Skip directly to content

Services

Our risk mitigation and limitation services consist of many of the same components including: Communications, Human/Physical and Management. These are offered in several common packages, however depending on the purpose and nature of your requested test we can add and remove components as necessary.  See the bottom of this page for a longer list of components that go into these projects.

Vulnerability Assessment

A vulnerability assessment tests all network services, including; web sites, email, databases, file servers and wireless for known vulnerabilities such as misconfiguration errors, weaknesses in authentication, coding errors, missing patches and other exploitable conditions. Once the state of the network has been discovered the vulnerabilities are validated through communicating with in-house IT staff and management. At this point the validated gaps in controls are compared to industry best practices, regulations and standards in order to identify high value "quick fix" controls. 

Penetration Testing

Penetration Tests are very similar to a vulnerability assessment but instead of focusing simply on known vulnerabilities, we discover unknown vulnerabilities and dive much deeper by exploiting software configuration errors, poor access controls, old and outdated software as well as human elements through social engineering if requested. The end goal of a penetration test is to identify systemic vulnerabilities and those things that would be missed during a vulnerability assessment with the objective of accessing important and sensitive electronically stored information by utilizing similar methods as a real attacker. 

Social Engineering

Social Engineering exercises involves manipulating personnel instead of computers to provide access to sensitive information that should not be disclosed. Attack methods include distributing USB drives and CD-ROM discs that contain custom malicious code, on-site impersonation of maintenance workers, or pre-text phone calls designed to solicit for information that can be used to better leverage attacks. These methods are the same ones that are used by confidence men ("con man"), industrial intelligence gathering groups and every-day attackers. 

Compliance

Compliance testing focuses closely on specific guidelines, regulations or standards such as:

Each compliance group includes specific controls such as firewalls, anti-virus, encryption of data, disaster recovery, security policies and procedures as well as vendor assessments.

 

Components

Communications

Internal Penetration Testing
External Penetration Testing
Network Vulnerability Testing
Firewall (effectiveness) Testing
VPN and Remote Access Implementation Review
Phone/Modem Sweep
Wireless Security
Web Application Security Testing
Code Auditing & Quality Assurance
Configuration Review and Design for Servers, Workstations and Network Devices
Software Patch Testing
System Hardening
Vulnerability Remediaton
Network Architecture
Pre-Post Implementation Testing
Security Policy/Procedure Review & Development
Vendor Assessment

Human/Physical

Social Engineering
Door-to-Door Security Review
Physical Security
Personnel Security
Email Phishing
OSINT (Open Source Intelligence Gathering)

Management

Information Security Program Analysis
Business Continuity/Disaster Recovery Policy and Procedure Review
Incident Response
GLBA, FDIC, NCUA, NERC-CIP Compliance Standards
Network Security
Application Security
Process Audits
Tabletop Risk Assessments
 

Information Security Compliance Assessment

Information Security Management System, Procedures, and Standards Review
Electronically Stored Information (Data) Risk Assessment
Regulatory Compliance (GLBA, FDIC, NCUA)
Network, System, and Application Security Review
Business Continuity Plan Review
Vendor Management Program Review
Incident Response Program Review
Physical Security and Environmental Controls Assessment
Security Posture Assessment (Vulnerability Assessment, Penetration Test and systemic issue identification)