CYBERSECURITY

Set guardrails, identify threats and safeguard confidential information - quantifying and reducing risk with outputs visible to executives and boards

SCOPE AND DELIVERABLES WE FOCUS ON

DCO Enterprise seeks to deliver a simpler and refined cybersecurity approach. We focus on the critical information and findings, seeking to remove as much "fluff" and filler content as possible that modern reports contain. We accomplish this through automation of the vulnerability assessment process, improving efficiency and streamlining the delivery process. This in turn improves service we provide, allowing for a cheaper and faster alternative.

VULNERABILITY ASSESSMENT SERVICES

Targets

agreement, stakeholder management, trusted advisor

Web applications, Including: Web apps, APIs, external IPs and cloud services

Approach

Requirements management, trusted advisor

Non-Intusive, passive scanning and analysis matched to over 250,000+ known vulnerabilities

Scope

Accelerators

External perimeter testing of target; no authentication or authorisation checks

Passive scanning and analysis against known vulnerabilities, cross-referenced against OWASP and CVE databases

COMPLIMENTARY EVIDENCE AND INFORMATION

Penetration Test Types

Uncovering the OWASP Top 10 API Vulnerabilities

FAQs

Cybersecurity: Securing your business and assets

These questions detail the core features, components and details of our cybersecurity services. This provides a more comprehensive explanation of our services, exploring common inquiries such as the type of tests we offer, possible targets for our services and what information is received from the service. This allows you to purchase our services with a clear mind and understanding.

What type of tests are offerred?

DCO Enterprise offers black-box vulnerability assessments. This approach tests targets using zero prior knowledge to simulate real-world threats, while remaining non-intrusive through passive automated scans. This is known as an external test, using internet traffic and network packets to analyse weaknesses and compare them against known vulnerabilities. This does not cover authentication or authorisation checks.

What is the difference between an 'external' and 'internal' test?

An external test acts outside of the system, attempting to exploit vulnerabilities that can be performed without authorisation and authentication permissions. As such an external test does not test for these vulnerabilities, unlike an internal test, which assesses the weaknesses inside of a system, assuming it has already been exposed. DCO Enterprise offers external tests, so we do not test for authorisation and authentication threats or any other internal weaknesses.

What level of privacy is maintained during testing and how deep does the service test?

All tests require digital signature and confirmation before they are conducted, ensuring permission is given before testing. Due to our passive, non-intrusive approach our tests maintain our clients privacy without interfering with their system's functionality or confidentiality. In terms of depth, our tests do not penetrate the internal system as they are external tests ensuring no private functions or stored information is exposed.

What are the possible targets of our vulnerable assessment services?

Our tests can target all accessible web-services as long as it has an IP address and is publicly accessible on the internet. The preliminary target is websites, but our tests can also analyse APIs and web applications.

Will the vulnerability assessment hinder or impede business or web service functionality?

The vulnerability assessment services we provide are passive, non-intrusive scans. They do not impede any functionality of the service as all testing is done externally, ensuring the targeted service is unaffected and suffers no impediments.

How does the vulnerability assessment detect and determine threats?

Our vulnerability assessment services detect threats by analysing network packets and internet traffic through comprehensive scans sent to the target. The scan is cross referenced against the OWASP Top 10 database and Common Vulnerability Exposure (CVE) database, using their records to match against any known vulnerabilities. Any matches are recorded and detailed inside the report, defining what the weakness is and the severity of the threat.

What evidence and information is recieved?

Our reports examine and compare their findings with the OWASP Top 10 and the Common vulnerability Exposure (CVE) databases, ensuring a comprehensive and quality test. The report flags any known weaknesses found which match against the databases to provided a simple and detailed overview of the security framework of the tested asset. This includes an assessment of the threats risk level, a description of the threat, a short solution and a link to the vulnerability in the Common Weakness Enumeration (CVE) database for more information.

Still have questions? Ask our AI Agent in the bottom right or reach out and contact us!