Trustwave SpiderLabs Uncovers Unique Cybersecurity Risks in Today's Tech Landscape. Learn More

Trustwave SpiderLabs Uncovers Unique Cybersecurity Risks in Today's Tech Landscape. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

How Human-Based Penetration Testing is the Perfect Complement to Automated Vulnerability Scanning

Perhaps it is the number of painfully costly data breaches that have rocked organizations to the tune of nearly 900 million records since 2005. Or the continually expanding attack surface and proliferation of sensitive data - and the attempt to secure them with increasingly complex security technologies that businesses lack the in-house expertise to properly manage. Or maybe it is the growing demands stemming from compliance requirements, such as PCI DSS.

Whatever the reason, more organizations are waking up to the fact that if they are to succeed against the enemy, present less of a target-rich environment and reduce their security risk, they must get to the root of the problem: vulnerabilities. If not caught in time, these weaknesses, which can range from poorly coded web applications, to unpatched databases to exploitable passwords to an uneducated user population, can enable sophisticated adversaries to run amok across your business.

One of the most effective ways to fix these holes is to think like a hacker through penetration testing.

Pen testing doesn't just identify vulnerabilities, misconfigurations and other weaknesses that can leave your databases, networks and applications open to attack - it actually attempts to break through your security defenses and exploit those flaws (without impacting your business).

While traditional vulnerability scanning is also important and evaluates a system for potential vulnerabilities or weak configurations, it is also largely automated and can only ever find a subset of security issues. Penetration testing, on the other hand, is a manual process executed by humans with diverse and specialized skill sets. A pen tester will use tools as a part of their work, but they apply their human ingenuity to exploit vulnerabilities and illustrate what an attacker might be capable of when targeting a particular system.

Penetration testing is so illuminating that even criminals are turning to these tools to spread their malicious wares. A recent ransomware strain has been spotted leveraging pen testing capabilities to attack targets.

I asked Michel Chamberland, senior application security consultant and penetration tester at Trustwave, to weigh in on the merits of pen testing and explain why holdouts may remain.

DK: What makes a manual pen test a great complement to automated scanning?

MC: A pen test will find real-world scenario vulnerabilities that are most likely the ones malicious actors would find as well.

Why are organizations reluctant to deep-dive pen testing?

First, they don't think such attacks will happen to them. Second, they often they think that if they don't know about the vulnerabilities then they don't exist. If they learn about them then they have to do something about them. As crazy as it sounds, I've heard this many times. And I attribute it to a lack of due care. Third, they know they have a lot of problems and don't want them exposed. Again, lack of due care. And last, they may be afraid to impact both system and resource availability that are already stretched thin.

Why is pen testing so effective?

Organizations are already stretched thin so having a third-party penetration testing company provide detailed, actionable reports with no false positives is extremely valuable and reduces remediation workload. In a true deep-dive penetration test, the testers take the time to understand the application much like a QA analyst would to find logic flaws that no tool would find. Manual testing leads to much better coverage of the application being tested.

What do organizations need to do to implement an effective pen testing program?

Start with a smaller scope and target a higher-value asset. Learn from it and expand the practice.

Do you have any interesting stories when it comes to using pen testing?

One of the banks we do tests for shared with us that they prefer our Managed Security Testing compared to vulnerability scans because they don't have to weed through a large amount of false positives. It lets them do more with fewer resources.

Dan Kaplan is manager of online content at Trustwave and a former IT security reporter and editor.

Latest Trustwave Blogs

Trustwave MailMarshal Unveils Major Upgrades to Combat New Email Security Threats

Trustwave MailMarshal will receive a massive upgrade on March 28 that will add four new levels of functionality, including an improved dashboard interface, the ability to detect and halt malicious QR...

Read More

Unveiling the Latest Ransomware Threats Targeting the Casino and Entertainment Industry

Anyone who has visited a casino knows these organizations go to a great deal of expense and physical effort to ensure their patrons do not cheat. Still, there is a large group of actors who are...

Read More

Third-Party Risk: How MDR Offers Relief as Security Threats Abound

While third-party products and services are crucial to everyday business operations for almost any company, they also present significant security concerns, as high-profile attacks including...

Read More