LOGIQUE ran a multi-layer security assessment for a national-scale organization in the energy sector, covering four layers of digital defence with a grey-box approach and testing Active Directory as an integrated part of a single assessment cycle. The engagement was delivered in two structured phases to preserve testing depth across large-scale assets.
The client operates national critical infrastructure as part of the energy sector. Under an internal cyber resilience policy, it commissioned an end-to-end security validation of its digital ecosystem, covering user-facing applications, the internal network between business units, and the identity layer that underpins day-to-day operations.
The requirement was not simply to satisfy an audit checklist, but to obtain an objective picture of how well its existing security controls hold up under real-world attack scenarios.
A combination of external and internal assets, web and mobile applications serving thousands of users, a multi-unit internal network, and Active Directory as the backbone of the organization's identity management.
As part of the national energy supply chain, the client is held to a higher resilience standard than a typical commercial organization.
Testing multiple layers at once without disrupting live operations, coordinated across the client's internal teams.
LOGIQUE designed a multi-scope engagement using a grey-box approach, testing four layers of defence within a single coordinated assessment cycle:
| Scope | Testing Focus |
|---|---|
| Layer 1Web Application | Authentication & authorization, business logic, input validation, session management (referencing OWASP Top 10 & ASVS) |
| Layer 2Mobile Application | Local data storage security, API communication, authorization controls, platform-specific hardening |
| Layer 3Internal Network / Infrastructure | Network segmentation, internal service exposure, system configuration, lateral movement paths |
| Layer 4Active Directory | Identity management configuration, privilege escalation paths, access control over the organization's most sensitive assets |
Scroll the table horizontally to see all columns.
Grey-box means the LOGIQUE team started with some information from the client — for example user-level credentials, high-level architecture documentation, or the list of in-scope assets — but still had to find the technical detail, exploitation paths, and configuration gaps itself through active discovery. The approach sits between black-box (no prior information at all, simulating a purely external attacker) and white-box (full access to source code and technical documentation).
For an organization whose ecosystem is as large and as complex as national critical infrastructure, grey-box usually strikes the best balance: more efficient in time and cost than a full black-box engagement, while still reflecting the reality that a real attacker often already holds an entry point or partial information — leaked credentials, an insider threat, exposed documentation — before launching a follow-on attack.
Given how broad the scope was, the engagement was split into two structured phases running over several weeks. That let each layer be tested at real depth rather than as a surface scan, and gave the client's team room to act on the first phase's findings in parallel, without waiting for the whole assessment to finish. For an organization with a large digital ecosystem, a phased approach like this helps protect testing quality while shortening the remediation cycle.
Treating Active Directory as an integrated part of a single assessment cycle, rather than as a standalone add-on test, is one of the hallmarks of LOGIQUE's methodology. The reason is straightforward: AD is a critical point, because if that layer is compromised the impact can spread across the organization's entire environment no matter how well individual applications are secured.
By treating AD as part of the assessment rather than an add-on beside it, LOGIQUE validates the organization's resilience against chained attack scenarios, in which an attacker moves from one layer to the next. This is what separates an end-to-end assessment from standalone per-asset testing, and it is one of the main reasons organizations with complex infrastructure choose LOGIQUE's multi-layer approach.
Chained-attack validation works by simulating how an attacker who has gained limited access in one layer — for example through a standard user's credentials in a web application — then tries to widen that access into other layers, moving from application access to the internal network and finally attempting privilege escalation at the identity management level. Standalone per-asset testing often misses this risk: each layer can look “secure” on its own while a combination of small weaknesses across several layers opens a full attack path that would never surface if the layers were tested separately.
The methodology follows industry frameworks (OWASP, PTES, NIST) and is carried out by a team with international certifications:
The client obtained a complete picture of its security posture, from applications through the network to identity management, within one consistent assessment framework rather than a set of disconnected reports.
Each area for improvement is prioritized by risk level, so the client's internal team can allocate resources efficiently and start with what matters most.
LOGIQUE does not stop at report handover; the team stays with the client throughout the fixes and runs a retest to validate that the remediation worked.
The assessment results support compliance with information security standards such as ISO 27001 and Indonesia's Personal Data Protection Law (Law No. 27/2022), along with the cyber resilience regulations that apply to organizations in the energy sector and national critical infrastructure.
After the initial report is handed over, the client's team carries out remediation in the recommended order of risk priority. LOGIQUE then runs a targeted retest of the remediated areas to verify that the fixes genuinely close the gaps that were found. This step matters because remediation that is never re-validated risks leaving a gap that is closed on paper but still exploitable with a slightly different technique.
The LOGIQUE team showed a clear understanding of how complex our infrastructure is as a national energy provider. The assessment was well coordinated and did not disrupt our operations, and the report we received was clear and actionable for our internal team to act on.
IT Security Manager, a national-scale organization in the energy sector
LOGIQUE delivers penetration testing entirely in-house with a certified team (OSCP, CEH Master, LPT Master), so your data stays confidential.
You get a clear, actionable report, with support that continues until remediation is validated.
Request a sample report or a proposal tailored to your needs. No commitment required.