Penetration Tests and Ethical Hacking - an exercise to simulate a hacker to exhaustively and rigorously finding the flaws and vulnerabilities of a target and perform everything a hacker could to penetrate the systems.
Our services are carefully planned, controlled and executed as safe tests such that potentially harmful actions must be approved and acknowledged by the clients first.
We offer the following categories of Penetration Test Services:
Wireless Network Penetration Test
Internal Network Penetration Test
External Network Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
Security Risk Assessment and Audit - The exercise to fully evaluate and understand the assets of the subjects and to evaluate and minimize the security risks threatening the assets.
From the concrete Physical Security to the logical System and Network Security, our consultants will understand and evaluate all of the security risks with objective, clear and fair justifications and provide the clients with recommended actions to minimize the identified risks.
Security Audit could also be performed to verify the effectiveness of the actions to minimized the identified risks.
Our Vulnerability Management services ranging from the consultancy, design and deployment of in-house Vulnerability Management Systems for regular compliance check and vulnerability discoveries to ad-hoc on-demand Vulnerability Assessment services.
Knowing the vulnerabilities in your environment timely and accurately with them will be essential to defend against unwanted malicious attacks.
You have rigorous and well defined security policies and guidelines. You have cutting-edge security appliances in-place. You have the most advanced firewalls installed.
These things are great on their own but are you sure they are working as intended in harmony and are really efficiently complementing each other?
Security Architecture is about making sure all components, whether physical, technical or administrative, are appropriately designed and placed in a mutual-complementary position to maximize the security protection effect.
Nowadays Cloud and Virtualization technologies are gradually becoming the major players in IT. Could you guarantee your data is securely protected in a Cloud or Virtualization multi-tenancy platform?
Our consultants have experienced in deploying large scale virtualization and cloud platform with rigorous security requirements such that we understand the risks and challenges faced by the new technologies.
Our consultants have practical experience in helping clients to prepare for and acquire the ISO/IEC 27001 Information Security Management System and ISO/IEC 42001 Artificial Intelligence Management System Certification ranging from smaller scope of a business function to a large scope of whole company certification.
We communicate regularly with the certification bodies to understand the requirements of successfully passing the certification audit.
When things are smooth everything is smooth.
However if an incident strikes, many companies are not ready to make quick and accurate responses such as containing and minimizing the impact of the incident and handling the public relations matters.
Incident Response Management is the formal process to classify what constitutes an incident and to define and communicate across different related departments the expected responses to minimize the impact and tangible or intangible asset loss.
After a security breach it will not be simply closing down the incident.
There is a need to understand what is the root cause of having the security breach or incident.
Computer Forensics is the professional exercise and techniques to investigate and retain evidence of a security breach for legal actions and root cause analysis to prevent the same breach from happening again.
There have been quite a number of incidents of intentional or accidental privacy breach.
Organizations have to be very conscious about the privacy risk of any new systems or applications before bringing them to production and the Privacy Impact Assessment would be the best exercise to evaluate the privacy risk and to take appropriate controls.
Our consultants have been supplying the baseline security configurations of different platforms to different organizations with different business natures.
Baseline Security Configuration is not just setting a rigid and standard configuration for all organizations but rather every configuration setting needs to be justified and confirmed as applicable in the specific organization. Any configuration item that is not implemented should be risk assessed and the controls should be documented and evaluated.
We understand the needs of all business and we are strong in arriving an applicable yet secure baseline security configuration for the specific organization.
Ranging from pieces of software like Anti-virus, Endpoint Protection, Mobile Device Managmenet to pieces of hardware like Web Application Firewall, Next-generation Firewall and Data Leakage Prevention appliance, we have the deep experience in integrating security products in a large practical environment.
GRC is the collective set of tools and internal controls to make sure the organization is complied with the internal and regulatory requirements on security. We are able to integrate GRC application to automate and manage the internal controls such that the management would be easy to check the GRC status.
The emergence of APT attacks is causing a lot of alarming and catastrophic loss to some famous organizations.
APT attacks are very sophisticated, organized, stealth and hard to detect. We partner with security intelligence vendors to deploy true APT prevention deployment in your environment such that APT attacks could be stopped before any damage.
Some organizations do not have a set of formal security policies and guidelines while some organizations have not updated their policy documents to adapt to the current environment.
We provide professional security policies and guidelines consultancy services such that a set of appropriate security policy documents covering all of the actual needs of the organization will be drafted and put in place.
We have been tackling and handling security incidents and break-in during the past 15 years. Sometimes we are engaged urgently because the clients are in deep troubles. We could help to provide professional advices on the best moves to safeguard the information and financial assets should an attack is in place or believed to be successful.
We would also provide emergent security incident handling services which require high level of techniques and broad experience of handling security incidents.
Organizations would need regular security awareness or technical training because of internal or regulatory requirements.
We would provide tailor-made security training services for clients and the training could be ranging from general security awareness training to very technical topics such as penetration test and specific security product training.