Skip to Content
Penetration Testing Screen with female Pen tester

Published 15/08/2020 – est. 5 minutes to read.

Regular penetration testing is essential

Regular penetration testing is an essential part of a positive cybersecurity strategy. It helps identify and eliminate gaps in your organisation’s defences by attempting to breach some or all of the target system’s security controls using the same tools and techniques an adversary might use.

A well-scoped penetration test (a.k.a. a pen test) can provide Organisations with insight into the security issues that could be exploited by the ‘bad guys’, and concise guidance on how to fix them and protect your systems and data.

A pen test is an ethical cybersecurity assessment conducted to identify, safely exploit, and help eliminate vulnerabilities across an organisation’s IT environment. It is recommended that all organisations commission testing at least once per year, with additional assessments following significant changes to infrastructure or applications, or before major product launches. Large Organisations and Government Departments that process vast amounts of personal or financial data should consider conducting penetration testing more frequently.

Before selecting a suitable provider

It’s important to be familiar with the types of pen tests available, as engagements vary in focus, depth and duration. Common penetration testing engagements include:

Infrastructure Penetration Testing

An assessment of on-premises network infrastructure, including firewalls, system hosts and devices such as routers and switches. Can be framed as either an ‘internal penetration test’, focusing on assets inside the corporate network, or an ‘external penetration test’, targeting internet-facing infrastructure. To scope a test, you will need to know the number of internal and external IPs to be tested, the network subnet size, and the number of sites.

Wireless Penetration Testing

A test that specifically targets an organisation’s WiFi network configuration and can help to identify rogue access points, weaknesses in encryption and WPA vulnerabilities. To scope an engagement, testers will need to know the number of wireless and guest networks, the locations, and the unique SSIDs to be assessed.

Web Application Testing

An assessment of websites and custom applications delivered over the Internet (or sometimes within your internal network), looking to uncover coding, design and development flaws that could be maliciously exploited. Before approaching a testing provider, it’s important to determine the number of apps to be tested, as well as the number of static pages, dynamic pages, input fields, and the login process to be assessed.

Mobile Application Testing

Testing mobile applications on operating systems, including Android and iOS, to identify authentication, authorisation, data leakage, and session-handling issues. To scope a test, providers will need to know the operating system types and versions they’d like tested, the number of API calls, and the requirements for jailbreaking and root detection.

Build & Configuration Review

Review of network builds and configurations to identify misconfigurations across web and app servers, routers and firewalls. The number of builds, operating systems, and application servers to be reviewed during testing is crucial for scoping this type of engagement.

Cloud Security Assessments

Cloud systems, whether they are infrastructure as a service (IaaS) such as Amazon’s AWS or Microsoft’s Azure, platform as a service (PaaS), or software as a service (SaaS), are prone to security misconfigurations, weaknesses, and security threats just as traditional systems are.  Some of the information needed to scope these assessments includes the cloud services used, the number of cloud accounts, cloud firewalls, cloud servers, and any cloud databases.

Whether it’s a diverse infrastructure or a complex Web Application, our certified pen testers can be trusted to deliver comprehensive testing programmes that meet your business needs and help identify vulnerabilities that the bad guys could exploit.

Unlike other Security Companies, our team of cybersecurity specialists provides a strong level of ‘aftercare’, ensuring that our Clients have the support they need to fix the vulnerabilities we identify.

For more information on how we can support you with our Penetration testing services, please get in touch with us on 0161 706 0244 or email info@cybersecurityspecialists.co.uk to speak with a member of the team.

Contact us

Related Pages

Cyber Maturity Audit icon.

Cyber Maturity Audit

 

Learn more about a cyber maturity audit

Shield Icon.

Virtual Data Protection Officer

 

Learn more about the virtual data protection officer

Cyber Essentials Plus Icon.

Crest Penetration Testing

 

Learn more about crest penetration testing

CS360 ai icon.

CS360.ai Exposure Management Platform

 

Learn more about CS360.ai