NINESTAR BLOG

Cybersecurity Case Study: Indiana Electric Cooperatives

Ross Ferson

Penetration Tests to Guard Against Cyber Attacks

CVBER ATTACKS ARE ON THE RISE
Cyber risks are a big concern for businesses across Indiana and in an effort to help its commercial membership identify security issues and mitigate potential pitfalls before an attack occurs, NineStar Connect offers a series of penetration tests to help companies stay ahead of the hackers. These tests include:

• Active Directory Test: Looks for hackable issues in a company’s e-mail accounts, password policies and practices such as multiple users that apply the same password.
• Vulnerability Scan: Identifies the ways in which network security is susceptible to a hack
and allows clients to apply a patch that will immunize them from the threat.
• Ransomware Test: Introduces a “defanged” (No longer harmful) ransomware program and attempts
to install it on a company’s network. The simulation will try and delete the local backup and filter that data to an external source.
• Black Box penetration testing: Examines a system to locate and exploit any weakness in a network without any information provided by the user.
• Grey Box penetration testing: Examines a system to locate and exploit any weakness in a network with some information provided by the user (such as a password).

When combined, these tests offer clients a “360-degree” view of their cyber defenses, identifies any gaps in the network and proposes solutions that can be implemented to shore up those vulnerabilities.
“The best time to find out about a security weakness is through a benign test rather than walking into the office on a Monday morning only to discover that there has been a breech in the system,” says Shira Dankner of NineStar Connect. “At NineStar, we believe that a rising tide raises all ships and if everyone’s security improves, it helps us all in the long run.”


PENETRATING AND DEFENDING AGAINST ATTACKS

To assess the efficacy of their pen tests, NineStar approached the Indiana Electric Cooperative (IEC) and asked them to be a demo client for the product. Although they had recently completed a pen test through another vendor, the IEC readily agreed to the analysis. According to Justin Weiskittel, IT manager with IEC, NineStar Connect was able to start on the first wave of pen tests fairly quickly and while the specific results of the project are confidential, Weiskittel said the pen test found more issues than the previous provider and proved to be a superior product from start to finish.


A COMPREHENSIVE SOLUTION TO POTENTIAL PROBLEMS
Weiskittel said NineStar was very transparent about what they were going to do and what they needed access to while going much deeper than IEC’s previous test. NineStar found more vulnerabilities but searched for them in different locations and in different ways. The tool sorted the found vulnerabilities based on criticality level so that IEC could prioritize and tackle each problem accordingly. NineStar also asked IEC’s permission for every test they wanted to run and took care to ensure that employees were not interrupted.

“NineStar Connect went above and beyond to do some tests for us that they didn’t have to do such as running things on all of the segments of our network,” Weiskittel said. “We felt like they left no stone unturned and the report we received at the end was detailed and included information about how to patch each vulnerability, but the biggest thing we liked was their offer to help us remediate the issues that were found. In the past, we were given some documentation or article to help us track down how to fix our vulnerabilities, but NineStar offered to take the lead on that, and their help will be greatly appreciated.”
NineStar Connect’s new cyber security pen tests are not only cheaper than comparable products on the market but can be customized depending on a client’s need. It does not impact productivity, does not compromise company data during simulations, cleans up after itself so that clients can feel secure about the process, and can be shut down at any time.

To learn more about NineStar’s Cybersecurity solutions, CLICK HERE.