A network security assessment is an outside review of how well your network holds up against attack: what is exposed to the internet, which systems are vulnerable, how firewalls and remote access are configured, and how far an intruder could get once inside. The phrase covers several different services, from an automated scan to a full attack simulation, and they answer different questions at very different prices. This guide explains each type, the checklist an assessor works through, how a network security audit differs from an assessment, and what each option costs.
Most people who ask for a “network assessment” do not yet know which of these they need. That is fine. The sections below are written to help you pick, and the table in the next section is the short version.
What a network security assessment actually measures
NIST’s technical guide to security testing, SP 800-115, sorts assessment work into three families. Every network security assessment on the market is some mix of them, and the mix is what you are paying for.
| Technique family (SP 800-115) | What it involves | What it tells you |
|---|---|---|
| Review techniques | Reading documentation, logs, firewall rulesets and system configurations, often without touching the live network | Whether controls are designed and configured the way policy says |
| Target identification and analysis | Network discovery, port and service identification, vulnerability scanning, wireless scanning | What is actually on the network and which known weaknesses it has |
| Target vulnerability validation | Password cracking, penetration testing, social engineering | Whether those weaknesses can really be exploited, and what an attacker reaches |
A review with no validation tells you what should be true. A scan with no validation tells you what might be wrong. Validation tells you what is wrong, and how badly. The cheapest assessments stop at the first or second family; the ones that change how a network is defended include the third.
The main types of network security assessment
These are the services sold under the “network security assessment” label, what each answers, and what each costs at Invadel. Prices are fixed per scope and every penetration test includes a free retest.
| Type | The question it answers | How it works | Invadel price |
|---|---|---|---|
| Validated vulnerability assessment | Which known vulnerabilities exist across the network, ranked by real risk? | Authenticated and unauthenticated scanning, then an analyst removes false positives and ranks what is left | $1,500 up to 250 devices, $2,500 up to 1,000 |
| Firewall and rule review | Do the firewall rules, VPN and management interfaces allow what the network needs, and nothing more? | Your intended policy compared with what the rules actually let through, tested from where an attacker would stand, plus the firewall’s own exposed management and VPN interfaces | Included in the external and internal tests below |
| External network test | What can someone on the internet reach, and can they get in? | Discovery of every internet-facing host, then manual exploitation of what is found | From $4,200 |
| Internal network test | If one laptop or account is compromised, how far does the attacker get? | Testing from an assumed foothold inside, including Active Directory and the paths to domain admin | From $6,000 |
| Segmentation test | Do the boundaries between zones, such as a payment or OT enclave, actually hold? | Attempts to cross from every out-of-scope segment into the protected one | Included in the internal test; standalone re-tests scoped and quoted |
| Network security risk assessment | Which risks matter most to the business, and what should be fixed first? | Threat, likelihood and impact analysis in the style of NIST SP 800-30, fed by the technical results above | Not a test on its own: see our security risk assessment guide |
Wireless networks are assessed the same way, usually alongside the internal test, because the question is the same: can a nearby attacker get onto a network that reaches something valuable?
Which one do you need?
Pick by the question you have to answer, not by the name on the request.
| Your situation | Start with | Why |
|---|---|---|
| You have never had an outside view of the network | Validated vulnerability assessment | A ranked baseline at the lowest cost, and it shows whether a deeper test is worth it |
| A cyber insurer or customer questionnaire asks whether the network has been tested | External and internal network test | Many questionnaires ask about penetration testing by name, and a scan does not answer that question |
| PCI DSS, SOC 2, HIPAA or NYDFS evidence is due | External and internal test, plus segmentation where scope depends on it | PCI DSS and NYDFS Part 500 require penetration testing, SOC 2 auditors routinely ask for it, HIPAA’s evaluation standard is usually evidenced with it, and PCI also requires segmentation testing where segmentation reduces scope |
| Leadership or an auditor asked for a “network audit” | A network security audit (checklist below), with a test for the technical items | An audit checks controls against a standard; the test proves the technical ones work |
| After an incident, a merger or an office move | Internal network test | You need to know what an attacker who is already inside can reach today |
| Between annual tests | Vulnerability assessment on a cadence | Catches new exposure early, and a quarterly or monthly cadence keeps the evidence current |
Network security assessment checklist
This is the working checklist an assessor covers across a full engagement. The last column shows which technique verifies each item, so you can see what a scan alone would miss.
| Area | What gets checked | Verified by |
|---|---|---|
| Scope and inventory | Every subnet, site, cloud VPC and internet-facing IP is listed and owned; nothing is on the network that is not on the list | Review plus discovery |
| Perimeter exposure | Only intended services face the internet; no management interfaces, databases or file shares are exposed | Discovery and external test |
| Remote access | VPN, remote desktop and vendor access require MFA, run supported versions and cannot be brute-forced | Configuration review and external test |
| Patch level | Operating systems, network devices and appliances are current; nothing is past end of support | Authenticated scan |
| Firewall rules | Every rule has a documented reason and owner; no “any to any” rules; egress is restricted, not just ingress | Rule review and attacker-side test |
| Segmentation | Sensitive zones (payment, clinical, OT, backups, management) cannot be reached from user networks | Segmentation test |
| Identity and Active Directory | No path from a standard user to domain admin; no weak Kerberos, delegation or certificate-service misconfigurations | Internal test |
| Name resolution and legacy protocols | LLMNR, NBT-NS and other broadcast protocols that leak credentials are disabled; SMB signing is enforced | Internal test |
| Credentials | No default or shared passwords on network devices, printers, cameras, IPMI or appliances | Scan and internal test |
| Wireless | Corporate Wi-Fi uses enterprise authentication; the guest network is isolated; no rogue access points | Wireless assessment |
| Logging and detection | Firewall, VPN, domain controller and endpoint logs are collected, retained and would show the test | Review, and the test’s activity as a live check |
| Backups | Backups are isolated from the domain and would survive an attacker with admin rights | Configuration review and internal test |
| Remediation and retest | Every finding has an owner and a date, and the fix is re-tested rather than assumed | Retest |
If you want to run the scanning part yourself first, our network vulnerability assessment checklist breaks that stage into 30 checks, from scoping to reporting.
Network security audit checklist: how an audit differs
“Network security audit” and “network security assessment” are used interchangeably, but they are different jobs. An audit compares your controls against a standard or your own policy and asks for evidence that they operate: documents, records and settings. An assessment measures actual exposure. A network can pass an audit, because every policy exists and every review was signed, and still fail an assessment, because a forgotten server has no patches.
A network security audit checklist, with the evidence an auditor asks for:
- Network security policy. Approved, current, and covering firewall management, remote access, wireless and logging. Evidence: the policy and its approval record.
- Network diagram and asset inventory. Current diagrams of zones, trust boundaries and data flows. Evidence: dated diagrams that match what is deployed.
- Firewall change management. Every rule change requested, approved and recorded, with a periodic rule review. Evidence: change tickets and the last review.
- Access reviews. Administrative access to network devices and servers reviewed on a schedule, with leavers removed. Evidence: the last review and its outcome.
- MFA coverage. Remote access and administrative interfaces require it. Evidence: configuration screenshots or exports.
- Patch and vulnerability management. Defined timelines for fixing critical findings, and records showing they were met. Evidence: scan reports and remediation tickets.
- Logging and monitoring. Which logs are kept, for how long, and who reviews alerts. Evidence: retention settings and alert records.
- Backup and recovery. Backups taken, isolated and restore-tested. Evidence: the last restore test.
- Third-party access. Vendor connections inventoried, time-limited and monitored. Evidence: the vendor access list.
- Independent testing. When the network was last tested by an outside party and whether findings were closed. Evidence: the latest test report and retest.
The last item is where an audit and an assessment meet: most audit frameworks accept an independent network test as the evidence that the technical controls work. For a broader view that covers applications, cloud and governance, our IT security audit guide explains how a full audit is run, and our list of cybersecurity audit companies separates firms that attest to frameworks from firms that test.
How an assessment runs, step by step
- Scoping. Agree the IP ranges, sites, cloud accounts and wireless networks in scope, the testing windows, and anything off limits. The price is fixed at this point.
- Discovery. Find what is really there, which is rarely identical to the inventory. Unknown hosts found here are often the most important result.
- Scanning. Authenticated scans where credentials are provided, because unauthenticated scans miss most missing patches.
- Validation. An analyst confirms each finding, removes false positives and ranks the rest by exploitability and business impact.
- Exploitation (penetration tests only). Testers chain findings the way an attacker would: from an exposed service to a foothold, from a foothold to credentials, from credentials to the systems that matter.
- Reporting. An executive summary for leadership, technical findings with reproduction steps for engineers, and an attack narrative for any path that succeeded.
- Remediation and retest. Fixes are verified by a retest and the report is updated to show them closed.
Critical findings do not wait for the report. If an internet-facing system can be taken over on day one, you hear about it on day one.
What an assessment typically finds
The same issues come up across very different networks, which is why they belong on every checklist:
- Remote access or administrative portals exposed to the internet without MFA.
- Firewalls, VPN appliances and switches running firmware past end of support.
- Flat internal networks, where a user laptop can reach servers, backups and management interfaces directly.
- Broadcast name-resolution protocols that let an attacker capture and relay credentials from the local network.
- Default credentials on printers, cameras, storage and out-of-band management cards.
- Old firewall rules nobody can explain, often allowing broad access for a project that ended years ago.
- Service accounts with domain admin rights and passwords that never change.
Several of these are invisible to a scanner. A scan reports a printer; it does not report that the printer’s stored credentials open a path to the file server. That is the difference the validation step makes, and why our guide to firewall penetration testing treats rule review from the attacker’s side rather than as a console audit.
What a network security assessment costs
Price follows scope, and scope for a network is counted in devices, internet-facing addresses and sites. At Invadel:
- A validated vulnerability assessment is $1,500 for up to 250 devices and $2,500 for up to 1,000, with larger estates quoted.
- An external and internal network test starts at $4,200 for the external perimeter and $6,000 for the internal network, including Active Directory. The two can be scoped together as one engagement, so paths from the perimeter to the inside are tested end to end.
- Segmentation testing is part of the internal test. Standalone re-validation, such as a service provider’s six-monthly PCI segmentation check, is scoped and quoted.
Every price is fixed in writing before work starts, and every penetration test includes a free retest of remediated findings. There is no hourly billing and no charge for the report.
Frequently asked questions
What are the main types of tests used in network security assessments? Vulnerability scanning, configuration and firewall rule review, external penetration testing, internal penetration testing, segmentation testing and wireless testing. A risk assessment sits on top of them and turns the technical results into business priorities.
Is a network security assessment the same as a penetration test? Not necessarily. “Assessment” can mean anything from a scan to a full test. A penetration test is the type that proves exploitation; a vulnerability assessment lists and ranks known weaknesses without exploiting them. Ask any provider which of the three SP 800-115 technique families the work includes.
How long does a network security assessment take? A validated vulnerability assessment usually takes days. A standard external or internal network test takes about a week of hands-on testing; a combined external and internal test, several sites or multiple Active Directory forests take longer. Scoping comes before it and reporting after.
Will it disrupt our network? It should not. Testing windows, exclusions and a stop contact are agreed during scoping, denial-of-service testing is excluded unless you ask for it, and fragile systems are tested with care or scheduled outside business hours.
How often should we run one? A full external and internal test at least once a year and after significant changes, with validated scanning in between. Several frameworks, including PCI DSS, set annual testing as the minimum.
Do you need credentials or on-site access? Credentials make scanning far more accurate, so we ask for a low-privilege account. Internal testing usually runs remotely through a small appliance or virtual machine we provide, so no travel is needed. On-site work is available where it is required, such as wireless testing in the New York metro.
Need an outside view of your network before an audit, a renewal or a board meeting? Tell us what is in scope and we will recommend the smallest assessment that answers the question, at a fixed price.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →