Skip to content
Safestorm
Menu

Specialist / enquire

IPv6 Security Assessments

Specialist assessment of unmanaged dual-stack exposure, local-network trust and monitoring gaps.

IPv6 is frequently active in networks described as IPv4-first. An IPv6 security assessment establishes where the protocol is present, whether filtering and hardening are consistent across both control planes, and whether alternative address, discovery or routing behaviour creates an unexpected attack path.

Founder-led technical delivery

Why Safestorm for this assessment

IPv6 is a defined area of Felix’s technical research. At BSides London 2025, he presented on risks created by under-monitored IPv6 in corporate networks. Safestorm applies that research through controlled discovery and validation rather than assuming the protocol is absent.

  • More than six years’ offensive-security experience
  • OSCP and OSEP certified
  • Red teaming, adversary simulation and control validation
  • Published IPv6 research presented at BSides London

Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.

What the assessment covers

Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.

  • IPv6 discovery, addressing, routing and asset visibility
  • Firewall and segmentation parity between IPv4 and IPv6
  • Router Advertisement and Neighbor Discovery trust assumptions
  • Name-resolution and identity interactions in dual-stack networks
  • Endpoint hardening, logging and monitoring coverage

Common risks identified

Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.

  • Preventative controls that can be bypassed by realistic attacker behaviour
  • Security activity that is not visible to the expected monitoring controls
  • Response procedures that do not operate as expected under test conditions

A controlled process

How the engagement works

  1. Step 1

    Define objectives, threat assumptions and success criteria

  2. Step 2

    Design scenarios, safeguards and rules of engagement

  3. Step 3

    Prepare stakeholders, communications and stop conditions

  4. Step 4

    Perform controlled testing and collect proportionate evidence

  5. Step 5

    Analyse control performance, visibility and response

  6. Step 6

    Debrief stakeholders, prioritise improvements and verify agreed changes

Who this service is suitable for

  • Organisations with a defined assurance objective and authorised scope
  • Security teams seeking focused validation beyond a conventional penetration test

Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.

Methodology and industry references

Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.

Referencing a framework does not represent certification against it or guarantee compliance with every control.

Frequently asked questions

How is the engagement scoped?

Safestorm begins with an objectives workshop and prepares a tailored proposal and rules of engagement. No assumptions are made about techniques, targets or operational risk.

Is a fixed price available?

A quote follows scope definition. Specialist requirements vary materially, so the proposal reflects the agreed scenario, duration and safety requirements.

Define the right scope

Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.

Discuss your requirements