CYBRI’s pen testing methodology relies on our experience and our security lifecycle that we provide to clients. Typical methods focus on just the test itself, but we extended it to a multitude of items that go behind the test. Our focus is the relationship and improvement with the test beyond the results.
Discovery
Our methodology starts, like many others with Discovery. We look to quantify everything in scope and ensure your company covers everything important. Ideally, the first few tests are white-box, or a transparent test, to uncover as much as possible. As maturity increases, the discovery phase shifts to the tester using reconnaissance to discover.
Red Team in Action
This phases most other methodologies’ steps that we wrap into one. PTES, OWASP, OSSTMM, and others cover this in-depth, so we wrap this into a single test that outlines the testing phase for a client. Often it is seen by a customer as a single phase, so the nuances can be lost or are insignificant. This step aims to uncover as many weaknesses as possible and simulate an actual attack.
Reporting
The reporting phase involves the preparation and delivery of the report to the client. The latter is important to convey every finding and its implications. Simply delivering a 100+ page report is not enough. CYBRI aims to clarify weaknesses and explain each finding’s significance. More than just a severity, we offer risk quantification and prioritization.
Collaboration
Our Collaboration phase goes beyond simple remediation by your team. We look to work hand in hand with the internal team to suggest areas of improvement and the best ways to maximize effort. We aim to ensure the fixes are implemented correctly for the retest, so the next test doesn’t just have the same findings.
Retest
A retest is a phase where CYBRI aims to validate your team’s strenuous efforts to fix the findings. This gives you the confidence that the problems have been solved, and you can move on to new issues. This is important to make sure that the following tests don’t just yield the same results.
Repeat
CYBRI aims to be there beyond the test. Repeating can be partial as needed or larger scheduled tests. Testing annually is important to ensure your security is updated and tested with the latest tools.