Security audit and testing
A review of the network, servers and accounts from outside and inside, with findings ordered by what actually burns.
A hundred item report helps nobody. What helps is knowing which five things somebody outside could use today, and which of those are one afternoon of work away from being closed.
A real case: the forgotten way in
A few years ago a company opened Remote Desktop (RDP) to the internet so an outside bookkeeper could work from home. The arrangement ended, the port stayed open, and so did a user account with a weak password. The server logs show hundreds of failed sign ins a day from addresses all over the world.
Nobody who works in the system every day notices things like this, because everything works normally.
The fix is simple: close the port, disable the account, and put remote work behind a VPN with two factor sign in. The harder part is checking whether anyone already got in, so the logs are searched for successful sign ins and for new user accounts.
What we review
- From outside: which services and ports are visible from the internet and which software versions they give away
- Firewall and router: rules, port forwards, firmware version
- Accounts in the domain or in Microsoft 365: inactive users, administrator rights, two factor sign in
- Servers and computers: patches, local administrators, disk encryption
- Wi-Fi: separation of the guest network and the security mode in use
- Mail: the domain's SPF, DKIM and DMARC records
Each finding comes with a description, evidence and a recommendation, and the list is ordered by how easy the weakness is to exploit.
Scope and limits
We test only with written permission from the owner of the systems, stating the scope, IP addresses, time windows and a contact person. Without it we scan nothing, not even for existing clients. Where part of the system is run by a third party, such as web hosting or a cloud service, their testing rules apply as well, or their consent is needed.
An audit shows the state of things at the time of the review and cannot uncover every last weakness. What is closed today may be open tomorrow, so it makes sense to repeat it after significant changes to the network.
Common questions
Can testing bring the system down?
The review is non intrusive and should not affect day to day work. Tests that could strain older equipment are agreed in advance and run outside working hours, or left out.
Is an audit the same as a penetration test?
Not quite. An audit reviews settings and practices from inside and outside, while a penetration test actually tries to exploit a weakness to show how far an attacker could get. Which one you need is agreed based on the risk.
How much does a security audit cost?
It depends on the number of servers, sites and services exposed to the internet. The scope is set in an initial conversation and the quote follows from it.