CYBERSECURITY AUDITS

BTESA, system integrator of networks and telecommunications solutions, offers network engineering and cybersecurity services.

Currently, both private and public companies are equipped with increasingly complex computer systems to be able to carry out their business activities. Both the network equipment infrastructure and the information contained in it make up what is one of the most important assets of the company. Hence the need to protect said information and the network systems that make it possible to keep the company in operation.

The scope of these ethical hacking audits is to determine which are the most important vulnerabilities to which our client’s network is exposed. To this end, two subtypes of audit are implemented: external (“Blackbox”) aimed at possible attacks from the Internet, and internal, looking for possible vulnerabilities that could be exploited by malicious internal users.

Among the objectives of the audit are the following aspects:

• Perimeter protections

• Inventory of network equipment

• Inventory of operating systems

• Network segmentation

• Network protocol detection

• Access policy

• Password control

• Configuration database

Once the audit is completed, a report is presented with the network inventory, evidence of the vulnerabilities found and their level of criticality, and the improvements to be implemented.

BTESA proposes to its client the necessary measures to solve vulnerabilities and ensure the protection of the network, adding new network equipment, replacing existing ones or changing its configuration.

In high availability networks, the deployment of a 24×7 SOC (Security Operations Center) will be necessary to keep the network protected by detecting possible vulnerabilities in the client’s network in real time.