
Martin Hořický
Penetration testing of infrastructure is a key method for detecting technical and configuration vulnerabilities in network, server, and virtualization environments. This form of testing helps organizations verify the resilience of their systems against external and internal attacks and ensure that the security measures they have implemented work in practice.
| Attack or Vulnerability Name | Vector | Category | Description |
|---|---|---|---|
| SMB Relay / LLMNR Poisoning | Internal network | Lateral movement | Exploitation of insufficient Windows environment hardening |
| VPN brute-force / MFA bypass | Perimeter | Access vulnerability | Gaining network access via insecure authentication |
| Privilege escalation (kernel) | Server / OS | Local attack | Gaining root/admin privileges through OS vulnerability |
| Misconfigured firewall rules | Network layer | Configuration error | Unintended exposure of ports/services to the internal environment |
| Outdated server software | Application layer | Technical vulnerability | Systems without updates vulnerable to known CVE exploits |
Regular penetration testing at least once a year, or after significant infrastructure changes.
Focus on systems that support critical or important business functions.
Documentation of vulnerabilities, proposal of corrective measures, and verification of their implementation.
Testing also in environments operated by third parties, if they are part of the ICT ecosystem.
BDO provides infrastructure penetration testing as part of a comprehensive security strategy. We help organizations identify and fix technical weaknesses before real attackers exploit them. We use a combination of manual testing, scripted automation, and knowledge of real attack techniques.
01 Technical expertise and experience
Our team has extensive experience in testing infrastructure in banking, telecommunications, industry, and government. We perform external, internal, and hybrid penetration tests, simulating attacks on servers, networks, devices, and third-party infrastructure.
02 Knowledge of the regulatory framework
BDO understands the requirements of DORA, NIS2, and related cybersecurity frameworks. We help integrate test results into the ICT risk management system and continuously improve resilience. The results of our tests can be effectively used in audits, inspections, and security reporting to management.
03 Independence and credibility
As an independent consulting firm, we are not technologically or procedurally connected to the operational parts of the organization. We offer objective and credible results that respect technical, business, and regulatory requirements. Our clients see us as a long-term security partner, not just a service provider.
04 Certified team with expert practice
Our specialists hold OSCP, CRTP, CEH, CCISO, CISSP, CompTIA PenTest+, BSCP, CRTP, CREST CPSA, MTCNA, and CCNA certifications, which confirm their skills in technical testing, network reconnaissance, and advanced exploitation techniques.