Ivanti Connect Secure Penetration Testing
Connect Secure’s admin roles, realms and resource policies decide who reaches your network. We test that configuration directly, from role mapping to Host Checker enforcement and the console. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
An authentication realm is Connect Secure’s binding of an authentication server, a directory server, an authentication policy and role mapping rules into the one decision that grants a session its role.
Why Connect Secure risk concentrates on realms, roles and the console you can reach
An authentication realm ties together an authentication server, an optional directory server, an authentication policy and role mapping rules, and Ivanti’s own authentication realms documentation defines role mapping rules as conditions evaluated against username, user attribute, certificate attribute, group membership or a custom expression. We test how each realm is wired and which condition actually decides a user’s role, not what the deployment diagram assumed.
Connect Secure separates super administrators, who hold the .Administrators role and full control through the admin console, from read-only administrators and any number of custom system or security administrator roles scoped to specific realms, resource policies and pages. We test whether every admin account, including ones created for a single project, still holds only the access that role needs.
Host Checker runs its endpoint posture checks, predefined signatures alongside any custom rules you define, at either the role or the realm level before a session is granted access, and resource policies then decide what an authenticated session can actually reach. We confirm the Connect Secure release actually running against Ivanti’s current administration guidance during scoping, the same configuration-hygiene check we run on every appliance in this scope.
SCOPE
What we pen test on an Ivanti Connect Secure device
Administrator Roles and Delegated Permissions
Connect Secure separates super administrators, who hold the .Administrators role and full control, from read-only administrators and any number of custom system or security administrator roles scoped to specific realms and resource policies. We test whether every admin account holds only the role its job actually needs.
Authentication Realms and AAA Servers
An authentication realm ties an authentication server, an optional directory server and an authentication policy together, and Connect Secure supports local, LDAP, RADIUS, Active Directory, SAML and certificate-based AAA servers. We test how each realm is wired to its servers and whether the authentication policy in front of it matches what the realm is meant to protect.
Role Mapping Rules
Role mapping rules decide which user role a session receives, evaluated against username, user attribute, certificate attribute, group membership or a custom expression drawn from the realm’s directory server. We test every rule’s conditions and evaluation order, since role mapping is what turns a verified identity into a set of resource permissions.
Sign-In Policies for Users and Administrators
Connect Secure runs two separate types of sign-in policy, one for users and one for administrators, each binding a URL and a sign-in page to one or more realms, so an administrator URL such as */admin can sit alongside ordinary user URLs on the same device. We test which realms and pages every configured URL actually resolves to, including wildcard entries.
Host Checker Endpoint Posture Policies
Host Checker is Connect Secure’s client-side agent, checking predefined signatures such as antivirus, antispyware, OS version and disk encryption status alongside any custom rules you define, and it can be invoked at either the role or the realm level. We test which roles and realms actually enforce a Host Checker policy and what happens to a session when a check fails.
Resource Policies and Access Control
Web, file, Secure Application Manager, Terminal Services and VPN Tunneling resource policies each define which resources a role can reach, evaluated in order until the first match, and a fresh installation ships its initial web and file access policies in a Deny state by default. We test whether that default-deny posture has been preserved or loosened as policies were added.
Admin Web Console vs Serial Port Console
Alongside the browser-based admin console, Connect Secure exposes a serial port console for initial setup and recovery, from which an administrator can create a new super administrator account, view access logs, or trigger a factory reset, and the console itself can be password-protected so that only super administrators can use it. We test whether that password protection is enabled and whether admin sign-in is restricted to the ports it needs.
Delegated Administrator Restrictions
The system blocks delegated administrator roles from writing to pages that could let them change their own privileges, such as Import/Export, Push Config and Local Backups, reserving those to the built-in Administrators and Read-Only Administrators roles. We test every delegated role against that boundary to confirm no custom role has been granted access it should not have.
Admin Access Session Logging
The Admin Access log records every administrator sign-in, sign-out, licence change and configuration change, separately from the User Access log, though the local viewer displays only the most recent 5,000 entries. We test whether Admin Access logging is enabled and forwarded to a syslog server before that local display limit rolls entries off.
Supported Version and Advisory Risk
Ivanti publishes administration guides and security advisories against specific Connect Secure releases, and a device running outside that supported version range stops receiving the fixes those advisories assume are already applied. We confirm the release actually running against Ivanti’s current guidance during scoping, the same check we run on any other device in this scope.
OUR PROCESS
Ivanti Connect Secure Penetration Testing: From Scope to Attestation
Scope and Access
We agree the realms, admin roles and resource policies in scope, plus admin accounts across every role type you use.
Configuration and Realm Mapping
We map every realm’s authentication and role mapping setup, resource policies, Host Checker enforcement and the ports admin sign-in is allowed on.
Manual Testing
A CREST-certified tester manually tests role boundaries, sign-in policies, resource policy enforcement and Host Checker behaviour by hand.
Attestation and Retest
You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Ivanti Connect Secure pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Ivanti Connect Secure Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Ivanti Connect Secure For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Ivanti Connect Secure Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Ivanti Connect Secure device?
We need admin accounts across the role types you use, including at least one with the .Administrators role, so we can compare what every account can actually do against what its role should allow. Read-only or delegated accounts are useful too, since testing role boundaries needs an account on each side of them.
How long does an Ivanti Connect Secure penetration test take?
A single appliance sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff.
Does the test touch live user traffic, or could it disrupt remote access?
Configuration review, admin console testing and resource policy checks run without needing to intercept live VPN sessions. Where we do test authenticated user paths, such as Host Checker enforcement or role mapping, we agree test accounts and a testing window with you first so genuine remote-access users are not affected.
Do you test a high-availability cluster pair or just one appliance?
Our single-device scope covers one Connect Secure instance. Ivanti’s own clustering documentation recommends standalone nodes or a maximum of two-node clusters behind a load balancer, so where you run an active/active or active/passive cluster pair we scope both nodes, since configuration can drift between them.
What’s out of scope for an Ivanti Connect Secure engagement?
We do not run denial-of-service or resiliency testing against the appliance, and we do not test backend systems reachable only after Host Checker or role mapping grants access unless you add them to scope. Anything beyond the Connect Secure device itself, such as the identity provider behind an authentication realm, is scoped as a separate engagement.
Does Ivanti have a customer penetration-testing policy we need to follow?
Ivanti’s Vulnerability Disclosure Policy covers researchers reporting issues in Ivanti’s own products and infrastructure, and it explicitly excludes testing an Ivanti product hosted by a customer on the customer’s own network without prior approval, which is the deployment model most Connect Secure appliances use. We confirm current terms for your specific licence and deployment during scoping.
Can Host Checker and resource policy testing lock out real users?
We test Host Checker rules and resource policy behaviour using accounts and roles agreed with you in advance, rather than roles carrying live user sessions. Any change we make during testing is reverted, and we agree a rollback point with you before altering realm or role configuration.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Ivanti Connect Secure device
Connect Secure’s admin roles, realms and resource policies decide who reaches your network. We test that configuration directly, from role mapping to Host Checker enforcement and the console. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.



