From an Ordinary Laptop to the Whole Network
A national science organisation runs hundreds of servers, from scientific processing clusters to public web services. While helping modernise its infrastructure, our engineer became the organisation’s go-to person for security.
The challenge
Security risks described in a report are easy to file away. IT staff and managers needed to understand what an attacker could realistically do inside their network, starting from the kind of access anyone might have.
What we did
- Tested like an attacker: Servers, network services and software tested by actually exploiting weaknesses, not just scanning for them
- Reported responsibly: Vulnerabilities found and reported in widely used software, including one in Microsoft DNS and one in an open-source data catalogue
- Looked beyond technology: Weaknesses identified in how documents and intellectual property were controlled
- Shown live: A live demonstration to IT staff and managers of a complete network takeover, starting from an ordinary, unprivileged computer
- Every step answered: A mitigation for each stage of the attack, explained in plain terms
The result
- Risk made real: Managers saw first-hand how a single foothold could become full control
- A clear plan: Practical fixes tied to each step of the demonstration, so priorities were obvious
- Wider benefit: Microsoft patched the DNS flaw we reported, protecting organisations everywhere
- Recognised: The work, alongside automation and system design, earned an internal award for innovation
Services involved
Want to know how far an attacker could get in your network? Call 04 282 0045 or send us a message.