Showing posts with label Services. Show all posts
Showing posts with label Services. Show all posts
Tuesday, 9 February 2016

Penetration Testing

Our penetration testing adheres to recognised standards including the OWASP, CHECK and CREST testing methodologies, meeting and exceeding the requirements of standards set by government and regulators such as the FCA, and the requirements of PCI DSS.

Our reports will help you clearly understand both business and technical risks, identifying not only known technical vulnerabilities, but also design flaws within the application's logic and errors in implementation . Our easy to follow recommendations will give you a clear indication of how to fix the vulnerabilities we have identify, and further sources of information.

We offer a complete range of security testing services, both remote and on-site.

  • Infrastructure Penetration Testing
  • Web Application Security Testing
  • Wireless Network Penetration Testing
  • Vulnerability Scanning
  • Mobile Application Testing
  • System Build Review
  • Source Code Review
  • Lost/Stolen Laptop Review
  • Lost/Stolen Mobile Device Review

Whether you require a basic external infrastructure vulnerability assessment, or a full internal penetration test we can help.
Tuesday, 2 February 2016

Is Social Engineering really a problem?

As computer security controls become more effective attackers are seeking ever more complex methods of targeting organisations and their staff. By combining technical expertise with social engineering they are increasingly more successful in gaining access to sensitive information, valuable assets and money.

Risk managers now frequently recognise the need to consider the human factors in Information Security as many attackers are now actively engaged in hacking the human as this is often more susceptible to attack than the technology.

Social engineering is the clever use of deception or impersonation to gain trust that leads to unauthorised access of sensitive information or facilities. Unfortunately people are often the weakest link in an organisation's security defences, as many of the good qualities we look for in human behaviour are the very same ones that can lead to compromise.

Although people have become much more familiar with the term "social engineering" in recent years, this hasn't unfortunately lead to a reduction in successful social engineering attacks. In fact, they are increasing rapidly. Awareness and understanding of social engineering techniques, and how to defend against them, are key to your survival.

We offer a full range of social engineering testing and training services.

Our review, assessment and testing services include:
  • Assessing the vulnerability of your facilities to physical compromise
  • Testing your physical defences and your staff's susceptibility to physical manipulation
  • Evaluating your staff's susceptibility to remote social engineering
  • Measuring the success of bespoke phishing attacks against your staff
  • Testing the effectiveness of your security awareness training
Our social engineering training is particularly useful for executive’s personal assistants, receptionists, help desk and call centre operatives, but is beneficial for all staff in both their work and personal lives. By raising their awareness of the dangers of social engineering, helping them to better understand the techniques used by attackers, and by providing them with defence strategies they will be better prepared to defend your organisation.

For those wishing to be educated themselves, to be able to test their own organisation or to better engage the services of others, we also offer an offensive course that teaches the techniques and methodology used to successfully gain unauthorised access to buildings and information. With a strong emphasis on the legal and ethical considerations associated with such testing we equip your risk managers with the knowledge they need.
Tuesday, 19 January 2016

PCI DSS Penetration Testing

Agility's penetration testing services meet and exceed the requirements of PCI DSS. Merchants and service providers can prepare for an annual PCI compliance audit by engaging with our specialist security assessment team who will perform internal and external penetration testing to meet your obligations as mandated by PCI DSS Requirement 11.

What is PCI DSS?

PCI DSS is a worldwide standard intended to reduce the rising number of incidents of stolen cardholder data. Endorsed by Visa, MasterCard, Cardholder Information Security Program (CISP), Discover, Diners Club, and American Express whose goal is to protect cardholder account information.

The due diligence required to meet the standard is complex, requiring merchants to address the twelve requirements of PCI DSS by undertaking testing, performing remediation, retesting, and documenting compliance findings in preparation for a PCI DSS compliance audit.

What’s included in the penetration test’s scope?

The scope of PCI mandated penetration testing includes all systems and networks within the cardholder data environment and requires the tests to be undertaken by experienced penetration testers who are independent from those individuals managing the cardholder environment.

Who does the PCI security standard apply to?

Entities that accept credit or debit card payment, collect, process or store card transaction information are required to be compliant with PCI DSS. Failure to meet the security standard can result in substantial fines or expulsion from card programmes.

Section 11.3 of the Payment Card Industry Data Security Standard (PCI DSS) requires organisations to conduct penetration tests at least once a year and after any significant infrastructure or application upgrade or modification. The penetration tests must include the network-layer and application-layer penetration tests both internally and externally.

Contact us today to discuss your requirements for PCI DSS including regular ASV vulnerability scanning, QSA services and PCI DSS penetration testing.
Thursday, 14 January 2016

Don't forget about your people!

Any business is only as secure as the people in it. Mistakes happen, they're unavoidable, but through education, policies and good practice the likelihood and severity can be reduced. It is important to equip your staff with the skills they need, you'd be negligent if you didn't and it's no good blaming them when things go wrong if you haven't set expectations and provided the knowledge.

We provide a wide range of training to help ensure that your people, both within the business and IT, have the skills and awareness they need to keep you secure. Enabling them to act responsibly and effectively, to understanding potential threats and how to protect against them, and how to detect and what to do when compromised are key to your survival.

Our awareness training course range from secure coding and development practices for your technical team, to combating social engineering attacks against call centres and key staff. General security awareness across your organisation is essential in today's connected world.

We occasionally run open courses at security conferences but frequently run bespoke courses for our clients, especially in the area of social engineering awareness and defence.

Popular courses include:
  • Social Engineering for Call Centres
  • Social Engineering for Penetration Testers
  • Social Engineering Awareness and Defence for Financial Services
  • Social Engineering Awareness and Defence for Healthcare Providers
  • Web Application Defensive Programming for Developers
  • Engaging Penetration Testers for Procurement and Project Managers
Monday, 11 January 2016

Manual vs Automated Web Application Testing

Three different approaches to web application testing can be adopted; automated, manual or a combination of both – however the outcomes, given a typical web application, are likely to be very different both in terms of coverage and cost, but most importantly in terms of the level of assurance obtained.

Agility's standard methodology utilises the combined approach, providing an efficient and effective service attaining a high level of assurance in the most cost and time effective manner.

Level of Assurance

Automated web application vulnerability assessment tools have the ability to efficiently identify some categories of technical vulnerabilities, such as the most simple forms of common web vulnerabilities including some SQL injection and Cross-site scripting, and typically identify only well known vulnerabilities.

More complex vulnerabilities, for example those related to or dependant upon application logic, or flaws in security functionality design (such as authentication and authorisation) are not readily identified using automated techniques and require a manual testing approach.

Other web application testing tools, designed to assist a manual tester, can greatly increase the efficiency of testing by automating a series of steps, or performing hundreds or thousands of iterations of a transaction under the guidance of the manual tester therefore achieving results that would otherwise be impractical.

AgilityIS therefore utilise a combination of these methods that is invariably the most appropriate approach. All our testing is manually led, first gaining an understanding of the application logic and then selecting the most appropriate tools to assist in the testing of the web application.

Using automated vulnerability assessment tools alone would lead to a false sense of comfort, with real issues going unidentified. The more intricate vulnerabilities that remain would ultimately be the ones that are most likely to be exploited to real effect, leading to the compromise of information or fraudulent transactions.

Manual testing alone would not be exhaustive enough and could lead to areas of vulnerability remaining undiscovered, particularly where multiple iterations are required to identify patterns in the applications behaviour that may be exploited.

By using a combination of manual testing techniques and automated tools testing is both efficient and effective. By testing from an informed position using this combined approach we can provide you with the highest level of assurance in the most cost and time effective manner.

Operational Impact

As well as the differing levels of assurance obtained when considering the relative merits of automated and manual web application testing, there are some further points that should be taken into account particularly around the risks associated with performing the different types of tests.

There are inherent risks associated with automated testing. Because it is impossible for an automated tool to view a given function in its complete context, testing any function which results in a change in application state or data could result in a loss of or damage to data, or erroneous data being stored or processed by the application.

Manual testing uses a number of strategies to dramatically reduce the risk of such events occurring. Most significantly, functions are subjectively analysed under ‘normal use’ scenarios before testing commences. This enables the tester to understand the full context and effect of a function. Testing can then be tailored for the specific function.

Manual testing is also able to identify the same vulnerabilities using a significantly reduced number of requests by analysing responses in a more intelligent manner. This greatly reduces the number of erroneous transactions, and permits the tester to keep track of transactions made during testing so that administrators can reverse them later.

Threat Defence

Finally, consideration needs to be given to which threats you are trying to protect against, and this may well vary depending on the application and its use.

An automated scanner will help in defending against automated attacks, making your application a less interesting target compared to other less well defended sites. However, it will not deter a more focused attacker who will look for more complex ways to exploit your infrastructure.

Agility commonly find sites that are vulnerable to exploits such as Cross-Site Scripting which allow an attacker to embed code within a website that subsequently allows the attacker to directly target genuine users of the website. These users are unaware that pages rendered in their browser may be malicious, even though they appear to come from your trusted website. Such exploits harvest user supplied information, may prompt for passwords and so on, and all the information is passed back to the attacker.
Thursday, 7 January 2016

What is Cyber Security?

Information Security, IT Security, ISO 27001, PAS 555, Cyber Security... What does it all mean? What's the difference? Is this something new you need to know about, or is it knowledge you already have?

What's this new cyber security thing all about?

For those well versed in IT security you'll be pleased to know it's nothing new at all - it's the same stuff we've been doing for many years!

So why the new synonym?

The cynical might sight it as a marketing initiative, creating new opportunities to sell the same old stuff under a new wrapper, and I have to say very little has in reality changed to warrant a new term.

Is there a difference between cyber security and IT security?

Some, but not a lot! Cyber security is essentially a subset of IT security, focusing only on cyber threats. For the most part that means things to do with the Internet, but cyber-space does extend to any computer to computer communcations, USB devices containing malware and the like.

So is IT security all about technical controls?

No. While the vast majority of defensive controls will be technical in nature, training and education, personnel vetting and so on are all relevant to IT and cyber security. Remember that these are themselves a subset of Information Security which covers all aspects of secure information management.

What does cyber security achieve?

Essentially it focuses on protecting computers, networks, programs and data from unintended or unauthorised access, change or destruction, ensuring the confidentiality, integrity and availability of information systems.

Why is cyber security suddenly so topical?

As the numbers of mobile users, digital applications and interconnected networks increase, so do the opportunities for exploitation. Network outages, computer viruses, data compromise and other incidents affecting our lives and businesses are becoming increasing more common. As more and more of our world becomes connected and the speed of connection increases, the risk grows. The impact, whether causing inconvenience, material losses, or threats to life, is also growing.

Is cyber security important?

Yes! SMEs, corporates, governments, military, educational, healthcare and financial institutions, and most other businesses all collect, process and store a great deal of confidential information on networked computer systems. With the growing volume and sophistication of cyber attacks, continuous effort is required to maintain the security of sensitive business and personal information, as well as safeguarding critical national infrastructure.

AgilityIS Cyber Capability

Our cyber specialists can assist you in all aspects of cyber security assurance. From secure design architecture reviews, infrastructure and web application penetration testing to assurance and due diligence reviews. We have decades of experience that we can bring to your projects.
Wednesday, 6 January 2016

Security Assurance for DWP and PeoplePlus Partners

Agility offer a full range of information security services to assist DWP and PeoplePlus partners in securing their organisation to the stringent level required by the Department for Work and Pensions (DWP) and PeoplePlus (formerly Action for Employment, A4e). Our services include penetration testing, ISO 27001 ISMS, social engineering and information assurance due diligence reviews.

PeoplePlus requires its partners to engage an independent reputable specialist company, experienced in Information Security services, to undertake penetration testing of their infrastructure and applications. Security testing should therefore be performed by a company that is not connected in any way with the provision of Work Programme Partner Information Systems and Services.

Agility meets these requirements being recognised by CREST (the Council of Registered Ethical Security Testers), with our consultants holding ICE and ACE qualifications as CREST Certified Testers (CCT). We have many years of experience in delivering all the services necessary to support the security requirements mandated by Government Departments and their partners.

Testing is not limited to technical vulnerabilities but also examines the settings and features of user access to the Partner Work Programme Information, which could allow misuse of authorised access to perform unauthorised actions, and also extended to physical security and social engineering.

The governance and testing requirements imposed by PeoplePlus are designed to reduce risks that pose a threat to the confidentiality of PeoplePlus and DWP data being held or processed on Partner Work Programme Information Systems and Services. Contact us for further details of our services.