NineStar Connect Offers Pen Tests to Guard Against Cyber Attacks
CYBER ATTACKS ARE ON THE RISE
Cyber risks are a big concern for businesses across Indiana and in an effort to help its commercial membership identify security issues and mitigate potential pitfalls before an attack occurs, NineStar Connect offers a series of penetration tests to help companies stay ahead of the hackers. These tests include:
• Active Directory Test: Looks for hackable issues in a company’s e-mail accounts, password policies and practices such as multiple users that apply the same password.
• Vulnerability Scan: Identifies the ways in which network security is susceptible to a hack and allows clients to apply a patch that will immunize them from the threat.
• Ransomware Test: Introduces a “defanged” (no longer harmful) ransomware program and attempts to install it on a company’s network. The simulation will try and delete the local backup and filter that data to an external source.
• Black Box penetration testing: Examines a system to locate and exploit any weakness in a network without any information provided by the user.
• Grey Box penetration testing: Examines a system to locate and exploit any weakness in a network with some information provided by the user (such as a password.)
When combined, these tests offer clients a “360-degree” view of their cyber defenses, identifies any gaps in the network and proposes solutions that can be implemented to shore up those vulnerabilities.
‘The best time to find out about a security weakness is through a benign test rather than walking into the office on a Monday morning only to discover that there has been a breach in the system,” says Shira Dankner of NineStar Connect. “We believe that a rising tide raises all ships and if everyone’s security improves, it helps us all in the long run.”
PREVENTION AND PROTECTION
Like a balanced diet, a firm’s cyber security plan should include several elements and must be evaluated periodically for potential deficiencies. Having worked with NineStar Connect on various projects over the years, Boone REMC (BREMC) IT infrastructure lead Matt Ladd knew the cooperative’s new pen tests would offer his organization the perfect preventative challenge to their cybersecurity protocols. After budgeting for the pen test, they were surprised to win one during a cybersecurity event.
“NineStar has built a strong reputation, and for me the value of what you get compared to other experiences … ! figured we couldn’t go wrong,” Ladd said.
KEEPING THE SECRET
Ladd said for him, the key to conducting the tests was to do so as quietly as possible. Even BREMC vice president of corporate development and technology Corey Willis was kept in the dark about what was being run and when the tests
were taking place.
“I wasn’t very forthcoming about what was going on because I wanted to run the tests organically to achieve the most thorough and accurate results,” he said.
Shira Dankner, of NineStar understood and without disrupting daily operations or making team members nervous about the process, she was able to test the effectiveness of the antivirus tools already in place and troubleshoot any potential vulnerabilities within the BREMC system. When the tests were completed, Dankner created a report then met with Ladd and Willis to discuss the reports and determine what next steps to take.
Ladd said the NineStar pen tests identified areas that BREMC believed to have been remediated in the past but were still problematic as well as hygiene gaps that put active and decommissioned computers at risk. And while it is hard not to focus on the negative, the report also showed what BREMC was doing right.
“I was kind of happy to see that it wasn’t worse than it was,” Ladd said.
Ladd said NineStar Connect pen tests were designed by IT professionals for IT professionals without a lot of upselling or added jargon and while larger firms tend to target executives with a lot of bells and whistles, NineStar works with those on the IT front lines to answer all of their questions and prioritize resolutions going forward.
“Our test offers assistance with remediation in the form of articles that explains what the exploit was, how it worked, how to fix it and finally – how to validate that it was resolved,” Dankner said. Willis said he too was pleased with the process and professionalism. “When you do a pen test, you are putting a lot of trust in the organization you choose to work with. We have worked with NineStar in the past and we are comfortable with them. They gave us an incredible amount of support,” said Willis. “We will definitely work with them again.”
To learn more about NineStar’s Cybersecurity solutions, CLICK HERE.