Penetration Testing

Penetration Testing

Subscribe to our Pentesting YouTube Playlist.

Your business is involved in the handling, processing, or transferring of federally protected information, or you are simply concerned with the protection of your employees' information and the intellectual property (IP) of your company. While you have worked hard to do the right thing, you are unsure of your compliance obligations regarding this sensitive information and the implications of what could go wrong from a business standpoint, the affected end user, or your personal liability.  One-pager here.


What are the effects of compliance? Being compliant can help your business because you can, in some cases, advertise being compliant. Noncompliance will attract regulatory attention and drive business away from your company. After all, why would a customer want to do business with a company that can't follow the rules or protect their own employees' data? One way to be more compliant is to ensure internal and external penetration testing is performed, and that there is no regulatory environment that doesn't require it.

Penetration testing can be in several forms:

Internal - Internal penetration is generally performed from the standpoint of a hostile insider. In other words, if your company had a disgruntled employee, what could that employee do to damage your company or increase risk? This could be viewed in a variety of ways, such as gaining access to the physical security system (badging), simply turning off all the magnetic doors or cameras, or allowing a hostile insider to walk into the building for uncontrolled access. Other options could include compromising printers to steal confidential data stored in print buffers or printer-based hard drives. Also possible would be a hostile insider deploying man-in-the-middle (MiTM) attacks by capturing data as it travels internally. The possible scenarios are relatively unlimited. Lastly, a hostile party will often engage in hostile insider activities if it has successfully penetrated a network using external attack methods. Should the client have an internal security team, this activity can also help exercise their skill sets, response times, overall response activity, and internal security technology configurations.

External - An external penetration test is viewed as an attack from outside the network, with attempts to steal data or to break into the target location to launch an internal attack. External testing is almost always going to involve some form of web application testing to gain access to the program and then launch further attacks from there. Quite often, data theft is possible, or hostile code is planted in the hope that legitimate users or administrators will inadvertently run it, creating further issues that only benefit the hostile party. From Arrakis' standpoint, once we have a valid external target (and an approval letter), we work with the absolute minimum information needed to simulate an actual hostile party. Similar to an internal penetration test, if the client has a security team or security-related technology, then this hostile external activity provides a perfect opportunity to exercise those teams and equipment.

Application - Application testing is simply testing the application's security controls and how the application can be compromised. Arrakis tests the application for the OWASP top 10 and other secure coding guidelines. We also apply a common-sense approach to the program itself, such as using a Social Security number as a username. Additionally, various user roles are tested for potential lateral movement or privilege escalation.

The Arrakis Methodology - Arrakis follows the same methodology regardless of what type of penetration testing is performed. After signing of an engagement letter, the potential targets are validated for legal testing, and any necessary approval documentation is completed. The initial steps are to conduct an information-gathering exercise on public target information, followed by passive reconnaissance of the target(s). If compromising information is found that could result in a successful penetration, a first attempt will be made. Assuming no compromising information is publicly disclosed, an active reconnaissance will be conducted, including a vulnerability assessment, to expand fingerprinting of the target(s). Once completed, any vulnerabilities are exploited. For internal penetration testing, programs that can be deployed in a hostile manner to gather additional information or compromise data in flight will be used.

After a PenTest: So you have had a pentest performed and would like to know where you stand. Arrakis can help you remediate issues and serve as an independent verification of remediation activities. As a part of this verification, Arrakis will provide a document indicating the status of remediation and any outstanding efforts still in progress. Additionally, Arrakis can help provide a long-term plan to reduce risk for future penetration testing.

Pricing - Arrakis offers a flat fee of $36,000 per year for pentesting-as-a-service, including monthly pentests for up to 500 devices. This Pentest-as-a-Service price is significantly lower than one-off penetration testing from other companies.  Having said that, Arrakis cautions companies not to fall into the trap of any pentest that is less than that, as it is likely a vulnerability assessment masquerading as a pentest.  While the company may not be able to detect the falsehood, an auditor will.  In other words, if you are being offered a pentest for a price that seems far too good to be true, then it's probably not a pentest.   While pentests are generally only required annually per regulation(s), doing it more often is far more beneficial to a company that wants to reduce risk.  Manual pentesting is also possible; however, it must be scoped and understood that it is much more expensive.  See our one-pager on our Penetration Testing as a Service here.

We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us