Pentesting – an overview

pentesting

Why should businesses invest in pentesting?

The rate of cyber-crime and data breaches increases year on year. With the huge changes to our work environments in the last 12 months, our businesses are more susceptible than ever. To combat this trend, businesses should always be looking to improve their security posture with a practice known as security hardening. However, it is not always obvious where to start, or where to spend your time/money to make the most improvement.  

Regular pentesting is one of the most effective methods of revealing where your business is most vulnerable. This enables you to focus resources in the areas that will have the greatest positive effect. This is shown in IBM’s 2020 Cost of a Data Breach Report, which states that this type of testing has been shown to reduce the average cost of a data breach by over $240,000. This is one of the biggest achievable cost-savings, while also being the most achievable for small businesses; employing an incident response team is not a practical suggestion for small-to-medium enterprises. 

How often should my systems be pentested?

This is often dictated by any compliance you may be seeking, but a generally-agreed rule of thumb is at least once every 12 months, or after any major change – though many modern businesses focused on rapid growth will opt to test up to once a week. 

What are the most common issues you see when pentesting web applications?

Many clients fail to keep up with security updates to plugins and frameworks. This leads to them using unsupported software with known vulnerabilities. Typically, the longer you leave these updates, the more difficult it can become to migrate. Businesses should always have a procedure for migrating to newer software releases or away from End-of-Life products, in the event that critical security vulnerabilities are found within them. This may come with a downtime cost but is certainly cheaper than the fines that result from a data breach. 

Other basic web server misconfigurations are also very common, such as HTTP security headers, outdated TLS support and insecure session cookies. Mozilla host a fantastic resource for all web server configuration options with up-to-date information about the most secure settings.

One vulnerability that has recently resurfaced as a major threat is Cross-Site Request Forgery. This is where an attacker can craft (forge) requests and trick an innocent user into actioning them in their legitimate user session by simply clicking a link or button. When someone uses this type of attack to modify account credentials, the consequences can be severe. In our testing, we have found it to be very common for web applications to have little-to-no defence against this type of attack, as most modern frameworks do not include this as standard.  

How can Securious help?

Our testers follow a proven methodology with a series of tests to identify any weaknesses in your systems. We test against the OWASP top 10 and detail our findings in a report. This highlights the potential risks, and recommends where you should apply additional resources to protect your systems. We adhere to an agreed set of rules of engagement before, during and after every penetration test, but if you are considering penetration testing for your business and are worried or confused about the level of access a tester will have, check out our previous article about Blackbox vs Whitebox testing for more information.

P_jack_1_Securious_Exeter_Devon_Cyber_Security

Written by Jack

Jack is one of our Cyber Security Consultants. He is an IASME Cyber Essentials Assessor and a pentester, with a BSc in computer and information security and a talent for finding holes in client systems the bad guys could exploit. 

Follow us on LinkedIn

See the latest from the Securious team on LinkedIn