Penetration testing
NIS2 requires you to assess how effective your security measures are. A penetration test does that in the most direct way: our specialists try to break in, as an attacker would, and document what works and why.
- External perimeter, internal network and web applications
- Active Directory and Entra ID, all the way to domain admin
- Technical report and executive summary
- Findings imported into the Nispo register as actions
| Finding | Severity | In the register |
|---|---|---|
| Admin panel exposed with default credentialsExternal perimeter | Critical | In remediation · M. Ferri |
| SMB signing not required on file serversInternal network | High | Assigned · IT |
| Service account with Domain Admin privilegesActive Directory | High | Assigned · IT |
| TLS 1.0 enabled on the customer portalExternal perimeter | Medium | Closed · retest passed |
| User enumeration on the VPNExternal perimeter | Medium | Scheduled |