Guides

Penetration testing, adversary simulation, red teaming, purple teaming, rainbow teaming, call if what you like, the security outcome we are working towards is:

  • Improved Security Posture
  • Assurance of security investments and controls
  • Enablement of information sharing
  • Collaboration and Understanding
  • Identification of strengths and weaknesses
  • Optimization and Improvement Opportunities

This is to support the organisations mission, vision, goals, and objectives. Cyber security is to support and enable the organisation’s capability to execute digital services in a safe manner.

How do we do this?

  • Communication
  • Learning
  • Education
  • Offensive and Defensive Security Practises
  • Technology Engineering
  • Knowledge Sharing
  • Intelligence based activity
  • Threat knowledge sharing

Full Spectrums Security Testing

Scenario Based Testing

These include assume breach and fast forward options to enable efficient testing from multiple positions and perspectives. Focus should be on:

  • Identification of Targets
  • Target Exploitation
  • Detection & Alerting
  • Response Actions can also be assessed however this should be considered with regard to constraints.

Scenarios

  1. External unauthenticated Threat Actor
  2. External vpn auth/vpn compromise
  3. External Standard compromised (Mailbox)
  4. External Standard User Identity, Mailbox and VPN Access
  5. External VIP Compromised
    1. Leadership team member
    1. HR Team member
    1. Finance Team member
  6. External IT Team Compromised
  7. Internal Rogue Device
  8. Internal Malicious USB Devices
    1. HID
    1. Removable Media
  9. Internal Compromised managed device
    1. PC Device
    1. Smart Phone
    1. IoT Device
  10. Internal Server Compromised

Specific Targeted Testing

  1. Wireless Network
  2. Firewall
  3. IPS/IDS
  4. External Web Application Testing
  5. External API Test
  6. Active Directory

Security Assurance

A penetration test is NOT security assurance, a single exercise is not assurance. Assurance is also not just about practical capabilities and testing. Security assurance should be a holistic set of activities covering:

  • Policy, Processes and Procedures
  • People, Skills, and Capabilities
  • Supply Chain Security
  • Risk management
  • Security Operations
  • Security Monitoring
  • Personnel Security
  • Incident Response
  • Vulnerability Management
  • Patch Management
  • Backup and Recovery
  • Continual Improvement
  • Security Testing

Security testing plays a part in demonstrating assurance, it’s also (if deployed sensibly) a really good tool for improving knowledge, understanding, communications and helping surface risks and enabling targeted remediation, detection, and response.