Penetration Testing Necessary? With the rapid shifts in the attack landscape in the black market hacking scene worth billions, if you wait to perform penetration testing you will miss out.
Far too many companies and organizations only perform a penetration test when they have to. Often, this is because they need to comply with regulations or someone has asked them to prove that they are secure.
Most, unfortunately, only do a penetration test after they have already been burned: that is, when the hackers have successfully taken their valuable data, something that cost the company far more than several penetration tests. .
Modern penetration testing is more than just a scan. Former Black Hat CEO Trey Ford says, “Regulations like PCI require penetration testing at a minimum of once a year, or after any significant changes to infrastructure or code.”
“I think that the first part of this discussion should refer to “what exactly is a penetration test?” says Ford. “Depending on who you’re talking to, this can include security testing of a web application, scanning a network, social engineering and phishing, wireless testing and more.”
Problem: Attacks evolve faster than requirements
Just five years ago, penetration tests – “pentesting” – were the subject of articles in IT security journalism that debated whether a pentest was worthwhile. Many things have changed in a short period of time.
Pentesting has evolved quickly to keep pace with a black market that is filled with specialized criminals, or government ones, the attacks have gained flexibility to penetrate the advanced defenses of enterprises.
There are some automated pentesting, but for better results you need a team that will be better than the attackers, which certainly costs.
Pentesting is the growth area today. For example, security company Rapid7. Considered a leader in the field of security software and services, Rapid7 has an extensive pentesting suite that includes the famous Metasploit (“the attacker’s playbook”) and has a huge community with 200,000 active members.
The security company has a revenue record and has 13 offices worldwide. It can boast about the 1,000 companies that use its products.
Its client list includes Diebold, Deutsche Telekom, Panasonic, Rodale, Revlon, Trader Joe, Virgin Atlantic, and many others.
Metasploit technician Tod Beardsley sees an average of 1.2 exploits being added daily to Metasploit.
Beardsley explained that the issue of “how often” is complicated by the fact that some businesses need pentesters more than others. “Some industries – for example, the financial sector – are more organized than others, and must meet pentesting requirements.”
However, I would like to say that every organization that handles data and is interested in keeping it confidential has the responsibility to ensure its network configuration is such that its defenses are sufficient for this mission.
Furthermore, if a company does not want to be an unsuspecting host for the distribution of a malicious program, there must be adequate external monitoring.
There is a joke that circulates at hacking conferences, Black Hat USA and DEFCON.
According to a Rapid7 study, spear phishing is the main breach factor in 9 out of 10 targeted attacks.
[tweet_embed id=493364883878998016]
“There are thousands of points between the external network and the internal network”, explained Mr. Beardsley. “the modern work life is moving more and more from the office to the home (a laptop on a kitchen table), and there are many risks for a company.”.
The home routers, for example, are not even the most secure. The risks do not stop there. The first thing that one should do is to «lock its DNS service, and it should require regular and systematic checking of all processes for DNS changes.”
“If someone gains control of a company's DNS, they will be able to monitor almost all e-mail.
Beardsley explained that it is difficult to categorize how important the particular pentest strategies are, and for this – a company should conduct pentests more often than required (or desired).
Departing from Rapid7's logic, which certainly contains intentions, we must think very seriously about how much a breach would cost on a website, a company, a financial institution, etc.
How often depends on your own discretion and financial flexibility.
The article was published on ZDNet by Violet Blue. It also contains the author's views.

