Re: SME risk assessment (Was: Bank Assessment)

miguel.dilaj_at_pharma.novartis.com
Date: 04/26/04

  • Next message: Steve Goldsby (ICS): "RE: Why eEye Retina (was MBSA scanner)"
    To: "Jason High" <strongcypher@hotmail.com>
    Date: Mon, 26 Apr 2004 17:24:01 +0100
    
    

    Hi guys,

    I've a small comment. So small that perhaps it won't be approved for the
    pen-test list (specially since I removed the discussion from my answer ;-)

    It's my impression that you're talking about the risk of someone getting
    their hands on the company's information.

    What about the risk of someone getting access only to use the resources?
    What if the h4x0r doesn't care about the company's assets?
    Given control of some of the company's systems everything can be done
    using those systems as a base to launch further attacks.
    The risk of being blamed for hacking activities, DoS, storing child porn,
    etc., have to be considered as well, and absolutely every individual and
    company out there is exposed to that if someone can compromise their
    systems. The publicity impact can be also very serious.

    I can perfectly understand your recent discussion if we don't take into
    account the above, and I tend to agree with you (if I understood you
    correctly). Both of you are partially right.

    Cheers,

    --
    Miguel
    aka Nekromancer
    WHAT password cracker? Do you know Lepton's Crack?
    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------
    

  • Next message: Steve Goldsby (ICS): "RE: Why eEye Retina (was MBSA scanner)"

    Relevant Pages

    • RE: Which Windows OS is Safest (fwd)
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... of an Ethical Hacker to better assess the security of your organization. ...
      (Security-Basics)
    • DC Phone Home from BH 2002?
      ... automated tools or scripts and references to this 180-degree hacking from ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Pen-Test)
    • Call For Papers : HITB Security Conference 2004
      ... Hack In The Box Security Conference 2004: ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)
    • RE: EC-Counsil (Book Review) Can we wrap this thread up?
      ... >>>Ethical Hacking at the InfoSec Institute. ... >>>with one of our expert instructors. ... >>>learn to write exploits and attack security infrastructure. ...
      (Pen-Test)
    • RE: Securing web site with redundancy ?
      ... In 2000 with IIS5 you can do webserver clustering from within IIS ... > Ethical Hacking at the InfoSec Institute. ... > learn to write exploits and attack security infrastructure. ... interaction with one of our expert instructors. ...
      (Pen-Test)