A buyer’s guide · Operating since 2002
Compromise is almost never one catastrophic flaw. It is an unpatched edge device, then a foothold, then a cached credential, then a flat internal network where reaching one host means reaching all of them. Each hop is individually unremarkable. Each is separately fixable.
Infrastructure security is the discipline of breaking that chain: servers, endpoints, network devices, identity, privilege and the backups that are supposed to save you. This page sets out the path attackers actually walk, which control breaks each hop, and how the assessment methods differ from one another.
The chain
The path, and what breaks each hop
Five hops from the internet to everything. A different control interrupts each one, and any single hop that holds stops the whole path.
This is why an estate is best scored on the chain rather than on a checklist. A control framework asks whether each box is ticked; an attacker asks only whether the hops connect. The two questions produce very different priorities, and only one of them reflects how compromise actually happens.
The comparison
Pen test vs scan vs config audit vs red team vs compliance
These five are quoted against each other constantly and they are not substitutes. Each answers a different question, and the last column is why buying the cheap one rarely gives you the expensive one’s answer.
Scroll the table sideways →
| Method | What it is | What it establishes | The honest limitation |
|---|---|---|---|
| Infrastructure penetration test | A person attacking your estate with an objective, usually domain or cloud administrator. | Whether the chain can actually be walked end to end. | Point in time, and scoped. It proves a path exists; it does not enumerate every weakness. |
| Vulnerability scan | Automated identification of known missing patches and exposed services. | Breadth — everything with a published CVE, across the whole estate. | No exploitation and no chaining. Produces volume, ranks by CVSS rather than by what it would actually let someone do. |
| Configuration auditCIS or vendor baseline | Systematic comparison of settings against a hardening benchmark. | Drift, insecure defaults, and the things nobody turned on. | Says nothing about whether a weakness is reachable. A perfectly hardened host on a flat network is still one hop from everything. |
| Red team | Objective-driven adversary simulation, usually including people and physical routes. | Whether detection and response actually work under realistic conditions. | Tests the defenders as much as the estate. Wasted on organisations that have not yet done the basics. |
| Compliance audit | Evidence that controls exist and are operating. | Gaps against a named standard, and the documentation to prove it. | Measures conformance, not security. Passing an audit and being compromised are entirely compatible states. |
The pairing that catches people out is scan and test. A scan is inventory — broad, cheap, ranked by CVSS. A test is a demonstration that a path exists, and that path frequently runs through three medium findings no scanner would ever connect to one another.
The work
Six areas, in the order they usually pay off
Hardening is unglamorous and measurable, and it removes whole classes of attack rather than individual vulnerabilities. These are the areas, roughly in the order that effort tends to return value.
Edge and exposed services
Everything reachable from the internet: VPN concentrators, firewalls, mail gateways, management interfaces that were never meant to be public. Inventory first, because the exposure nobody knows about is the one that stays unpatched.
Server and endpoint baselines
Configuration against a recognised benchmark, unique local administrator credentials, script and macro controls, and the removal of the legacy protocol nobody has needed since 2002 but nobody has dared switch off.
Identity and privilege
Administrative tiering so a workstation compromise does not reach a domain controller, multi-factor on every administrative path, service accounts with owners and rotation, and no shared credentials whose scope nobody can describe.
Network segmentation
East-west control so reaching one host does not mean reaching all of them. This is the single highest-value and most commonly deferred item on the list, because it is disruptive and invisible when it works.
Patch and lifecycle
Measured patch compliance rather than assumed, with a defined position on the equipment that is past end-of-support and cannot be patched at all — because there always is some.
Backup integrity
Backups isolated from the credentials that protect production, and restores tested by performing them. Ransomware operators target backups first precisely because so few organisations verify them.
Segmentation is fourth on that list and first in impact. It is deferred more than any other item because it is disruptive to implement and invisible when it works — and it is the control that most reliably turns a total compromise into a contained incident.
Straight answers
What buyers get wrong about infrastructure security
Attackers walk a chain; checklists score boxes
Compromise is almost never one catastrophic flaw. It is an unpatched edge device, then a foothold, then a cached credential, then a flat internal network, then everything. Each hop is individually unremarkable and each is separately fixable. Scoring an estate control by control misses the property that actually matters, which is whether the hops connect.
Segmentation is the highest-value deferred item
It is disruptive, it is invisible when it works, and it never has an owner pushing for it. It is also the control that most reliably converts a total compromise into a contained incident. Organisations that finally do it usually do so immediately after the incident that would have been contained by it.
“We scan monthly”
Scanning is necessary and cheap and finds the known-missing patch. It performs no exploitation, chains nothing, and ranks by CVSS rather than by what a finding would actually let someone do next. A scan is inventory. It is not an assessment.
Passing an audit and being compromised are compatible
Compliance measures whether named controls exist and operate. An attacker measures whether a path exists. Both can be true simultaneously, and organisations that treat a clean audit as a security result are consistently surprised.
“Was there an internal phase?”
External testing examines the perimeter, which is the part most organisations have already hardened. The interesting question is what happens after someone gets a foothold — and assumed-breach internal testing is the phase most frequently descoped to hit a price.
Backups are targeted before data is encrypted
Ransomware operators go for the backup infrastructure first, because a working restore removes their leverage entirely. Backups reachable with production credentials are not isolated, and a backup job reporting success is evidence a job ran rather than evidence your data comes back.
Before you sign
Ten questions for any infrastructure assessment
Use these on us and on everyone else. Question three is the one most quotes quietly omit to hit a price.
Is the test objective-driven, or a scan with a report cover?
Ask what the objective was and whether it was achieved. “Domain administrator from an unauthenticated position” is an objective; “identify vulnerabilities” is a scan.
Do you chain findings, or list them separately?
Three medium findings that combine into a full compromise matter more than any single high. A report that never connects them has done the easy half of the work.
Is there an internal assumed-breach phase?
External-only testing tells you about the perimeter. Most damage happens after someone is already inside, and that is the phase most quotes quietly omit.
How do you actually test segmentation?
Ask for the method. Reading firewall rules is not testing; attempting to cross boundaries from a controlled host is.
Which hardening benchmark do you assess against, and which version?
CIS Benchmarks and vendor guidance are versioned and they move. “Industry best practice” as an answer means no benchmark at all.
Do you test credential hygiene and administrative tiering?
Cached credentials and shared local administrator passwords are how a single foothold becomes an estate-wide compromise. It is the most common finding and the least common thing on a scan report.
Are backups in scope, including whether a restore works?
A backup that shares a credential path with production is not a recovery plan. Ask whether a restore was performed or merely reported as successful.
How do you handle equipment that cannot be patched?
Every real estate has some. A provider with no compensating-control answer for end-of-support systems has not worked on real estates.
Is a retest included after remediation?
Findings you cannot demonstrate are closed are findings you still have. It should be in the price, not a change order.
What is the risk to production, and what is the abort procedure?
Infrastructure testing touches live systems. Agree the boundaries, the contact and the stop conditions in writing before anyone starts.
Working with us
How we run this
We have built and defended enterprise infrastructure since 2002 — the networks, the firewalls, the servers — and we run the operations centre that watches them afterwards. We are usually assessing estates of a kind we also operate.
Findings that chain
Reports connect the mediums that combine into a compromise, rather than listing them separately and leaving you to notice.
Internal phase included
Assumed-breach testing is part of the engagement, not the line removed to reduce the quote. It is where the useful findings are.
Realistic about legacy
Every estate has something that cannot be patched. We give you compensating controls and a documented decision rather than a finding you cannot action.
Retest included
A finding you cannot demonstrate is closed is a finding you still have.
Certified operations
ISO/IEC 27001:2022 certified, with our operations centre inside the certified scope and the scope statement available on request.
US presence
P J Networks LLC is our US entity, based in Dallas, Texas — the company a US client contracts with. It is a subsidiary of P J Networks Pvt Ltd, which holds the ISO/IEC 27001:2022 certification referenced on this page.
Questions we get asked
Infrastructure security, answered
What is infrastructure security?
Infrastructure security covers everything beneath the application layer: servers, endpoints, network devices, identity and directory services, virtualisation, and the backup systems that are supposed to save you. It is concerned with reducing what an attacker can reach and do once inside, rather than with the code your developers write — that is application security.
How is this different from your managed security services?
Managed security services is the ongoing operational arrangement — running your controls, monitoring, responding. This page describes the assessment and hardening discipline: finding out where the attack paths are and closing them. In practice the assessment usually comes first, because managing an estate nobody has assessed means operating controls whose gaps are unknown.
What is an infrastructure penetration test?
A person attempting to achieve a defined objective across your estate — typically domain administrator, or access to a specific critical system, starting either from the internet or from an assumed foothold inside. Unlike a scan it chains weaknesses together, which is how real compromise works and why chaining is the thing to ask about.
How is it different from a vulnerability scan?
A scan identifies known missing patches and exposed services across everything, quickly and cheaply, and ranks by CVSS. A penetration test establishes whether a path can actually be walked, which frequently runs through three medium-severity findings that no scanner would connect. Both are useful and they are not substitutes; a scan is inventory and a test is a demonstration.
What is server hardening?
Configuring a system to reduce its attack surface: removing unnecessary services and software, applying a recognised benchmark such as the CIS Benchmarks, enforcing unique local administrator credentials, disabling legacy protocols, controlling scripting, and ensuring logging is on and shipped somewhere. It is unglamorous, it is measurable, and it removes whole classes of attack rather than individual vulnerabilities.
Which hardening benchmarks do you use?
CIS Benchmarks where they exist for the platform, and vendor hardening guidance where they do not. Both are versioned and both move, so the version assessed against is stated in the report. A provider who answers this question with “industry best practice” is not working from a benchmark at all.
What is network segmentation and why does it matter so much?
Segmentation limits what can talk to what, so that reaching one host does not mean reaching every host. It is consistently the highest-value control in infrastructure security and the most commonly deferred, because it is disruptive to implement and invisible when it works. It is also the difference between an incident affecting one department and one affecting the entire organisation.
Do you test from outside, inside, or both?
Both, and the internal phase is the one that matters most. External testing examines the perimeter, which most organisations have already spent money on. The internal assumed-breach phase asks the more useful question: given that someone will eventually get a foothold, how far can they get? That phase is also the one most often removed to reduce a quote.
What about equipment that cannot be patched?
Every real estate has some — a controller running an unsupported operating system because the vendor never certified anything newer, a device whose replacement needs a plant shutdown. The answer is compensating controls: isolate it, restrict what may reach it, monitor it closely, and document the decision. Pretending it is not there is the only wrong answer.
Are backups in scope?
Yes, and specifically whether they are reachable using production credentials and whether a restore has actually been performed. Ransomware operators target backup infrastructure first precisely because a working restore removes their leverage. A backup job reporting success proves a job ran, not that your data comes back.
Will testing disrupt production?
Testing touches live systems, so the boundaries, the named contact and the stop conditions are agreed in writing before anything starts. Genuinely destructive techniques are excluded unless you explicitly want them in a controlled window. Any provider who does not raise this before you do is not thinking about your uptime.
Do we get a retest?
Yes, and you should require it from any provider. A finding you cannot demonstrate is closed is a finding you still have, and remediation frequently addresses the symptom rather than the path.
How does this relate to your VAPT service?
VAPT is the scoped testing engagement across network, application and cloud. This page is the wider infrastructure discipline that testing sits inside — hardening baselines, segmentation, privileged access and backup integrity, which are the things you do with the findings. Many organisations buy the test first and build the programme afterwards.
How is this scoped and priced?
By the number of hosts, sites and domains, whether an internal assumed-breach phase is included, whether cloud and identity are in scope, and whether you want hardening implementation as well as assessment. Send us a rough estate size and we will scope it against that rather than a template.
Next step
Tell us the estate, and what you would least like reached
Rough host and site counts, whether cloud and identity are in scope, and the system you would least like an attacker to reach. We will scope an assessment around that objective, tell you honestly whether an internal phase is worth more than an external one at your maturity, and say so if hardening work would serve you better than another test.



