chrismathers
inc. is committed to improving the security posture of our
clients by providing prevention, awareness and response
solutions. In concert with our strategic partners, we deliver
these solutions to organizations that understand the need to
incorporate IT security into strategic business goals and
objectives.
Ensuring the security of the Active Directory environment is
an important management responsibility. This responsibility is a
daunting task with today’s environment of increasing risk.
Maintaining this secure environment is essential to the
professional and public reputation of all corporations.
Corporations need assurance that their host
environments are secure and that any possible
vulnerabilities are identified and addressed. Along with our
strategic partners, we pride ourselves on our assessment and
penetration testing methodologies and custom developed
tools. Through the application of our custom tools, our
Forensic IT professionals have discovered at least one major
and undocumented vulnerability not previously discovered
using industry standard commercial tools. The use of custom
tools reduces unknown and/or undesired effects on the target
environment. This added value, combined with our risk
profiling methodology, increases the effectiveness of our
services and clearly differentiates us from our competitors.
What is penetration testing?
Penetration testing is the evaluation of the
inherent security features of an IT environment to assess
its vulnerability to unauthorized access.
How is it done?
Technicians make use of commercial and custom
tools, including specialized software and hardware and
“social engineering” techniques, to simulate an attack on
the Active Directory environment by unauthorized persons.
What is Social Engineering?
Social Engineering is the gathering of
confidential information from unsuspecting employees through
lies, misrepresentation, pretext or guise. In the context of
a Penetration Test, this information, such as passwords and
user ID’s, is then used to replicate the conditions of an
unauthorized attack.
Why would my company require regular
Penetration Testing?
Your intellectual property, proprietary
information and client records are of significant value to
criminals and your competitors, not to mention various
activists, protesters and reporters. Unauthorized access to
your network could mean that some or all of your
confidential information might be stolen, altered or
destroyed. In addition, intruders could perpetrate other
types of significant damage that could cause economic loss
and embarrassment for your company, such as, the “hijacking”
of corporate websites or significant disruption of internal
email systems.
|