Menu

Call us on 03450 21 21 51

Repositioning the penetration test: prioritising performance insights over tolerable risk
The SRM Blog

Repositioning the penetration test: prioritising performance insights over tolerable risk

Dean Moulden

Written by Dean Moulden

23rd July 2021

Share this article

pen test for performance

Today, penetration testing is a staple of good cybersecurity practice. Born from the ethical hacking industry of the late 90s, penetration testing is used by organisations of all sizes to assess system and network risks. What’s more, mandatory penetration testing has become an intrinsic part of addressing data protection laws, privacy regulations, compliance and cybersecurity guidelines.

Yet for many organisations, penetration testing is still considered to be something of a tick box exercise – a task that needs to be completed rather than an opportunity to enhance performance and increase resilience as a successful and responsible enterprise.

While there are certainly many diligent and conscientious organisations that value penetration testing highly, others care more about getting a clean pen testing summary to share with customers than actually identifying and rectifying potential threats.

In order to utilise penetration testing to its maximum potential, organisations must reframe their approach to this critical information security service.

 

Official guidelines on pen testing highlights the need for mandatory measures

For any organisation seeking to gain or retain ISO27001 certification or achieve PCI DSS compliance, annual penetration testing will already be familiar. However, even for those that are meticulous about conforming with recognised information security frameworks aren’t guaranteed to get the full value from such an exercise if their sole focus is compliance – rather than resilience. Failure to scope any test and exercise project correctly can result in blind spots or missed opportunities to improve security more broadly.

Similarly, failing to remediate vulnerabilities effectively post-test is a common issue that should be avoided if an organisation genuinely wishes to mature its information security management.

At SRM we always take a considered and holistic approach to scoping that takes into account not just the fundamental requirements of accreditations such as PCI DSS or ISO27001 but also the current and future demands on an organisation’s systems and digital estate.

While it can be tempting for businesses to opt for the cheapest penetration testing solution offered by a provider who performs little more than a cursory vulnerability scan, even the most cost-conscious organisation needs to keep in mind that the potential benefits of a thorough and detailed test far outweigh the upfront cost implications.

 

Penetration testing is more than a box to tick – it’s a necessary step to improving performance

Despite the clear language and implied legal duty expressed in security guidelines around the world, it has taken a scare to encourage many businesses to take cybersecurity seriously. Following the SolarWinds hack, more and more suppliers have asked for ISO 27001 or SOC 2 annual audits reports, as well as remediation steps and regular penetration testing. Penetration testing is gradually becoming a contractual requirement for businesses handling sensitive data and trade secrets.

This can only be a good thing when it comes to protecting data and assets. Even if regulations don’t enforce it, organisations should still start perceiving penetration testing as a legal duty rather than just a formalistic security task. When completed thoroughly, penetration testing can act as a valuable contribution to a company’s competitiveness in the global market, as more and more customers are coming to care strongly about the security of their personal information.

If gaining a greater understanding of your organisation’s vulnerabilities is on your priority list for 2021, why not get in touch with us today by clicking here.