The corporate security policies are in place, the security team has trained all staff, everyone understands and follows the rules... or do they? When was the last time, if ever, security was tested? Ever found strangers wandering the halls?
WhiteHat understands how intruders break into companies and networks from within, gain access to critical information, and how they can walk away with corporate assets. Often times your helpful staff can assist an intruder, by opening a door, or giving out information without properly challenging the 'intruder'. These intruders may also work for your company, or work for a service company you hired. Intruders can call your help desk acting as someone else to gain access to privileged information. Often times the last security defense is people, your employees. How can you be sure the security policies and controls put in place will stop these average intruders? The answer is testing.
In search of pre-determined target(s) or simply running your staff through live exercises, trusted Whitehat representative(s) will thoroughly test the security awareness of your site security and staff. Typical assessment activities would include:
- Gaining access to restricted areas within the company
- Obtaining access to a PC or open network connection
- Installing a network sniffer to search for passwords
- Gaining network access
- Gaining priviledged access
- Personal information gathering on staff
- Impersonate staff over the phone calling the help desk or colleagues to gain further information,
- Impersonate delivery staff, vendors, etc.
- Gain entrance with a fake badge
- Liberate confidential information (simulate theft)
- Liberate asset(s)
- Liberate back-up tapes
- Testing of off-site storage facility
- Other activities can be devised to test security awareness of employees
A corporate "Report Card" is generated, scored and the results are put into presentation form. The findings are delivered to the client in a high energy, motivational presentation. This is the perfect motivator for the entire company and the best time to increase the level of essential security awareness in the company.