..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Network Vulnerability Testing

commissum Managed Security services allow us to free up your resources and lighten your workload with our first-class range of management services. These include our outsourced CISO offering, Managing your alignment to ISO27001, helping you to manage critical Business Continuity, and at a more technical level, regular managed testing of your network, applications, and blended code review.

Vulnerability Assessment

commissum's monthly managed vulnerability assessment ensures continued network security.

With about eight thousand vulnerabilities being discovered in commercial software annually, can you really afford to wait twelve months between penetration tests? While most vulnerabilities will not affect your organisation’s infrastructure, even if one percent impacts upon your environment, you could be exposed to twenty a quarter or almost seven per month on average.

Our managed monthly scanning is designed to complement full penetration testing, once this CREST level of detailed testing has established the impact of exploiting a vulnerability and breaching you defences.

By way of analogy

If your son comes in from the pub at two in the morning and leaves his keys in the door, that is a vulnerability. A vulnerability scan will find and report this, and will offer suggestions for mitigation such as "Remove his keys – but you need to get up at two in the morning to let him in", "Install a swipe card system" or even "Kick him out of the house!"

A penetration tester, on the other hand, would go up to the door and turn the keys and handle, only to find your son had been sober enough to bolt the door from the inside; ie the "high" risk presented by the vulnerability has been mitigated. The tester would then take the keys and try the back door, and identify that the keys for his car are also on the key-ring, exposing this asset to theft. In other words, the vulnerabilities are assessed for potential exploitation to determine the true business impact and not just the theoretical vulnerabilities.

Our Monthly Managed Service is designed to follow on after the full penetration test has established the impact (the stolen car), and will check that the underlying vulnerability is mitigated. In the analogy above, it would show every month whether the keys were still in the door or had been removed (i.e. mitigated). It would also indicate if they returned after a period of absence. This perhaps corresponds to notification of a server that has been restored from backup and not subsequently patched, which would equate to an episode of binge drinking in the analogy.

Overall, the Managed Scanning Service is the equivalent of a security guard regularly checking that all is well. A recent example of a successful outcome using a managed service provider was the exposure of data records that had not been exposed by the penetration test, but which appeared only after a firewall upgrade. The security scanning service discovered them, and the issue was quickly resolved before the public became aware of it.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
“We have used commissum for several years and their work has always been professional and delivered to a high standard. We appreciate their ability to readily interpret project requirements and to make a valuable contribution even when a project's budget is tight. commissum are easy to deal with and have the flexibility to manage changing time scales and requirements.”

Mr Iain R, Account Director, International Business Systems & Managed Services Company

Latest News

Alleged Chinese Government Hacking Department back in action

Alleged Chinese Government Hacking Department back in action

Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...
Tue 21 May, 2013 // Martin
cyber-war

Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years

A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...
Wed 08 May, 2013 // Briony
cyber-tanks

Suspected hacker arrested after “biggest-ever DDoS attack”

Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...
Tue 30 Apr, 2013 // Briony