IT infrastructure resilience testing

IT infrastructure

Penetration testing of infrastructure is a key method for detecting technical and configuration vulnerabilities in network, server, and virtualization environments. This form of testing helps organizations verify the resilience of their systems against external and internal attacks and ensure that the security measures they have implemented work in practice.

Benefits of infrastructure penetration testing


  • Identification of vulnerabilities in network architecture, servers, firewalls, and other elements
  • Verification of the effectiveness of segmentation, access policies, and detection mechanisms
  • Prevention of successful exploitation of errors that could lead to privilege escalation or network compromise
  • Assistance in meeting regulatory framework requirements (DORA, NIS2, ISO 27001)
  • Obtaining an objective overview of the technical resilience of the environment, including third parties

Main objectives of infrastructure penetration testing


  • Testing network security boundaries (external IP, DMZ, VPN, exposed services)
  • Test resistance to lateral movement within the internal network
  • Identify configuration errors, outdated systems, and not updated services
  • Gain access to target systems using both authenticated and unauthenticated methods
  • Evaluate the detection and response capabilities of security tools

Typical attacks and differences between attack vectors

Attack or Vulnerability Name Vector Category Description
SMB Relay / LLMNR Poisoning Internal network Lateral movement Exploitation of insufficient Windows environment hardening
VPN brute-force / MFA bypass Perimeter Access vulnerability Gaining network access via insecure authentication
Privilege escalation (kernel) Server / OS Local attack Gaining root/admin privileges through OS vulnerability
Misconfigured firewall rules Network layer Configuration error Unintended exposure of ports/services to the internal environment
Outdated server software Application layer Technical vulnerability Systems without updates vulnerable to known CVE exploits

What are the requirements for testing teams?


  • Advanced knowledge of network protocols, server platform management, and infrastructure segmentation
  • Ability to perform man-in-the-middle attacks, privilege escalation, and targeted detection tests
  • DORA does not impose specific certifications, but requires appropriate team expertise
  • Experience with testing hybrid environments (on-prem, cloud, virtualization, containerization)
  • Independence of the testing team from the development team, IT operations department, and infrastructure suppliers
  • Test documentation, including relevant forensic outputs and a report that meets regulatory and audit standards

What requirements does DORA set for infrastructure penetration testing?

01

Regular penetration testing at least once a year, or after significant infrastructure changes.

02

Focus on systems that support critical or important business functions.

03

Documentation of vulnerabilities, proposal of corrective measures, and verification of their implementation.

04

Testing also in environments operated by third parties, if they are part of the ICT ecosystem.

Why work with BDO?


BDO provides infrastructure penetration testing as part of a comprehensive security strategy. We help organizations identify and fix technical weaknesses before real attackers exploit them. We use a combination of manual testing, scripted automation, and knowledge of real attack techniques.

01 Technical expertise and experience

Our team has extensive experience in testing infrastructure in banking, telecommunications, industry, and government. We perform external, internal, and hybrid penetration tests, simulating attacks on servers, networks, devices, and third-party infrastructure. 

02  Knowledge of the regulatory framework

BDO understands the requirements of DORA, NIS2, and related cybersecurity frameworks. We help integrate test results into the ICT risk management system and continuously improve resilience. The results of our tests can be effectively used in audits, inspections, and security reporting to management.

03  Independence and credibility

As an independent consulting firm, we are not technologically or procedurally connected to the operational parts of the organization. We offer objective and credible results that respect technical, business, and regulatory requirements. Our clients see us as a long-term security partner, not just a service provider.

04  Certified team with expert practice

Our specialists hold OSCP, CRTP, CEH, CCISO, CISSP, CompTIA PenTest+, BSCP, CRTP, CREST CPSA, MTCNA, and CCNA certifications, which confirm their skills in technical testing, network reconnaissance, and advanced exploitation techniques.

Main contacts

Martin Hořický

Martin Hořický

Partner • Digital Services
View bio
kovalcik

Marek Kovalčík

Chief Information Security Officer • Digital Services
View bio