Lean Security Expert Lean Security Expert

How Well Is The Security Testing In Your Organisation?

With the growing number of breaches and online threats, it’s really surprising how many businesses fail to cater to their information security testing.

With the growing number of breaches and online threats, it’s really surprising how many businesses fail to cater to their information security testing.

Importance of this type of testing – including vulnerability scanning, vulnerability assessments and penetration testing service is well known.

Yet actual scope of such working is difficult to figure out and assess correctly.

What should be included in security testing? What are the vulnerabilities that need to be tested and identified? How many times should external and internal vulnerability scanning be performed? These are questions that trouble web developers and businesses.

Struggling With Finding Scope – Security Concerns of Businesses

The level of security implemented by a business when it comes to their network or web application is determined by the size of their operation. For example: Large enterprises often conduct external penetration testing or focus on one or two core web applications specifically.  

What seems to be the problem here?  

The entire security environment isn’t fully assessed. Midmarket enterprises experience a similar situation i.e. primary focus on external security testing and foregoing internal entirely.

Small businesses seem to know what is more important in the grander scheme of things! The question is, how well or poor is security testing in your organisation? Following are some common web application vulnerabilities that hit businesses with poor security.

Beware of:

  • SQL injection
  • Remote code execution
  • Cross Site Scripting (XSS)
  • Format string vulnerabilities
  • Username enumeration

Notice an increase in cyber-hacking and information theft attempts via web applications used by employees? You have poor security in place.

Improving security requires thorough adherence to the following:

Perform Inventory of Web Applications

You probably don’t have any idea which applications employees use on a daily basis. It doesn’t matter how organised your company is – there are always some rouge applications running at any given time. Little attention is paid to these applications until something goes wrong.

Give Priority to Certain Vulnerabilities

This is the second step that has to be followed prior to testing chosen applications. Make a list of important vulnerabilities that must be eliminated and another of slightly less important.  

The fact of the matter is: All web applications have some vulnerabilities and removing everyone isn’t possible. This is why conduct testing of the most threatening vulnerabilities which will save a lot of your time.

What about those that are missed by your vulnerability scanners? Enlist the help of Lean Security to make sure your web application security is at the top of its game.  

Read More
Lean Security Expert Lean Security Expert

How-to Improve Cyber Security For Non-Profit Organisations

The number of businesses and organisations that have been hacked by cyber-criminals and malicious hackers just keeps increasing.

Cyber-security experts are scrambling here and there to cover all vulnerable holes within a framework – considering no organisation is safe from hackers.

The number of businesses and organisations that have been hacked by cyber-criminals and malicious hackers just keeps increasing.

Cyber-security experts are scrambling here and there to cover all vulnerable holes within a framework – considering no organisation is safe from hackers.

From healthcare to banks, retail and government agencies… all are constantly at risk.

NGO’s – Why Do They Attract Cyber-Criminals

One point of attraction hackers and cyber-criminals have towards non-profit organisations is the large volume of sensitive data handled every day. This includes client records, donor information, confidential emails, and numerous other transactions passing through the organisation.

Cyber security should be at the top of every organisation’s priority list but how concerned should non-profits be in the face of increasing cyber attacks and security threats? How can non-profit organisations ensure their sensitive data remains secure from malicious threats?

More importantly, how can donor confidence in non-profit organisations and their security framework be re-established?

By Upgrading All Computers

Many non-profits don’t realize the importance of installing the latest computer systems. Are you still using an old version of Windows XP? Fun Fact: Microsoft no longer supports Windows XP.

This means computer systems operating on outdated software are even more vulnerable when it comes to cyber attacks and hacking.

Focus On Strong Passwords

Do you use the same password for every social network and website that you access? This will just make it easier for hackers to steal important information considering cracking one password will lead to a domino effect.

Change your passwords, even a slight difference will ensure that information cannot be accessed by another person. Can’t remember complicated passwords? Copy and keep it in a secure location like your work related diary.

What makes a great password? According to web application security experts Lean Security, there are 6 different ways you can build a strong password. What is the best way to make a strong password?

Mix up different types of characters used normally to make a password like numbers, letters, and symbols. Don’t use words that can be found in the dictionary.

Assess and Identify Security Risks

Improving cyber-security for your non-profit organisation is a team effort and needs to include representatives from IT, legal and compliance, HR, accounting, finance and operations departments. Order of the day should be risk management – assessing risks by making inventory of the organisation’s systems and data.

The web security assessment team’s first task is to rank systems and data according to importance and sensitivity. Risk and damage from the following events should be considered for good risk management:

  • Asset failure or loss
  • Asset theft
  • Exposure to unauthorised entry

You have a responsibility towards not just your donors but also the beneficiaries. Make sure cybercrimes don’t mar your credibility by focusing on improved security from internal and external forces. Get in touch with Lean Security for more information.

Read More
Network Security Lean Security Expert Network Security Lean Security Expert

Highlighting Open Source Software – How Detrimental It Is For Your Company

Like many businesses looking to increase productivity and efficiency without shelling out the extra bucks, you also must have thought about exploring the world of open source software.

Like many businesses looking to increase productivity and efficiency without shelling out the extra bucks, you also must have thought about exploring the world of open source software.

After all, it doesn’t make sense to spend a lot for Photoshop or Microsoft Office with better, more efficient and less costly (sometimes free) software available in the market!

Why should you even fork a ton of money on the newest Windows operating system for your business’s computer system when other cheap alternatives are easily available?

It does make sense to choose the cheaper alternative for some web applications. However, using open source software isn’t all milk and honey.

Try and learn more about this type of software before implementing in your operation.

Open Source Software – What It’s All About

It is a term that refers to something which can be modified and shared as its design is publically accessible. The term open source is normally used in the concept of software development, to design computer programs using a different or specific approach.

Open source software.png

 

Understanding Open Source Software

It is simple software with source code that allows barrier free access to content. Any software with such an open source code can be inspected, modified, and enhanced by people.

Source code is the part of software program that cannot be seen i.e. most computer users don’t ever see it. This is the code that individuals (programmers and hackers) manipulate and use to change entire aspects of a program or application. They can change how it works.

Still planning to give open source software a chance? Following are some advantages that can convince any company to try this type of software:

  • Cheaper than commercially marketed software
  • Helps an organisation become more flexible
  • Created by expert programmers
  • Highly reliable and efficient

As mentioned above, it’s not always milk and honey when it comes to using OSS. There are some disadvantages of this type of software, the first and most important one being security vulnerabilities.

While all software has some bugs and internal vulnerabilities – OSS has the added disadvantage of being used by malicious users for their own gain.

Older software usually has more security vulnerabilities that often go undetected or unreported. Make sure the OSS you are using isn’t out-of-date by many months or years.

You can have the web application security services of Lean Security at your beck and call during implementation of OSS or even closed sourced software. Check out our full service catalogue here.

Read More
Lean Security Expert Lean Security Expert

Infographic: Five Most Common Security Concerns Businesses Face Today

From untested system to exposed source, read five most common security concerns businesses face today

From untested system to exposed source, read five most common security concerns businesses face today

Read More
Lean Security Expert Lean Security Expert

Web Security Issues You’re Not Addressing

Back in 2013, a popular research study by the National Institute of Standards and Technology concluded that inadequate web security and tools cost the economy as much as $22.2 billion annually

Back in 2013, a popular research study by the National Institute of Standards and Technology concluded that inadequate web security and tools cost the economy as much as $22.2 billion annually.

Things don’t seem to be getting any better. As the modern business environment continues to grow so do the numbers of people looking to exploit key business information transmitted over the internet.

If you are looking forward to web security testing to identify if your website and applications deliver the data safety protection you promised, don’t forget to address the following issues.

Cross Site Scripting

Cross site scripting works by injecting code through a client-side script in the web application’s output. The primary concept behind cross site scripting to get hold of client side scripts and execute imminent steps just like the hacker would want.

It can be used to deface websites on your browser, redirect you to malicious websites and even hijack user sessions.

Broken Authentication

If you have issues like broken session management and authentication, address these issues before anything else. If your authentication credentials are not protected, broken sessions management could be the perfect chance to breach into your company data.

Insecure References

When a web application exposes any reference to an internal implementation page, it is called insecure direct object reference. Internal pages could show up in the form of database records, keys, directories and even other confidential information. It’s as simple as this—when a webpage leads to a reference where critical information is displayed, this page can be used to access other parts of your website including personal data.

Security Misconfigurations

Security misconfigurations often go unnoticed and they are among the most common issues behind security risks and vulnerabilities. A secure configuration must be deployed for database server, web server, frameworks, and the platform.

Double check all configurations as even the slightest error here could end up compromising your entire system.

SQL Injections

SQL injection issues involve a hacker who attempts to use application code to access, corrupt or modify database content. In case the hacker is successful, he/she will be able to edit, alter, read and delete data from backend database. While SQL injections are among the most common web security issues, they are also among the most ignored.

Looking for a penetration testing provider how offers web and application security testing? You’ve come to the right place. We offer a wide variety of services, all aimed at making your websites, applications and IT infrastructures safer and more efficient. Get in touch with us to discuss your needs.

Read More