
The art of penetration testing.
I read somewhere that the security of an information infrastructure is only as effective as the methodology adopted to test it, which has a fairly strong logical basis and explains the shift we have observed in recent years in the market for information system security services. The well-known penetration testing, or as most people like to call it now, ethical hacking, is a way through which we can test the security of our network and while it is nothing new, it has become increasingly popular in recent years. We are increasingly used to telling anyone who conducts infrastructure security tests to think like a malicious user, like an attacker, like a hacker, which is the essence of effective penetration testing. You simply think and act like a real attacker who is trying to gain unauthorized access to the system you want to test. We often use this particular methodology in exactly the same way that a malicious user uses it, checking all the vulnerabilities, critical and not, that the tools we use (Burpsuite, Nessus, etc.) throw up when conducting a check to see if we can actually exploit these weaknesses or if we are ultimately safe.

Some companies hire in-house staff to conduct security audits while many rely on external security consultants. Of course, most companies currently, and not only in Greece, do not perform security audits on their corporate infrastructure either because they do not know what the risks are or because they consider penetration testing to be quite costly. Those companies that are PCI-DSS are of course required to perform security audits at regular intervals. Someone will reasonably ask, however, “how come so many banks and so many large companies still fall victim to hacking while they have a dozen certifications for the security of their infrastructure?” The answer is simple. They treat each security audit as just another checkbox, without the slightest innovation in methodology. It's just something else they have to do – and they will do it but with the same enthusiasm and efficiency 😉 Not to mention the validity of several certifications out there. Of course, the checkbox method can be effective for an initial stage of testing to check for some non-critical vulnerabilities and perhaps some human logic errors, but it is not a guide for a full-fledged – substantial penetration testing.
So think again, those of you out there who think your IT infrastructure is effectively secure. It's always good to ask ourselves whether and to what extent we are satisfied with the security checks we conduct, because there is always a possibility that something has not been done properly.
