SCADA | ICS Risk Assessment
It is true that a simple Nessus or Nmap scan can bring down a critical control system application. However, isn’t this something you should know and address before an attacker or an IT Department staffer gains access to the SCADA or ICS and inevitably starts with these tools?
Our team uses an arsenal of assessment testing tools and methodologies similar to those used by attackers on the net: automated scanning tools, commercial scripts, in-house developed scripts, manual tests, customized proprietary scripts and best of breed open-source penetration testing tools specific to ICS/SCADA applications/protocols. We test for exploitable vulnerabilities that could allow unauthorized access.
Our team performs comprehensive assessment of your critical infrastructure in following manner:
- Security Architecture Review
- Evaluate the network design of the SCADA/ICS environment, analyzing the security controls in place and the connectivity between the SCADA environment and the corporate network.
- Critical Infrastructure Security Testing
- Evaluate the security of systems in the SCADA/ICS environment including routers, firewalls, control system servers, database systems, and ICCP gateways.
- Host Security Configuration Review
- Assess the configurations of routers, firewalls, and SCADA/ICS servers against known industry best practices while looking for known vulnerabilities associated with the deployed product and associated utilities.
- Wireless Access Review
- Identify wireless access into the environment and evaluate weaknesses that could allow an attacker to gain access to the SCADA/ICS network.
- Remote Access Review
- Identify systems with dial-up and remote access capability that could allow an attacker to gain access to the SCADA/ICS network.
- Policies & Procedures Gap Analysis
- Evaluate the current policies and procedures for critical infrastructure against known best practices according to the ISA-SP99 security standards.
- Interviews with managers, operators, engineers and system administrators
- Review and audit of key procedures such as change control, backup, incident detection and recovery
- Analysis of the ability to recover from a cyber-attack
- Analysis of the physical security of cyber assets
- We provide comprehensive report with prioritized list of vulnerabilities, compensating controls for vulnerabilities that cannot be directly addressed.
- Actionable recommendations to mitigate the risks your environment faces from external attackers, Insider threats, automated worms, and network management errors to maximize improvement of your environment security posture.
- Vulnerability Management portal
- Realtime CIO dashboard.
- Online submission and tracking of VA/PT tasks.
- Downloadable reports.
- Track closure of vulnerabilities identified.
- Our team has extensive expertise from simple to complicated infrastructure security issues currently facing modern enterprises, such as cloud computing, virtualization, VoIP, Wireless Networks and Storages.
- Our testing methodologies and the skills of our team have been developed and continually improved over the course of numerous client projects. This enables us to help you stay one step ahead in ensuring that your systems and infrastructure are secure.
- Key benefits such as
- Empanelled with Government of Maharashtra, CERT-India and NASSCOM.
- ISO 27001 Certified Company.
- CEH, CISSP, eCPPT, OSCP, SCADA PenTester certified professionals.
- Use of Industry Recognized frameworks such as OSSTMM, OWASP, WASC, ISO 27001 etc.