Our security assurance and testing services go way beyond a basic vulnerability scan. We work with you to understand your business context and the architecture of the service. We look at the threat landscape, your data flows, and assets to determine the best approach to assuring you have a strong security posture.
We test both from an external and from multiple internal positions to ensure you understand the current state position for risks both the service and its upstream and downstream interfaces.
We ensure the scope is reflective upon your risk landscape and threat profile. We tend to start with a wide view to ensure we do not miss something which later comes back to bite you.
We conduct external perimeter testing focusing on areas such as:
We do this using black, grey, and white box perspectives. We also strongly recommend using an assume breach mentality with regards to scoping and assessment.
Our internal baseline testing includes:
We do not believe in taking unnecessary risks, we therefore where possible attempt to assess a large breadth of an estate (we aim for ~90% coverage subject to requirements and conditions). In the cyber security world, it is the things you don’t know that tend to lead to incidents.
Our output reports are one element, however the key to success with these activities is to ensure your team understand the vulnerabilities, how they arrived in the environment and understand how identity, protect, detect, and respond to these. The aim here is to try and avoid vulnerabilities being introduced or re-introduced to the environment. We support this with a high communications approach.
© 2023 - All Rights Reserved - Designed by