The scenario
This blueprint describes how FOXMINDS plans and runs a penetration test for a typical mid-sized financial services firm in Lebanon or the Gulf: a broker, insurer or microfinance company with about 250 employees, a head office and four branches.
- Microsoft 365 for email and Teams, with on-premises Active Directory synchronized to Entra ID
- Core systems on a VMware cluster: core financial application, SQL Server, file shares
- A client web portal and a mobile app backed by REST APIs
- Site-to-site VPN to the branches, remote-access VPN for staff, guest Wi-Fi
Management wants to know one thing: could an attacker reach client data or move money, and what should we fix first? Regulators and auditors increasingly expect an independent answer every year. For example, PCI DSS (requirement 11.4) requires regular penetration tests wherever card data is processed.
Scope: what gets tested
| # | Area | What we test | Approach |
|---|---|---|---|
| 1 | External perimeter | Public IPs, firewall, VPN gateways, exposed services, email security (SPF, DKIM, DMARC) | Black box |
| 2 | Client portal & APIs | Authentication, authorization between clients, injection, business-logic flaws | Grey box with two test accounts |
| 3 | Internal network & Active Directory | What a compromised employee laptop could reach and escalate to | Assumed breach |
| 4 | Microsoft 365 & Entra ID | MFA coverage, Conditional Access, admin roles, external sharing, mailbox rules | Configuration review |
| 5 | Wi-Fi & branches | Guest/corporate separation, rogue access points, branch-to-HQ paths | On-site |
| 6 | Phishing resilience | Simulated phishing campaign (optional, approved by management and HR) | Social engineering |
Rules of engagement
A penetration test is only legal and safe with clear, written permission. Before any testing starts we agree and sign:
- Authorization letter from an officer who owns the systems, listing every IP range, domain and application in scope, and confirming permission from any hosting or cloud provider involved.
- Test windows, for example evenings and weekends for production systems, and blackout periods such as month-end closing.
- Prohibited actions: no denial-of-service, no changes to production data, no access to real client records beyond proving it is possible.
- Emergency contacts on both sides and a stop procedure if anything behaves unexpectedly.
- Data handling: evidence encrypted, kept only for the engagement, and securely deleted after the retest.
Methodology and timeline
We follow recognized frameworks: the Penetration Testing Execution Standard (PTES), the OWASP Web Security Testing Guide for applications and APIs, and NIST SP 800-115 for technical security testing. A typical engagement of this size takes three to four weeks end to end.
| Phase | Step | What happens | Duration |
|---|---|---|---|
| 0 | Pre-engagement | Scope, rules of engagement, written authorization, test windows, emergency contacts | 3–5 days |
| 1 | Reconnaissance | Map public IPs, domains, subdomains, exposed services and leaked credentials | 2–3 days |
| 2 | Vulnerability analysis | Automated scanning plus manual verification to remove false positives | 3–4 days |
| 3 | Controlled exploitation | Prove real impact on agreed targets, with no data exfiltration or service disruption | 4–6 days |
| 4 | Post-exploitation | Test lateral movement and privilege escalation toward agreed crown jewels | 2–3 days |
| 5 | Reporting & debrief | Executive summary, technical findings with evidence and CVSS ratings, remediation plan | 3–4 days |
| 6 | Retest | Verify fixes for critical and high findings and issue an updated report | 1–2 days |
Tooling includes Nmap, Tenable Nessus, Burp Suite Professional, Metasploit, BloodHound and Microsoft 365 configuration analysers. Tools find candidates; experienced testers decide what is real and what matters.
Weaknesses we look for
These are the weaknesses most often found in environments like this one across the industry. They are what an attacker tries first, so they are where we start.
| # | Weakness | Area | Typical fix |
|---|---|---|---|
| 1 | VPN or firewall firmware behind on security updates | External | Patch within days of vendor advisories; restrict management interfaces |
| 2 | Legacy authentication that bypasses MFA in Microsoft 365 | Cloud / identity | Block legacy protocols with Conditional Access; enforce MFA for all users |
| 3 | Service accounts with weak passwords and Kerberos tickets that can be cracked offline (Kerberoasting) | Active Directory | Long random passwords or managed service accounts; monitor ticket requests |
| 4 | Same local administrator password on many PCs | Internal | Deploy Windows LAPS so every device has a unique, rotated password |
| 5 | LLMNR/NBT-NS enabled and SMB signing not required | Internal network | Disable legacy name resolution; require SMB signing |
| 6 | Client portal issues from the OWASP Top 10 (access control, injection, outdated components) | Web application | Fix code, add server-side authorization checks, update libraries, add a WAF |
| 7 | Backups reachable from the main domain | Resilience | Separate backup credentials, immutable or offline copies (3-2-1-1) |
| 8 | Flat network between branches, servers and guest Wi-Fi | Network | VLAN segmentation and firewall rules between zones |
Why chains matter: attackers rarely need one critical flaw. A phished password, a reused local admin password and one crackable service account can be enough to go from a single laptop to full domain control. Our report shows these attack paths step by step, so you fix the links that break the whole chain.
What you receive
- Executive summary for management and the board: overall risk, the attack paths found, and the top five actions.
- Technical report: every finding with evidence, CVSS severity rating, affected systems and step-by-step remediation.
- Remediation roadmap grouped into 30, 60 and 90 days.
- Debrief workshop with your IT team.
- Retest and letter of attestation once critical and high findings are fixed, useful for auditors, regulators and partners.
A 90-day remediation plan
- First 30 days: patch exposed systems, enforce MFA everywhere and block legacy authentication, fix critical portal vulnerabilities, rotate exposed credentials.
- Days 31–60: deploy Windows LAPS, harden Active Directory and service accounts, disable legacy protocols, separate backup credentials.
- Days 61–90: network segmentation, EDR on every device with 24/7 monitoring, security awareness training, then the retest.
FOXMINDS can carry out the remediation as well as the test, and provide ongoing monitoring with Microsoft Defender and Sentinel. Testing then becomes a yearly cycle of continuous improvement rather than a one-off report.