External attack-surface assessment & penetration test
Confidential Libyan government entity
Challenge
The entity ran several domains and more than 75 sub-domains. Internet-facing systems had no WAF and no DDoS protection, and sat inside an insecure local cloud that offered none of these protections.
Our approach
We mapped the full external attack surface, then ran vulnerability assessment and penetration testing against public web pages, application keys and the online services offered to users. Several other internet-exposed systems were tested the same way, with a rapid-response report for each.
Outcome
Multiple exposed vulnerabilities were identified across pages, application keys and user-facing services. Official reports documented realistic threat and breach scenarios with severity ratings aligned to NIST.

