Insights

Good Security Does Not End With Penetration Testing

We often think of different areas of cyber security in isolation, but we can benefit from taking a step back and considering the bigger picture. This blog post aims to remind organisations of what can happen with security “tunnel vision”, and what can be done to give holistic protection to the systems we are trying to defend.

I have worked primarily in the field of Incident Response for over eight years. To give myself and clients a broader range of expertise, I recently decided to shift more of my focus towards the offensive side of cyber security and have occasionally noticed an opinion of penetration testing that has the danger to result in a false sense of security for organisations.

The need for penetration testing can sometimes stem from a requirement to meet a security policy, or just to get a “tick in the box” for security, rather than a consideration for the overall risks and security of an application or piece of infrastructure.

I’ve been fortunate enough to work with organisations of many different sizes throughout my career, ranging from small not-for-profit charities, local retailers, and private individuals through to multi-national manufacturing companies, government entities, and critical national infrastructure. During a cyber incident there was always one common theme: nobody expected the incident to happen.

This statement sounds obvious but on many occasions, I have heard some variation of the following sentences during the incident:

  • “We had a penetration test on this a month ago – why wasn’t this issue picked up then?”
  • “Our infrastructure isn’t supposed to be set up this way; it was only changed temporarily.”
  • “We had no idea that this system could be abused in this manner.”

Many of these organisations had frequent penetration tests and proactive security controls in place to prevent a security incident from happening. So, what was missing from these organisations’ approach to security that could have helped?

Why is Penetration Testing Not Enough?

When it comes to Penetration Testing, it is simply one of tools in the toolbox when it comes to securing information (you can read the recently released excellent blog post “What is Penetration Testing and Why Is It Important?” for further information on why this should be performed). One of the mistakes organisations can make is considering only this in isolation as a complete sign-off for the security of an application or a piece of infrastructure without considering other areas such as supporting policies or containment mechanisms should a breach occur.

A good penetration testing provider will not just highlight technical areas of abuse but also areas of weak business process, and provide holistic strategic and tactical recommendations of where to improve.

For example, a finding regarding an out-of-date software library on a web application could be simply listed as something to update to solve the issue. However, if that is the only recommendation given, it is unlikely to do anything to stop the issue from occurring again as it does not consider the root cause of the issue.

Although it may not be always possible for a penetration testing provider to establish the answers to these during an engagement, at least internally you should be asking:

  • Why did we not know this was out of date?
  • Do we have a list of all the software libraries used by our applications, and what the current versions are? How would we build this and keep it up to date?
  • How can we determine if a vulnerability appears in a software library before an external penetration test catches it (or we have a security incident)?
  • If this vulnerability were exploited and the application was compromised, what could we do to limit the impact of an incident?

You can apply this type of thinking to all findings – is there anything you can change about your current development process, change control, security monitoring, or response procedures to prevent, identify, or mitigate issues before your next external validation?

Of course, there will always be exceptions, testing constraints, or simply areas that a testing provider does not cover during a penetration test engagement, but having a  provider who can at least prompt you to think of these types of considerations will better prepare you for future security incidents.

A False Sense of Security

Imagine getting an assessment of the security of your house. You say to the assessor your primary concern is preventing unauthorised access to the property. The assessor walks around the perimeter of the building, does all of their checks, and comes back with a positive result: all your windows and doors are locked, and it would be difficult for someone to get in. Perfect!

Or is it? What about when you invite someone you know into your house and they try and steal something without your knowledge? What about someone using fake credentials to impersonate an authority that you trust and let inside? What about if you just happen to leave a door unlocked one day by mistake when you leave? If something bad does happen, do you know what you would do?

This simple analogy highlights multiple important lessons that we should be applying to our digital assets:

  • Choose an appropriate scope for your engagement. Do not just consider tests from one perspective (only checking the house from an external viewpoint). Speak to your provider about the risks that are present and work with them to ensure they consider these during an assessment.
  • Consider the actual threats that may be present in your environment. Do you need to include in the assessment, a review of what a potential insider may be able to perform?
  • Ensure you know what steps to take if a compromise occurs. Of course, all of us know the number for emergency services in the physical world, but we may not be able to say the same applies in the digital world. A quick, effective response to an incident can have the most impact on a successful outcome.

Key Takeaways

It has sometimes felt like an unfortunate truth for many that it was not a case of ‘if’ you experienced a cyber incident, but ‘when’. By considering the actual reason behind requesting a penetration test, ensuring it is tailored appropriately for your risk scenario and taking a small step beyond surface findings of an engagement, you can severely limit the impact of a security incident when it happens, and increase the speed at which you can return to normal operation.

At Prism Infosec, we aim to understand your requirements in detail and work with you to deliver the best experience possible. We have a range of services including cyber security assessments and penetration testing services, emergency incident response and retainers, and governance, risk and compliance services. Contact us today to find out more information about how we can help you.

About the author

DSC_3314 - Copy
Chris Kuzu-Sabine
Chris Kuzu-Sabine is a Security Consultant at Prism Infosec. Having primarily worked within Incident Response over the last eight years (with additional experience in penetration testing and governance), he is able to utilise this expertise in defensive operations to deliver practical advice in emergency response, as well as translate this to effective guidance in offensive operations and penetration testing engagements. Chris has held positions in various consultancies, supporting clients of different sizes in different industry verticals, ranging from local charities to multi-national organisations.
the-cyber-scheme
pci
Crest
cbest
CHECK Penetration Testing (Dark Logo)
Cyber Incident Exercising
Cyber Incident Response Standard Level logo
Untitled design (1)
4b30d27e-0b52-4807-9ef9-9d88954e3e1c

Experiencing a security breach?
Contact the cyber security experts now