, the findings and a retest after the rules are corrected.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Rules added for a project years ago and never withdrawn

Management networks reachable from general user space

Backup, monitoring or vendor links quietly bridging two zones

Egress wide open from a segment that should talk to almost nothing

A boundary enforced by routing convention rather than by a control

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Network diagrams and the zones you consider separate
  • A test position inside each zone (a host, a drop or a jump account)
  • Your last segmentation evidence, if this is a repeat exercise
  • An escalation contact during the window

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.