All penetration tests and assessments / Assumed breach test

Assumed breach test

How far can an attacker get after an assumed breach?

In an assumed breach test, we start from the assumption that a breach has occurred. A threat scenario determines the assessment: what objective would an attacker pursue in your organisation and which routes are relevant to it?

From question to insight

What we clarify

  • How far can an attacker get from the agreed starting point?
  • Which measures interrupt the scenario?
  • If detection and response are in scope: which further steps are detected and followed up?

When is this relevant?

Start with what you want to know.

You want to know what happens after misuse of an account, workstation or other access. For example, when you want to test the protection of a critical process or understand how technology and detection work together.

The approach

From scenario to insight.

01

Scenario and starting point

We choose a relevant attacker objective and agree the assumed access. Optionally, we substantiate the hypothesis with threat intelligence: information about threats and methods relevant to your organisation.

02

Investigating the attack path

Our ethical hackers examine which further steps are possible. The scenario guides the test. We look at the connections between access, permissions, segmentation and the chosen objective.

03

Evidence and feedback

You receive the demonstrated attack paths, the conditions under which they worked and the measures that make a difference. If detection and response are in scope, we also discuss what was observed and followed up.

What you receive

Insight you can act on.

You see how a targeted attack could develop from the agreed starting point. Together, we translate the findings into priorities for prevention, detection and remediation.

In this assumed breach test, we examine which routes to the chosen attacker objective are possible from an agreed starting position. We agree in advance how this assessment relates to an internal penetration test.

SECWATCH colleagues review technical information on screens together.

Discuss your assessment.

Tell us what you want assessed. We will help you find an approach that moves you forward.