Penetration Testing

Overview
Periodic penetration testing helps a client identify security exposures in its security infrastructure and allows management to address the exposures before they become a problem.
This service attempts to exploit known vulnerabilities and determine whether the vulnerability can actually be exploited. Many reported vulnerabilities found during scans are false positives and do not require remediation. It is critical to determine which vulnerabilities can actually be exploited and to apply resources to remediate these deficiencies.
Most companies are required to have an annual Penetration Test performed per regulatory requirements.
An annual Penetration Test is considered an IT best practice.
If a client has a security breach and they have not been performing regular Penetration Tests, the leadership’s performance in protecting the enterprise may be called into serious question.
Clients do not want their name in the paper as a result of a security breach. An organization’s good name can be severely tarnished in the event of a security breach.
Deliverable
The report from this project is a detailed description of the steps taken in our penetration test, the vulnerabilities found, and what vulnerabilities could be exploited. A detailed description of how the vulnerabilities can be corrected is provided.
Customers-Partners
Features
All engineers have CISSP, CISA, and PCI QSA certifications
Web based collaboration site used for project communication (Tasks, Documents, Milestones, Discussions)
Great References
State-of-the-art lab for payment application testing and forensic analysis


















