|
One of the main assets of every modern company is its data. Data
represents the strategic information of any company, such as its
business plan, engineering development and know-how, accounting
data, personnel data and so on.
All this information is
confidential and only available to those who need it for the benefit
of the organisation.
In the information
era we live in, companies have all this
classified information on computers, which communicate on Internet
and on other networks.
It is essential that the network
must be secured so it won't allow intruders.
Knowing that a security incident
could endanger the existence of the company, decision makers should
invest time, money and energy in hiring the right people to secure
the gateway router, the servers and other network equipments.
No one could guarantee 100% that
the network administrator or the independent consultant has done his
job right, has installed all the patches, has secured all the
services, has harden the applications and so on. To protect your
network and data from a determined attack, you need a good assurance
and understanding that the security policy was properly implemented
as required.
A penetration test is the
process of evaluating the right implementation of the information
security measures. It guaranties that the security policy has been
applied and that the risk of security incidents is minimal.
That's why an independent
security audit becomes a MUST for any company, which wants to be
sure that its data is well protected.
It is also encouraged that this
independent security audit shall take place on a regular basis to
reflect the unscheduled things that have changed since the last one.
These tests are important for a company so that it doesn’t fall for
a sense of security when it doesn’t exist.
There is a number of ways we
could undertake the testing, but the most common procedure is that
the security measures are actively examined for design weaknesses,
implementation flaws and known vulnerabilities.
We will perform security audits
and security penetration tests in a controlled manner so that the
activity of your network is not affected.
We conduct the audit in one of
the two ways; black-box (with no prior knowledge of the
infrastructure that is tested – like any back-hat hacker would do)
or white-box (with complete knowledge of the infrastructure which is
tested – like any sustained attack conducted from the inside or from
the people who intentionally have targeted your company for a
specific reason).
Basically we:
-
Establish the parameter and
the boundaries
-
Choose the adequate set of
tests which fits exactly in your network design
-
Follow a methodology:
nothing is random, everything will be planned and documented
-
Present the results of the
security audit comprehensively in a report along with the
recommended measures to Executive, Management staff or the
person in charge.
The quality of the penetration
testing service that you will receive is the direct result of the
quality of the consultants that will be supplied for the project. We
can provide you a well-conducted penetration test that not only will
show the vulnerabilities in your network, but will also help you to
determine whether your operational practices, equipment, and
policies are up to their task. We can offer advice on how to secure
your network or individual servers and PC's against any type of risk
and ensure your data is safe from prying eyes.
|