Home / Work / Orbital

Pentest · Orbital · 2024

Zero-trust across 14,000 endpoints in 30 days.

A global fleet with no unified identity layer and flat internal trust. We designed the rollout, hardened every device class, and verified the result by attacking it ourselves.

The challenge

14,000 doors, one key under the mat.

Orbital’s fleet had grown by acquisition: five device-management regimes, inconsistent disk encryption, and service accounts with standing domain-admin rights. Our initial assessment showed that compromising any single laptop could reach production data within four hops.

The board wanted zero-trust — but without halting a company that ships daily.

Engineer enrolling hardened endpoint devices during the fleet rollout
FLEET HARDENING — STAGED BY DEVICE CLASS

Approach

Roll out in waves, verify by attack.

Identity

Unified identity first

Phishing-resistant MFA and short-lived credentials replaced standing privileges — service accounts included — before a single agent was deployed.

Segment

Micro-segmentation in waves

Device classes moved in staged waves with automatic rollback triggers. Four hops to production became zero routable paths.

Prove

Adversarial acceptance test

We re-ran the original four-hop attack path against the finished estate. It died at the first device — exactly as designed.

OKEndpoints
1%Surface cut
30dTo rollout
Solo verification pass re-testing controls across the hardened estate
ADVERSARIAL VERIFICATION — RE-TESTING EVERY CONTROL

Outcome

96% less surface. Zero downtime.

“They think three moves ahead of any attacker we’ve faced. Our detection got faster and my team got their weekends back.”

— Marcus Hale, VP Security, Orbital

StackCobalt StrikeSuricata

How many hops to your production data?

More work: 47-second containment · Verdant hospitals

Assess Your Attack Paths