Penetration tests

Penetration tests are needed to identify vulnerabilities of systems, non-compliance of security policies and incident detection, as well as prevention of possible incidents.

The penetration test is performed in accordance with ISO 27001 recommendations.

The purpose of a penetration test is to simulate a cyber attack, attempt to penetrate a company's systems. The test made in the context of both an external attacker and a company employee who has limited access to the company's infrastructure.

Tests are individually agreed and carried out for each specific company, with clearly defined times, techniques, methods, objects, and scale of intrusion.

The Penetration test is performed by the OptiCom qualified Certified Ethical Hacker specialist.
Confidentiality is maintained throughout the service process.

• Planning;
• Reconnaissance
• Analysis of information and preparation for an attack
• Attack;
• Analysis of results and preparation of reports
• Recommendations on the prevention of vulnerabilities.

• Black Box – auditors know only the name of the company, testing takes place from locations outside the company's infrastructure
• White Box – auditors have all possible knowledge about the target of the attack;
• Gray Box – auditors have partial knowledge of the infrastructure and the target of the attack.

• Checking the security situation of the company's IT infrastructure
• Identification of vulnerabilities and possible attack directions
• List of infrastructure vulnerabilities and recommendations how to prevent them.
