Checking the lock on your front door once a year is not enough............

Checking the lock on your front door once a year is not enough............

When trying to explain the difference between intrusive, yet highly important, Penetration Testing and regular scanning services to colleagues, friends or even family I find the best way to do so is by using a 'House' analogy!

Having a yearly Penetration Test is highly important should you rely on critical internal & external facing assets to ensure you identify all areas of vulnerability and then mitigate the relevant threats. You most definitely need to ensure the resilience of your security controls and identify all the ways that an attacker might gain unauthorised access to these key assets. This, in my example, is the checking of your lock(s) to stop any unauthorised access to your 'house'. 

Doing this (PT) more than once a year though is costly, but does that mean you shouldn't regularly check the rest of your 'house' to ensure vulnerabilities are not exposed to any risk? 

If you have expensive items in your lounge, or Kitchen, or even cash stowed away under a bed (this is not me by the way for those wondering) then you complete checks of your 'house' to makesure everything is as it should be, and this is what regular scanning is on your own external and internal infrastructure. 

You need to asses your key assets for potential vulnerabilities and where required put in place effective means to manage and monitor the vulnerability risks associated with external and internet facing infrastructure on a more regular basis than standard infrastructure penetration testing.

A Managed Security Service (regular managed scanning if you wish) simply supplements the comprehensive penetration testing you are already receiving, and would consist of daily infrastructure delta scanning coupled with monthly, quarterly or adhoc automated vulnerability assessments. A regular status report would be provided with all identified vulnerabilities assigned a risk rating of high, medium or low depending on the level of assessed threat.

Regular scanning just keeps your 'house' in order in between your more intrusive yearly Pen Tests! 

要查看或添加评论,请登录

Jonny Hyde的更多文章

  • PRA Regulations - Deadline incoming!

    PRA Regulations - Deadline incoming!

    PRA’s Outsourcing and Third-Party Risk Management (PRA SS2/21) In March 2021, the PRA published a Policy Statement on…

  • IP Lawyers - Escrow & COVID-19

    IP Lawyers - Escrow & COVID-19

    As we continue to ride out the COVID-19 pandemic, companies continue to prepare for the unexpected. The impact on our…

  • Escrow Responsibilities

    Escrow Responsibilities

    Over the years, I’ve been involved in a vast number of software escrow agreements. The purpose of an escrow agreement…

  • Ch-Ch-Ch-Changes......

    Ch-Ch-Ch-Changes......

    No business is immune to change, whether planned or unplanned, or driven by internal or external factors. Computing and…

  • To do it or not to do it?

    To do it or not to do it?

    All Sales, operations, admin, managers, secretaries, directors, business people..

  • Cloud or not to Cloud???

    Cloud or not to Cloud???

    On premises or cloud backup? Why it should never be an either/or decision You don’t get forced into either cloud or…

    2 条评论
  • Cyber Security improving within FTSE350 companies - but is it on top of everyone's agenda?

    Cyber Security improving within FTSE350 companies - but is it on top of everyone's agenda?

    Cyber security management improving at FTSE companies FTSE companies are showing a greater understanding of the risks…

  • Gone Phishing..........

    Gone Phishing..........

    UK businesses face increased number of phishing attacks in 2016. More attacks are focused on companies in the UK than…

    2 条评论
  • MoD contractors must comply with Cyber Essentials............

    MoD contractors must comply with Cyber Essentials............

    All Ministry of Defence (MoD) contractors must now comply with Cyber Essentials. All MoD procurement, suppliers and…

  • Are you prepared for the inevitable?

    Are you prepared for the inevitable?

    In 2014, 81 percent of organisations in the UK reported a cyber-security breach. So far this year, 40 percent of public…

社区洞察

其他会员也浏览了