For
most of our customers the security
checks in our network health check
are sufficient, however the larger
organisation or those customers at
risk from specific targeted threats
should consider a specialist security
analysis.
Using proven repeatable processes,
our security analysis can include
some or all of the following:
Network Discovery. Using
a combination of tools and experience,
we discover the network structure
and map your network. We disclose
the network perimeter, highlighting
third-party connections. Our discovery
service includes a review of router
and switch configuration, passwords
and SNMP community strings. We investigate
third-party connections, dial-in
and dial-out facilities, firewalls
and edge routers, and set the stage
for subsequent penetration tests
and vulnerability scans.
Network Penetration Testing.
We carry out a penetration
test on your network by connecting
on site and attempting to gain access
to local and third-party resources.
Initially we work without a legitimate
logon, then as a standard (non-privileged)
user and finally as a privileged
user. In all cases we attempt to
exploit the information gained in
the network discovery phase. We
target customer data, personnel,
financial and payroll information.
We also attempt access to other
networks by "piggy-backing"
from your corporate network. During
this exercise, we also review your
standard workstation configuration
(operating system, Internet browser,
e-mail, etc.) for important vulnerabilities.
Vulnerability Testing.
Using professional analysis
tools and staff interviews we analyse
your corporate network security
profile. We produce a detailed report
of weaknesses and an action plan
to remedy them. We find redundant
accounts, well known admin accounts,
easy-to-guess passwords, excessive
file permissions and much more.
We review the security configuration
of a number of sample servers, including
account policies, rights and permissions,
audit logs, administrative accounts,
service accounts, patch levels and
published vulnerabilities. We also
penetration test a sample of servers
recommend modifications and improvements
as necessary.