Cyber security

System security assessments (internal and external)

We independently assess the security posture of your information systems, identify the key risks and provide recommendations for improving the resilience of your environment.

System security assessments — a server under a magnifying glass

External security assessment

By simulating attacks we test how resilient your external infrastructure is against hackers. The assessment is carried out from our own location, usually using a black box methodology — we know nothing about the infrastructure in advance and obtain all information ourselves during the engagement, which comes closest to a real attack scenario. An external security assessment can cover:

  • Websites and web applications
  • The security configuration of the mail server and its resistance to unsolicited email (spam)
  • Remote access security controls
  • External server infrastructure
  • DNS servers
  • Other services exposed to the internet
External security assessment — simulated attacks from the internet against web, mail, VPN, DNS and API servers, plus OSINT analysis

Once the assessment is complete you receive a detailed technical report describing every vulnerability found, its criticality rating (CVSS), proof of successful exploitation, an assessment of the business risk and clear remediation recommendations. We also present the findings at a closing meeting, where we go through the results together, answer questions and propose remediation priorities. After the vulnerabilities have been fixed we can, by agreement, carry out a re-test to confirm that the measures have been effective.

Open source intelligence review (OSINT)

As part of an external security assessment we also carry out an open source intelligence review (OSINT). Its purpose is to establish what information about your company is publicly available and could be used by attackers to prepare or carry out a cyber attack.

The review covers public sources, search engines, archives, publicly accessible databases and the dark web, looking for information that could represent a security risk or reveal details about your information environment.

In particular, we look for:

  • subdomains, publicly accessible servers and exposed services,
  • exposed applications and development environments,
  • leaked usernames, passwords and other credentials,
  • employee email addresses and any misuse of identities,
  • DNS records, certificates and other technical information about the infrastructure,
  • publicly published configurations, backups, source code repositories and other unintentionally exposed data,
  • any other sensitive information that we can reasonably conclude was not intended for publication.

Based on the findings we produce an overview of the exposed information, assess the associated security risk and give concrete recommendations for reducing your digital exposure and preventing misuse.

Internal security assessment

Internal security assessments are carried out at the client's premises or, by agreement, over a secure VPN connection. The aim is to establish how resilient your internal ICT infrastructure is to attacks originating inside the network and how effectively your security controls work. We simulate attack scenarios that could be carried out by an intruder who has already breached the network or by a user with legitimate access to internal resources.

We examine the scope for lateral movement across the network, privilege escalation, access to sensitive data and takeover of business-critical systems. Where appropriate we also simulate the consequences of a malware infection (ransomware, trojans and similar) and evaluate how effective your existing defences are.

An internal security assessment can include:

  • a review of wireless network security controls (employee and guest networks),
  • a review of security controls within the internal network,
  • testing the consequences of a malware attack,
  • simulated privilege escalation and takeover of business-critical servers,
  • verification of network segmentation and access paths between systems,
  • automated scanning of the environment with licensed vulnerability discovery tools,
  • a configuration review of workstations, servers and network devices,
  • a detailed review of the Active Directory environment and domain controllers,
  • anything else agreed with the client.
Internal security assessment — reviewing the internal network: Active Directory, servers, VLAN segmentation, workstations and analysis with reporting

When the assessment is complete you receive a detailed report describing the vulnerabilities found, their criticality, proof of successful exploitation and concrete remediation recommendations. We also present the results at a closing meeting, where we agree remediation priorities and, if required, carry out a re-test once the measures have been implemented.

Methodology — from black box to white box

We tailor penetration testing to the objectives of the engagement and the level of collaboration with the client. Depending on how much information is available before testing begins, we use black box, grey box and white box methodologies.

We usually begin with the black box approach, in which we have no prior knowledge of the information environment. This simulates a realistic scenario in which an external attacker has to gather all the information themselves.

The assessment can then be extended using the grey box approach, where the client provides basic information about the infrastructure and a user account with ordinary privileges. This makes it possible to examine internal security controls and business applications in much greater depth.

For a detailed review of configurations and security settings we also carry out white box testing, where we have full visibility of the infrastructure or administrative access. This work is done in close cooperation with the client and is designed to uncover configuration weaknesses that conventional penetration testing cannot detect.

A white box review can include:

  • configuration review and hardening recommendations for Linux servers,
  • configuration review and hardening recommendations for Windows servers,
  • a review of Active Directory security settings,
  • a review of the DNS infrastructure,
  • a review of Docker and other container environments,
  • a configuration review of selected server services and applications,
  • a review of the operating system security configuration.

Specialised assessments of SCADA, ICS and IoT environments

Alongside conventional IT infrastructure we also carry out specialised security assessments of SCADA, ICS and IoT environments, where a cyber incident can disrupt production, critical infrastructure and other physical processes. These environments call for a different approach from standard information systems, because uninterrupted operation matters just as much as security.

We use methodologies adapted to industrial environments, taking particular care not to affect system availability. We review device configurations, communication protocols, network segmentation, access management and other controls that reduce the risk of unauthorised access or operational disruption.

On completion we produce a detailed report setting out the vulnerabilities found, a risk assessment and concrete recommendations for improving the security and resilience of your SCADA and IoT environment.

Important
  • Our goal in a project is not merely to run a security assessment, simulate an attack and hand over a report, but to improve the security and resilience of your ICT environment.
  • On any project we can, if you wish, work together with your SOC team, measure how effectively your security controls detect activity, and prepare recommendations for improving the detection of attack techniques.
  • All security assessments and penetration tests are agreed in advance in terms of both schedule and methodology, and are carried out in a controlled, previously agreed manner.
Interested in this service?

We would be glad to discuss your needs

Contact us