Showing posts with label penetration test. Show all posts
Showing posts with label penetration test. Show all posts

Monday, October 31, 2016

The Free Cyber Security Benchmark, increasing awareness of vulnerability for UK organisations

UK Government has been working to increase awareness of Cyber Security threats to organisations for years. It should be obvious why, almost 80% of UK GDP is services, and a significant portion of the non-services-based economy is just as dependant on intellectual property. While physical property, plant and equipment is difficult to steal or damage, most intellectual property is stored on computers and can be corrupted or stolen silently in a instant.

Back in 2013 the government announced a free cyber governance health check for the UK’s largest (FTSE350) firms. Large firms are important, but SMEs make up 50% of the economy by turnover and are among the most vulnerable to cyber attack, generally lacking dedicated teams of Information Security analysts or the apparatus to detect, repel, or analyse attacks.

To help these smaller organisations, and in concert with the UK Government Cyber Essentials scheme, 360is are announcing a Cyber Security Benchmark (CSB). Like the Government FTSE350 health check, the CSB is free of charge to qualifying organisations. It is designed to help medium sized companies. At the moment 360is is the only company providing this service.

The CSB will make you aware of the prevalence and seriousness of vulnerabilities in your Internet-facing infrastructure by providing you with a straightforward 1-page report all about you and your IT. You can then use that report to improve your cyber security posture and reduce the chances of you becoming one of the  organisations suffering from a breach this year. 

How To Obtain Your Free Cyber Security Benchmark
  • Take a look at the sample report for a fictional company and decide if it would be of use to you.
  • Complete the questionnaire and submit it to info@360is.com, a scan or picture of the completed form will do, don't forget to sign it.
  • We will verify that you are authorised to permit the assessment and that your organisation qualifies for the scheme.
  • Agree to the legal terms and conditions and await your results, they won’t take long.

The active phase of the exercise is non-disruptive and will not impact your IT operations.

Limitations

The CSB is not a full penetration test or vulnerability assessment and it is not a substitute for one. While accurate and evidence-based, the report is only a brief summary. The focus is on awareness, rather than the range of remediation activities. Once you are aware of the size and scale of your organisations vulnerability, you can take the next step in investigating, assessing, mitigating, and managing it. If you already know you need assistance with cyber security then get in touch

Tuesday, May 08, 2012

360is Guide to Understanding, Commissioning, & Maximising Value from Penetration Testing or Security Assessments

-->

Clients often contact us while weighing up the value of getting a Security Assessment or Penetration Test. Whether it's a recent breach, compliance obligation, the regulator, or auditors that trigger the inquiry, we find ourselves repeating similar advice during those initial conversations. Their questions may be familiar to you;
  • What exactly is a Penetration Test?
  • Is it any different from a “scan” or a “vulnerability assessment”?
  • What will it really do for us?
  • What do we do with the results?
  • How do I evaluate different companies offering this service?
  • Why can’t I get a consistent budgetary cost from the market?
We've recorded the answers to these questions and more in one place, using consistent language,  in a way that can be understood by both IT and non-IT professionals alike. Whether you are a systems administrator, or a CSO (more likely in the UK, IT Director/Manager) you will be able to use this guide to reduce the time taken to protect your assets, meet your business needs, and keep the customer/auditor/regulator/boss happy.
Aren’t there already countless guides, papers, and articles on Penetration Testing and security? Certainly. However, most of them are years old, focused on (or written from) a non-UK perspective, or are difficult for non-technical readers to understand. Our guide is different.
-->
  • UK & European perspective: While you can find an abundance of articles discussing Penetration Testing within the context of HIPAA, SOX, and FISMA, scarcely a nod is given to UK and European regulations and standards. Hackers may not respect geography, but your organisation still has to.
  • Up to date: While technical details of vulnerabilities have changed, sysadmins, programmers, and engineers are still making many of the same mistakes now as when we did our first assessment in the mid 90s. However, language changes, an organisation’s view of IT changes, as do end-user working practices. This document reflects that, taking a contemporary view of the subject.
  • Non-technical: Couched in ordinary terms the business can understand, this guide avoids much of the technical jargon that makes other articles heavy-reading for those whom IT security is not their full time occupation. While the skills employed may be highly technical, we can’t lose sight of the business problems being solved.
-->
We hope this guide will help many of our clients and future clients get the most from a Security Assessment/Penetration test (whether provided by 360is, our contemporaries, or your own IT security team):

Penetration Testing Guide, Part 1.
An Introduction to Penetration Testing. [PDF]
Penetration Testing Guide, Part 2.
Selecting A Penetration Testing Company. [PDF]
Penetration Testing Guide, Part 3.
Maximising Value From A Penetration Test. [PDF]
The Consolidated Penetration Testing Guide.
Parts 1,2, and 3 all in one document. [PDF]
Parts 1,2, and 3, text only, academic, no commentary. [PDF]

There will always be something missing from such a document; specific relevance to your particular situation. Get in touch to complete the picture. 360is is a company where you can talk to a client account manager who can get a consultant on the phone, without prior arrangement and without running the meter. Contact Us.

-----------------------------
 Update 24-05-2012
-----------------------------

For further information on 360is Penetration Testing Services, bookmark our Penetration Testing Homepage.

Monday, June 01, 2009

Security Assessment & Penetration Testing Case Study

360is has been operating since 2002, our consultants have been advising UK companies since the early 90's. Over the years we've been asked many times for case studies on Security Assessments, Penetration Tests, and Post Incident Investigations. Up to now we have always resisted, for reasons of customer confidentiality and because most of our clients are still referred to us by word of mouth.

We are pleased to announce the first of several Security Services case studies. While based upon a real engagement, some details have been changed to ensure confidentiality and each case may draw upon information from more than one project.


Can you see anything of your current situation reflected in these stories?
Are the benefits gained by our clients interesting to you?
Have you thought about the ways we can help you this year?