NET9 finding classesNetwork
What can be reached, and from where?
The Network domain covers reachability: which services are exposed, to which networks, and what sits between an untrusted packet and a sensitive system. Most Tier 1 findings are network findings in disguise — a vulnerable service that nothing can route to is a very different problem from the same service on a public IP.
What this domain covers
- Internet and partner-network service exposure
- Firewall, security group, and network ACL configuration
- Segmentation between trust zones and regulated environments
- Ingress and egress filtering
- Network telemetry, flow logging, and intrusion detection coverage
Distribution across tiers
Typically owned by Network engineering / cloud platform.
BCN-T1-NET-00124 hoursInternet-Exposed Remote Administration Services
SSH, RDP, SMB, or equivalent management protocols reachable from the public internet.
BCN-T1-NET-00224 hoursPublicly Accessible Storage and Data Services
Object storage, file shares, or managed data services readable without authentication from the internet.
BCN-T1-NET-00372 hoursNo Segmentation Between Trust Zones
A compromise of any low-value host grants unrestricted network reachability to critical systems.
BCN-T2-NET-00130 daysRegulated Environment Segmentation Gaps
Insufficient isolation around a cardholder, health, or otherwise regulated data environment.
BCN-T2-NET-00230 daysInsufficient Logging and Retention
Security-relevant events are not captured, not centralised, or not retained for the required period.
BCN-T2-NET-00330 daysMissing Intrusion Detection Coverage
No detection capability at network boundaries or across critical segments.
BCN-T3-NET-00190 daysNon-Critical Service Exposure
Unnecessary services reachable on internal networks, expanding attack surface without immediate risk.
BCN-T3-NET-00290 daysCloud Network Hardening Gaps
Cloud network configuration diverging from CIS Benchmark or provider best practice.
BCN-T3-NET-00390 daysIncomplete Egress Filtering
Unrestricted outbound connectivity, permitting unconstrained command-and-control and exfiltration.