Project Description
Cybersecurity project in Africa
BTESA has carried out the cybersecurity audit for one of the most important telecom operators in Africa. The objective of the audit has been to expose the vulnerabilities discovered in its systems. Tor this purpose, some tests have been carried out from two different perspectives: external audit (simulating an attacker without prior knowledge of the exposed systems) and audit of the internal networks (where an attacker is already inside the corporate network).
The main purpose of these tests has been to evaluate the state of the security of the entity’s systems and discover possible vulnerabilities that could endanger said information systems and the data stored in them.
For this purpose, the testing has been carried out in two phases, a phase of recognition and collection of information: software used, programming errors, disclosure of internal information, etc. After the subsequent analysis of the information collected, we moved to the exploitation and vulnerability assessment phase (provided that said action does not affect the availability or integrity of the audited systems).
The exploitation phase has been carried out in such a way that there was no outage in the client’s network and network services.
BTESA has classified the detected vulnerabilities according to the following criteria:

In the external audit, aspects of circumstances have been found:
• In summary, the exposure of network systems from the Internet is considered medium level.
• There are exposed services that use clear text protocols.
• There is no perimeter system that has detected and reacted to the exploitation tests carried out by the auditor.
During the audit of the externally exposed systems, a total of 5 vulnerabilities have been detected, of which two are considered to have a medium risk.

During the internal audit, critical vulnerabilities were found that pose a serious risk to the systems, data and operations of the company:
• It is necessary to implement filtering between different network segments
• Obsolete operating systems have been found without support from the manufacturer
• A correct password policy must be implemented
During the audit of internal systems, a total of 8 vulnerabilities have been classified

As a result of the audit report, the following have been proposed as possible improvements:
• Filtering between segments of the client’s network
• Operating systems update policy
• Installation of an EDR in all the company’s systems
• Centralized authentication system
• Define in a communications security policy which protocols
• Install a vulnerability management system
• Implementation of a SOC