Security Test Scoping

Every organisation knows security testing is a clearly defined requirement to meet compliance standards. Which systems should be tested, the threats that should be simulated and the efforts of the simulated attack are however less clear cut.

Many organisations take a tick-box approach to security testing, and therefore miss the value in completing the exercise. Blackfoot consultants review a company’s data to identify which data assets are of value to a potential attacker and what lengths an attacker would go to, to compromise it. This provides clients with a clear understanding of the threats they are likely to face and allows subsequent testing to focus on the effectiveness of the security controls in place and prioritise its security approach.

