Penetration Testing for PCI-DSS
Your internal IT and connected systems are the nervous system of your business. Making sure that it is maintained and healthy is critically important to all business, but more so for PCI-DSS regulated businesses. The PCI-DSS mandates, in requirement 11.3 that all PCI-DSS regulated businesses must undergo an annual penetration test to maintain their PCI-DSS compliant status.
Why is it important
Our Small Business PCI-DSS penetration testing service identifies vulnerabilities and security weaknesses that are present within your networks and connected systems. Internal infrastructure-related weaknesses and vulnerabilities often originate from poor hardware configurations, ineffective system configuration parameters and weak security system controls. Criminals exploit these through malware, phishing and social engineering attacks to gain access to previously private resources.
Our internal infrastructure penetration testing service will help you:
- Gain real-world insight into your vulnerabilities;
- Identify which vulnerabilities will affect your PCI-DSS compliance status;
- Check and test network segmentation;
- Check for rouge wireless devices;
- Identify any missing patches;
- Identify weak configurations;
- Harden software and systems;
- Identify where inappropriate services that increase your exposure.
What the test entails
We will perform a complete infrastructure level penetration testing following the OSSTMM (Open Source Security Testing Methodology Manual) and PTES (Penetration Testing Execution Standard) methodologies. These methodologies ensure we identify any weaknesses that could allow an attacker to compromise the network, the data stored within it, or the devices hosted.
One of our CREST certified testers will perform your penetration test. The test will:
- Conduct a series of automated vulnerability scans;
- Provide immediate notification of any critical vulnerabilities to help you act quickly;
- Carry out a range of manual tests using a methodology closely aligned with the OSSTM and PTES methodologies;
- Produce a detailed report that identifies and explains the vulnerabilities prioritised by the risk posed to your business, not based on CVSS scores;
- Identify a list of recommended countermeasures to address any identified vulnerabilities;
- Include an executive summary that explains what the risks mean in business terms.
COVID-19 remote delivery options
Despite the current COVID-19 situation, we remain fully operational and at your disposal. Hedgehog fully embraces flexible and remote working. We adjust our delivery methods to provide consultancy services, penetration tests, and training remotely where necessary. Hedgehog fully embraces flexible and remote working. We adjust our delivery methods to provide consultancy services, penetration tests, and training remotely where necessary.
Why choose Hedgehog
We only use experienced penetration testers to carried out clients penetration tests. Our penetration testers have the necessary technical skill set, qualifications and industry experience. They have the strong technical knowledge and proven track record needed to enable a successful penetration test. Our testers can carry out safe exploitation of applications and systems, advising on the appropriate mitigation measures required to ensure that your systems are secure. Our CREST-certified penetration testing team will provide you with clarity, technical expertise and peace of mind. Our experienced testers will have reviewed your scoped environment, tested it to the fullest during the time permitted and will provide you with a detailed report.