home

HOME

about

ABOUT US

services

SERVICES

others menu

OTHERS

close

Multi-Layer Security Assessment for National Energy Infrastructure

Summary

LOGIQUE ran a multi-layer security assessment for a national-scale organization in the energy sector, covering four layers of digital defence with a grey-box approach and testing Active Directory as an integrated part of a single assessment cycle. The engagement was delivered in two structured phases to preserve testing depth across large-scale assets.

Updated:

Four layers of defence tested within a single assessment cycle Diagram of four testing layers, from the outermost layer inward: Web Application, Mobile Application, Internal Network / Infrastructure, and Active Directory. A single chained-attack test path runs across all four layers. Web Application Mobile Application Internal Network / Infrastructure Active Directory Chained-attack test path

Background

The client operates national critical infrastructure as part of the energy sector. Under an internal cyber resilience policy, it commissioned an end-to-end security validation of its digital ecosystem, covering user-facing applications, the internal network between business units, and the identity layer that underpins day-to-day operations.

The requirement was not simply to satisfy an audit checklist, but to obtain an objective picture of how well its existing security controls hold up under real-world attack scenarios.

Challenges

Scale and complexity of the digital ecosystem

A combination of external and internal assets, web and mobile applications serving thousands of users, a multi-unit internal network, and Active Directory as the backbone of the organization's identity management.

High expectations for critical infrastructure

As part of the national energy supply chain, the client is held to a higher resilience standard than a typical commercial organization.

A need for coordinated independent validation

Testing multiple layers at once without disrupting live operations, coordinated across the client's internal teams.

LOGIQUE's Approach

LOGIQUE designed a multi-scope engagement using a grey-box approach, testing four layers of defence within a single coordinated assessment cycle:

The four testing layers, ordered from the outermost layer inward to the organization's identity core.
Scope Testing Focus
Layer 1Web Application Authentication & authorization, business logic, input validation, session management (referencing OWASP Top 10 & ASVS)
Layer 2Mobile Application Local data storage security, API communication, authorization controls, platform-specific hardening
Layer 3Internal Network / Infrastructure Network segmentation, internal service exposure, system configuration, lateral movement paths
Layer 4Active Directory Identity management configuration, privilege escalation paths, access control over the organization's most sensitive assets

Scroll the table horizontally to see all columns.

What does a grey-box approach mean in this assessment?

Grey-box means the LOGIQUE team started with some information from the client — for example user-level credentials, high-level architecture documentation, or the list of in-scope assets — but still had to find the technical detail, exploitation paths, and configuration gaps itself through active discovery. The approach sits between black-box (no prior information at all, simulating a purely external attacker) and white-box (full access to source code and technical documentation).

For an organization whose ecosystem is as large and as complex as national critical infrastructure, grey-box usually strikes the best balance: more efficient in time and cost than a full black-box engagement, while still reflecting the reality that a real attacker often already holds an entry point or partial information — leaked credentials, an insider threat, exposed documentation — before launching a follow-on attack.

Why does a large-scale engagement need to be split into phases?

Given how broad the scope was, the engagement was split into two structured phases running over several weeks. That let each layer be tested at real depth rather than as a surface scan, and gave the client's team room to act on the first phase's findings in parallel, without waiting for the whole assessment to finish. For an organization with a large digital ecosystem, a phased approach like this helps protect testing quality while shortening the remediation cycle.

Why does Active Directory need to be tested as an integrated part, not a separate add-on?

Treating Active Directory as an integrated part of a single assessment cycle, rather than as a standalone add-on test, is one of the hallmarks of LOGIQUE's methodology. The reason is straightforward: AD is a critical point, because if that layer is compromised the impact can spread across the organization's entire environment no matter how well individual applications are secured.

By treating AD as part of the assessment rather than an add-on beside it, LOGIQUE validates the organization's resilience against chained attack scenarios, in which an attacker moves from one layer to the next. This is what separates an end-to-end assessment from standalone per-asset testing, and it is one of the main reasons organizations with complex infrastructure choose LOGIQUE's multi-layer approach.

Chained-attack validation works by simulating how an attacker who has gained limited access in one layer — for example through a standard user's credentials in a web application — then tries to widen that access into other layers, moving from application access to the internal network and finally attempting privilege escalation at the identity management level. Standalone per-asset testing often misses this risk: each layer can look “secure” on its own while a combination of small weaknesses across several layers opens a full attack path that would never surface if the layers were tested separately.

Frameworks and team certifications

The methodology follows industry frameworks (OWASP, PTES, NIST) and is carried out by a team with international certifications:

  • OSCP — Offensive Security Certified Professional
  • CEH Master — Certified Ethical Hacker Master
  • LPT Master — Licensed Penetration Tester Master

Results & Value for the Client

End-to-end visibility across layers

The client obtained a complete picture of its security posture, from applications through the network to identity management, within one consistent assessment framework rather than a set of disconnected reports.

A technical report with prioritized remediation

Each area for improvement is prioritized by risk level, so the client's internal team can allocate resources efficiently and start with what matters most.

Continued support through remediation

LOGIQUE does not stop at report handover; the team stays with the client throughout the fixes and runs a retest to validate that the remediation worked.

A foundation for compliance

The assessment results support compliance with information security standards such as ISO 27001 and Indonesia's Personal Data Protection Law (Law No. 27/2022), along with the cyber resilience regulations that apply to organizations in the energy sector and national critical infrastructure.

How does the retest process work?

After the initial report is handed over, the client's team carries out remediation in the recommended order of risk priority. LOGIQUE then runs a targeted retest of the remediated areas to verify that the fixes genuinely close the gaps that were found. This step matters because remediation that is never re-validated risks leaving a gap that is closed on paper but still exploitable with a slightly different technique.

Client Testimonial

The LOGIQUE team showed a clear understanding of how complex our infrastructure is as a national energy provider. The assessment was well coordinated and did not disrupt our operations, and the report we received was clear and actionable for our internal team to act on.

IT Security Manager, a national-scale organization in the energy sector

Why LOGIQUE

  • Familiar with the national critical infrastructure context — we understand the resilience standards, coordination, and confidentiality that energy-sector organizations and their peers require.
  • Multi-layer capability in one team — Web, Mobile, Network, and Active Directory are handled in an integrated way, not subcontracted to different parties.
  • Able to run large-scale engagements — phased planning that protects testing depth without disrupting the client's operations.
  • Support until remediation is validated — including a retest, not just a report handover.
  • Confidentiality as a working standard — all processes and client data are handled under strict confidentiality protocols, including in published work such as this case study.

CONTACT LOGIQUE

How secure are your systems and applications right now?

LOGIQUE delivers penetration testing entirely in-house with a certified team (OSCP, CEH Master, LPT Master), so your data stays confidential.

You get a clear, actionable report, with support that continues until remediation is validated.

Ready to start, or want to learn more first?

Request a sample report or a proposal tailored to your needs. No commitment required.