{"id":65301,"date":"2021-10-04T08:29:00","date_gmt":"2021-10-04T07:29:00","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=65301"},"modified":"2023-05-25T10:31:39","modified_gmt":"2023-05-25T09:31:39","slug":"vulnerability-assessment-penetration-testing-or-red-teaming-which-is-right-for-your-enterprise","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2021\/10\/04\/vulnerability-assessment-penetration-testing-or-red-teaming-which-is-right-for-your-enterprise\/","title":{"rendered":"Vulnerability assessment, penetration testing or red teaming: which is right for your enterprise?"},"content":{"rendered":"\n<p><strong><em>Red teaming is a service focused on the assessment of a company\u2019s operational security capabilities via conducting a sophisticated attack simulation exercise and evaluating detection and response reaction of defending SOC specialists (blue team). Alexander Zaytsev, Head, Security Assessment, Kaspersky, explains the difference between red teaming and other services including vulnerability assessment and penetration testing.<\/em><\/strong><\/p>\n\n\n\n<p>More than a third of enterprises experienced a targeted cyberattack in 2020. So, you might say that it\u2019s important for companies to understand how their security operations would hold up if they are faced with similar sophisticated threats. Arguably one of the best ways to achieve this understanding is to look at your own organisation from a threat actor\u2019s standpoint. Unfortunately, there\u2019s a plethora of security assessment service offerings out there, masquerading behind misleading marketing materials.<\/p>\n\n\n\n<p>What are security assessment services all about? From our experience, customers often get confused between three types of services \u2013 vulnerability assessment, penetration testing and red teaming.<\/p>\n\n\n\n<p>Unfortunately, in the field of information security, a lot of shiny, new terms eventually get promoted aboard a hype-train for a never-ending ride of supply-creating demand. This was true when penetration testing first became a thing and the same is true today for red teaming.<\/p>\n\n\n\n<p>Almost any security service provider on the market is ready to offer some form of \u201cred team\u201d service, because more and more regulations demand it, resulting in more and more requests for proposals (RFPs), which push requests for \u201cnew services\u201d.<\/p>\n\n\n\n<p>Closer communication with customers reveals that in around 80% of all the requests we receive for red teaming, the company is actually looking for good, old fashioned penetration testing.<\/p>\n\n\n\n<p>This discrepancy is perfectly understandable, because the \u201cpenetration testing\u201d term is currently just as muddied by marketing as \u201cred teaming\u201d. The only difference being that you could easily end up getting a vulnerability scan labelled \u201cpenetration testing\u201d and companies will often overlook this option in favour of an \u201cupper tier\u201d service.<\/p>\n\n\n\n<p>That being said, we consider that the key steps to fulfilling your own expectations from any kind of security assessment service are: taking the time to formulate your needs and ensuring that the vendor understands how to satisfy them with their offering.<\/p>\n\n\n\n<p>To once again demonstrate how vulnerability assessment, penetration testing and red teaming differ, we\u2019ll consider three basic criteria &#8211; the goal of the service, its scope and methodology.<\/p>\n\n\n\n<p><strong>What\u2019s out there?<\/strong><\/p>\n\n\n\n<p><strong>Vulnerability assessment<\/strong> (VA): The most common service of the three, is an automated or semi-automated approach to the identification of security issues. Its goal is to discover as many publicly-known vulnerabilities as possible among a strictly defined set of systems, ideally minimising false positive results. The methodology is quite simple, and boils down to pattern matching data received from a network service against a database of known security issues. Such a straight-forward approach allows for a great level of automation, thus gaining the advantage of speed and repeatability. Disadvantages on the other hand are quite obvious too: in the end, all you get from a VA is a list of existing well-known vulnerabilities.<\/p>\n\n\n\n<p>We\u2019re not stating that VA is not the right service for you; it is a crucial part of the vulnerability management program in any security-mature organisation, alongside asset inventory and change management processes.<\/p>\n\n\n\n<p>Keep in mind that VA has nothing to do with any kind of simulation of adversarial behaviour. So, if a service provider you\u2019ve enlisted for penetration testing or red teaming engagement mostly relies on an automated vulnerability scanning solution in the course of their work \u2013 they are not doing it right.<\/p>\n\n\n\n<p>Now with vulnerability assessment addressed, let\u2019s take a closer look at penetration testing before digging into red teaming.<\/p>\n\n\n\n<p>As the name implies, penetration testing (pentest) aims to demonstrate how a security boundary could be breached, allowing a threat actor to get from point A to point B inside an organisation\u2019s network. Unlike a vulnerability assessment, pentest goes beyond plain enumeration of potential security weaknesses: proper penetration testing engagement, applied to an external perimeter, corporate network or both, would show how a malefactor would behave if targeted to compromise a company\u2019s IT infrastructure.<\/p>\n\n\n\n<p>Methodology-wise, pentest is mostly a manual service that relies more on the knowledge and experience of the expert team performing it rather than on tooling and automation. Considering the above, you should plan the project accordingly: typical engagement might take you everywhere from 30 to 60 business days for the practical part and reporting. And since reporting is the key deliverable of the whole exercise, when choosing a service provider, pay close attention to what would be included in your report. Most established vendors would have a sample report that you could request to evaluate whether the final product would match your expectations.<\/p>\n\n\n\n<p>Finally, a <strong>red teaming<\/strong> service is focused on the assessment of a company\u2019s operational security capabilities via conducting a sophisticated attack simulation exercise and evaluating detection and response reaction of defending SOC specialists (blue team). Though it may look similar to penetration testing, there are significant differences behind testing security operations (OpSec) and looking for attack vectors.<\/p>\n\n\n\n<p>The methodology and scope of each red teaming exercise are heavily dictated by threat intelligence (TI) gathered prior to the engagement. During penetration testing, a service provider is trying each and every attack vector that would aid in breaching IT infrastructure security. During red teaming, the customer and service provider develop a set of goals together, to be reached via a corresponding set of attack scenarios. These would be the most relevant for the company based on the results of a deep threat intelligence research. In most cases the scope would not be limited by any particular IP addresses or domains, instead covering the whole organisation, including people and processes. These kinds of exercises also last longer than any others, half a year or even longer, due to the need to simulate low-profile behaviour of a real attacker.<\/p>\n\n\n\n<p>So now when you\u2019ve seen all the typical propositions and weighed up your real needs, ask yourself one more question before starting the hunt for the top red teaming service provider: \u201chow did my SOC perform the last time we ordered a proper pentest?\u201d If your answer is akin to: \u201coh, well now I\u2019m unsure if we\u2019ve ever conducted one\u201d or \u201cactually we don\u2019t have a dedicated security operations team right now\u201d, then you probably won\u2019t get the bang for your buck that a red teaming engagement would cost and you may get better value from hiring an expert penetration testing team. Just remember to ask them to keep a timestamped track of all the indicators of attack and compromise. If, on the other hand, your answer would include such cryptic terms as, \u201cthreat hunting\u201d, \u201cMTTD\u201d, \u201cMTTR\u201d or similar \u2013 then chances are you\u2019re good to go for a red teaming adventure.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Red teaming is a service focused on the assessment of a company\u2019s operational security capabilities via conducting a sophisticated attack simulation exercise and evaluating detection and response reaction of defending SOC specialists (blue team). Alexander Zaytsev, Head, Security Assessment, Kaspersky, explains the difference between red teaming and other services including vulnerability assessment and penetration testing. [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":65302,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5307,137,5,139,6,36,9961,13],"tags":[364,2528],"class_list":["post-65301","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-blog","category-enterprise-security","category-industry-expert","category-insights","category-intelligent-technology","category-thought-leadership","category-top-stories","tag-kaspersky","tag-security-assessment"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/65301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=65301"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/65301\/revisions"}],"predecessor-version":[{"id":65303,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/65301\/revisions\/65303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/65302"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=65301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=65301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=65301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}