Pen Testing: What and Why

Pen Testing: What and Why

“I’m just a keystroke away from downloading their entire database,” said the experienced hacker! Fortunately, this was an ethical hacker - an expert penetration tester in my company performing an authorized test commissioned by a client, while carefully documenting the results to present to said client.

Clearly stated, a penetration test is a real-world, simulated attack. - Greg Johnson, CEO Webcheck Security

Unfortunately, there are plenty of bad actors who would download the “entire database” and sell or post the contents on the Dark Web or to other bad actors. Performing penetration tests is an excellent way to determine how vulnerable your systems, applications, and organizational assets are. In fact, although cyber security is truly multi-layered and multi-faceted, frequent penetration testing is a quick way to really understand what I would call infrastructural blind spots.

Clients will often call and say “I want a penetration test. “ I always make it a point to ensure we’re on the same page by ascertaining whether the client wants a mere vulnerability or web app scan, or a proper penetration test. So how would you define the differences?

Clearly stated, a penetration test is a real-world, simulated attack performed by certified and qualified engineers, using both automated and manual attack techniques. They professionally find and appropriately exploit all vulnerable attack vectors until they have exploited them all, and professionally document all findings with clear remediation advisement including multiple screen shots.

The book from CRC Press, when available will share many “scrubbed” but real scenarios and the vulnerabilities that led to the findings, including tools, methodologies and conclusions.

For the real takeaways, conclusions and “meat” surrounding the chapter on penetration testing and other contributions, stay tuned! The book should be out and available by May-June of this year.

Until then, I leave you with this: annual or semi-annual penetration testing is a small price to pay compared to the potential $3.9 million average data breach cost (IBM in conjunction with the Ponemon Institute https://databreachcalculator.mybluemix.net/)

Jim Carwile

VC / Venture Development

5 年

Looking forward to it Greg!!

回复

要查看或添加评论,请登录

Greg Johnson, PCIP的更多文章

  • Guidance on the Recent Nation State Attack

    Guidance on the Recent Nation State Attack

    Webcheck Security has access to several Ex-NSA analysts in its managed threat hunting department. The following advice…

  • Rise of the FISO

    Rise of the FISO

    In today’s business landscape, catalyzed by the COVID19 pandemic, there is a lot of uncertainty to wade through. One of…

  • 3 Qualities of Excellent Pen Testers

    3 Qualities of Excellent Pen Testers

    The team of penetration testers I work with is excellent. One in particular has three qualities which I believe are…

  • Don't Play Roulette With Your Web App

    Don't Play Roulette With Your Web App

    Yesterday I spoke to a gentleman responsible for all things IT in his organization. During the conversation, he…

  • Silver Bullets and Cyber Security

    Silver Bullets and Cyber Security

    The phrase “silver bullet” relates to an all-encompassing or even miraculous solution to a problem or challenge. In the…

    7 条评论
  • What is Cyber Security?

    What is Cyber Security?

    Would you agree that in many companies, security is vendor-driven? If I've done my research and can show to the C-Level…

    3 条评论
  • Book Review - Why CISOs Fail

    Book Review - Why CISOs Fail

    What is a CISO? Why do so many fail? What qualifications should the CISO have? Why do organizations fail to hire the…

  • The Equifax Breach - Policy Not Vulnerability?

    The Equifax Breach - Policy Not Vulnerability?

    The recent Equifax breach was not a failure by vulnerability, but a failure of policy. Technically, evidence suggests…

    7 条评论
  • 3 Security and Commerce Trends that will Continue in 2017

    3 Security and Commerce Trends that will Continue in 2017

    With the ushering in of another new year I find myself acting nostalgic, wondering where the previous year went and of…

  • Visa Global Registry of Service Providers: Are you on the list?

    Visa Global Registry of Service Providers: Are you on the list?

    Visa has released new tools and changes, which add value to service providers who store, process, or transmit…

    3 条评论

社区洞察

其他会员也浏览了