..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Application Vulnerability Assessment

commissum Managed Security services allow us to free up your resources and lighten your workload with our first-class range of management services. These include our outsourced CISO offering, Managing your alignment to ISO27001, helping you to manage critical Business Continuity, and at a more technical level, regular managed testing of your network, applications, and blended code review.

Web Application Scanning

Next generation external application testing can safeguard your website from potential threats.

commissum is delighted to offer next-generation web application vulnerability scanning as a blended managed service, incorporating an automated vulnerability assessment with manual review by experienced consultants to offer unprecedented accuracy and comprehensiveness.

While not as detailed as a full-blown web application test, the blended assessment offers an extremely cost-effective way to assess a large number of web-facing applications. In an ideal world, this is used to prioritise those applications requiring a full application security review and, when run on a regular basis, typically offers an equivalent level of assurance for applications as our Monthly Vulnerability Assessment does for infrastructure.

commissum’s Monthly Application Scan quickly scans and analyses large complex web sites and applications. It also identifies application vulnerabilities and site exposure risk, ranks threat priorities, produces highly graphical and intuitive reports, and indicates site security status according to vulnerabilities and threat exposure.

For each assignment, consultants determine the best way to evaluate an application for vulnerabilities such as input validation, poor coding practices, weak configuration management, etc. They also configure the scanning engine to deliver the best possible set of results. After carrying out context-sensitive vulnerability checking, commissum consultants review the results, looking for false positives and false negatives, to offer a complete and cost-effective assessment with outstanding accuracy.

In addition to assessing application vulnerabilities, commissum’s Monthly Application Scan performs advanced analysis on your site's structure, content and configuration in order to identify inherent exposure to future or emerging threats. This can be critical in determining future security requirements and site architecture planning to mitigate future threats.

A key feature of the reports is the ability to replay the attack using a "show me" button. This helps to educate developers to avoid coding such issues in the future. In this sense it complements our code review service, by helping to prevent developers from writing vulnerabilities into future code, as part of the Security Development Lifecycle.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
"Above all I value the responsiveness and flexibility shown by commissum in responding to my requirements. Faced with short notice requests they have always rapidly responded, delivering on time with consistently excellent quality and clarity of reporting.”

Sonya B, IT Security - UK Local Government

Latest News

Alleged Chinese Government Hacking Department back in action

Alleged Chinese Government Hacking Department back in action

Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...
Tue 21 May, 2013 // Martin
cyber-war

Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years

A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...
Wed 08 May, 2013 // Briony
cyber-tanks

Suspected hacker arrested after “biggest-ever DDoS attack”

Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...
Tue 30 Apr, 2013 // Briony