RINP // SERVICES
ComparisonNetwork-surface exposure or an assumed-breach attack path - which is the right start?
The Network Security Penetration Test and the Modular Red Team Simulation Assumed Breach line do not produce the same evidence object. This page does not open which is better, but which is the right start for your pressure.
- Network Security Penetration Test: chainable access flaws and segmentation impact across external, internal and wireless network surfaces.
- Modular Red Team Assumed Breach: an attack path under the assumption the attacker is inside, critical-target impact and the detection gap.
- A wrong start loses time and budget chasing the wrong evidence; pressure determines the decision, not the category.
In which situation is which the right start?
The seven criteria below separate the decision between the Network Security Penetration Test and the Modular Red Team Simulation Assumed Breach line; the cells are neutral and the two columns carry equal weight - the page does not take sides, it opens the right-start question.
| Criterion | PT-2Network Security Penetration Test | RT-3Modular Red Team - Assumed Breach Line |
|---|---|---|
| Decision question | Where can the network really be entered, from outside or inside? | If the attacker is inside, how far do they advance to the critical target, and does the defense see it? |
| Primary evidence object | Validated technical exposure, a chainable access flaw, segmentation impact, a prioritized closure order. | An attack path to the critical target, a lateral-movement chain, a detection-gap matrix, a chain-breaking control proposal. |
| Ideal trigger | A new internet service, a segmentation change, a wireless refresh, a NAC migration, surface validation before a customer security review. | Resilience validation of a new segmentation, EDR or identity investment; a critical-asset hypothesis; a post-assumed-breach impact question; a SOC detection-gap question. |
| Wrong fit | Trying to meet an expectation of an attack path, critical-target impact or detection gap with a network-surface test. | Inflating a limited network-surface exposure list into an assumed-breach scenario; counting a network penetration-test output as attack-path evidence. |
| Customer prerequisite | Written authorization and asset ownership, module selection (External/Internal/Wi-Fi), the access model, a test window and an escalation line. | Written authorization and rules of engagement, a critical-asset definition, the starting assumption, telemetry and read-only SIEM/EDR access, stop criteria. |
| Typical duration and rhythm | 5–20 business days per module; one-off technical validation; a comprehensive re-test cycle where appropriate. | 2–6 weeks per scenario; controlled threat-scenario execution; an optional Purple Team or scenario-repeat sprint. |
| Neighbor routing | If network-surface exposure is wanted, the Network Security Penetration Test is the right start; not every internal-network movement counts as this service’s scope. | If assumed breach, lateral movement and crown-jewel impact are wanted, the Modular Red Team Simulation Assumed Breach line is the right start. |
What this page does not do
This page does not answer "which is better?". The two services do not produce the same evidence object, and presenting one as the lightweight or showy version of the other is a wrong start. The right start depends on your pressure and your decision question.
- One service is not the continuous, showy or deep version of the other; the two lines produce different evidence objects.
- In the comparison matrix no service is emphasized; the two columns carry equal weight - the page is an editorial-protection surface.
- If both lines are needed in the same engagement, scope, order, telemetry and rules of engagement are clarified in the discovery call.
// DISCOVERY
Let’s clarify the right starting surface together.
In a 30-minute pre-discovery we determine the pressure, the evidence question and the right service line together; where appropriate, the two lines are designed as a sequential program.