Network Vulnerability Assessment

Cover image for Network Vulnerability Assessment
Infrastructure & Operations

286 unique vulnerabilities identified across 94 internal assets; 31 high-severity findings concentrated in unmanaged net…

Network Vulnerability Assessment

Retail and Distribution · North America

Firewall rule review identified 14 overly permissive inter-VLAN rules, including unrestricted access from the guest Wi-Fi segment to internal POS systems.Remediation roadmap delivered and implemented in full within 60 days, directly addressing gaps identified during a prior PCI DSS pre-assessment.
Mar 30, 20262 min read

At a glance

Executive Summary

Project Details

Industry

Retail and Distribution

Region

North America

Services Provided

  • Internal Network Vulnerability Assessment
  • Asset Discovery
  • Patch Gap Analysis
  • Firewall Rule Review
  • Remediation Roadmap

Key Takeaways

  • Firewall rule review identified 14 overly permissive inter-VLAN rules, including unrestricted access from the guest Wi-Fi segment to internal POS systems.
  • Remediation roadmap delivered and implemented in full within 60 days, directly addressing gaps identified during a prior PCI DSS pre-assessment.

Overview

A retail and distribution company with six locations engaged Blue Orca Solutions to perform an internal network vulnerability assessment following an inconclusive PCI DSS pre-assessment that flagged network security gaps without providing a complete vulnerability inventory. Blue Orca conducted authenticated scanning across all sites, supplemented by firewall configuration review and manual validation of high-risk findings, delivering a prioritised remediation roadmap tied to PCI DSS requirements.

Key outcomes

60 days

286 vulnerabilities identified and risk-stratified; 31 high-severity…

60 days

Full remediation roadmap executed within ; client re-engaged PCI DSS…

60 days

Remediation roadmap delivered and implemented in full within , direct…

Deep dive

Case Narrative

Challenges

  • Network infrastructure across six sites had grown organically with no central asset inventory or patch management process in place.
  • POS systems at each location were on shared VLANs with general corporate traffic — isolation controls were inconsistently applied.
  • Unmanaged switches and access points at smaller locations had never been inventoried or assessed.
  • The IT team had a three-person headcount responsible for all six sites, limiting the capacity to absorb a complex remediation workload.

Our Approach

  • Multi-Site Asset DiscoveryBlue Orca deployed lightweight scanning agents at each location to perform asset discovery before the main assessment window. The resulting inventory identified 94 unique addressable assets across all six sites, including 22 devices not previously known to the IT team — primarily unmanaged switches, access points, and IoT-category devices.
  • Authenticated Vulnerability ScanningCredentialed scans were executed against all identified assets using service accounts with local administrator access on Windows endpoints and SSH credentials on network appliances where supported. Unmanaged devices without credential support were scanned using unauthenticated profiles with manual review of any findings.
  • Firewall Rule and Segmentation ReviewBlue Orca reviewed firewall rulesets across all six sites and assessed inter-VLAN routing policies. 14 overly permissive rules were identified, including a rule permitting unrestricted TCP access from the guest Wi-Fi VLAN to the POS network at three locations. Segmentation gaps were documented with specific rule change recommendations.
  • Prioritised Remediation RoadmapFindings were consolidated into a capacity-aware remediation roadmap structured for a three-person team. Phase 1 addressed the five firewall rule changes covering POS segmentation. Phase 2 covered critical patch deployment on managed endpoints. Phase 3 addressed unmanaged device replacement and access point firmware updates across all sites.

Results

  • 286 vulnerabilities identified and risk-stratified; 31 high-severity findings validated and addressed within 60 days.
  • Guest Wi-Fi to POS network access blocked at all three affected locations within five days of report delivery.
  • 14 firewall rule changes implemented, eliminating unnecessary inter-VLAN paths identified in the review.
  • Full remediation roadmap executed within 60 days; client re-engaged PCI DSS assessor with documented evidence of remediation.

Why Blue Orca Solutions?

Blue Orca delivered a comprehensive network vulnerability assessment that gave a multi-site retail operator clear visibility into their internal risk posture and a practical remediation path their lean IT team could execute within a defined timeframe.

Plan your next engagement

Ready to achieve similar outcomes?

Talk to Blue Orca about your priorities. We’ll map a delivery approach aligned to your goals, team capacity, and risk profile.

Continue reading

Related Case Studies