Showing posts with label First Base Technologies. Show all posts
Showing posts with label First Base Technologies. Show all posts

Sunday, 11 May 2014

Infosec 2014 Highlights

A week after Infosec, we can look back and say it was a great show. Twenty years on, it still successfully delivers insights into the dynamic market of information security. With 340 companies, of which 80 were new exhibitors, special country pavilions for 24 international representatives and a great wealth of products, tools and services, there was plenty on offer. 


Source: @InfoSec_Joy

The discussions and panels were up to date with current changes to the economy, legislation and global trends in cybersecurity and experts, such as Peter Wood, Mikko Hypponen, Graham Cluley, Dr. Eric Cole, Rik Ferguson and James Lyne, attracted audiences with panel debates and thought-provoking updates on the industry. 


James Lyne (left) and Rik Ferguson (right) on a thought-provoking revelation Credits to @DanRaywood
      As cybercrime increases, cybersecurity will constitute a business driver in the future. 

Many speeches and presentations have brought fresh views for information security professionals, but the one we liked best was MP David Willetts’ keynote speech. The highlight of his keynote at Infosec has been the 2014 Cyber Security Breaches Survey launch. As he went through the highlights of the survey, he also reminded the audience of how the Cyber Growth Partnership "aims to increase the value of cyber security exports to £2bn a year by 2016". As cybercrime is a costly strain on UK business, cybersecurity can be a chance to boost the country’s economy. 





 Peter Wood moderates the debate. Source: scmagazineuk.com
  Meanwhile, Peter Wood, CEO at First Base Technologies, and a keen user of Nipper Studio, moderated a panel debate on "Security as a Business Enabler". The general consensus of the conversation was that while there's little evidence to support that information security actively brings in profits, global breaches have shown that they do drive away business. He also found time to drop by our stand for a quick catch up - Thank you, Peter!

   The Malvern Cyber Security Cluster is growing. 

      But for the cyber security companies trading from the “cyber valley”, there was good news as the Minister, David Willetts, congratulated the  7 winners of a total of £500 000 in investments for R&D from the Technology Strategy Board
      It was rewarding to see that the Malvern Cyber Security Cluster is taking centre-stage at an event such as Infosec Europe. D-RisQ Ltd, Montvieux Limited, PixelPin, C2B2, Infinite Precision Ltd, Babble IT Systems Ltd, Westgate Cyber Security Ltd deserve congratulations for their innovation and techniques in the cyber security industry. 


 Titania's software and updates proved attractive to visitors once again. 

Titania went to Infosec with great products, a relentless team, champagne and a lot of chocolate. We came back with fresh questions to answer, plenty of compliments and (sadly!) no more chocolate. 




    
Mark & Peter (Hedgehog Security) & Steve Penny (middle)
We saw an increased interest in compliance and security auditing this year, as well as answering a lot of questions on our upcoming product - TEC. We met lots of friends on the Malvern Cyber Cluster stand as we took turns to attend to the booth – Advent Security, Borwell, DeepSecure, UK Cyber Security Association, Sutcliffe & Co., Hedgehog Security.




 

At the end we bumped into Pen Test Partners when we went out for some well-deserved burgers. To our surprise the burgers did not come from their ad-hoc kitchen – apparently their “cooking” skills were a tad more sophisticated.  

Pentest's Kitchen... Cooking up some AV Source: pentestpartners.com



Finally, back in the office, our team celebrated with a bottle of champagne...

The team (from left to right): Neil, Charlotte, Ian, Nicola, Kelly, Nigel, Andy



Monday, 24 February 2014

Using Nipper Studio for Penetration Testing

by Peter Wood

About the Author

Peter Wood, CEO at First Base Technologies

Pete has worked in the electronics and computer industries for over forty years and founded First Base in 1989. He is a world-renowned security evangelist, speaking at conferences and seminars on ethical hacking and social engineering. He founded First Base Technologies in 1989, providing information security consultancy and security testing to commercial and government clients.  In this case study Pete explains how he came across Nipper Studio security auditing software and why he thinks it is one of the best tools of its kind on the market.




The first time I heard about Nipper Studio was back in 2009 when the product was very new to the market and still in its first version, Nipper One. I received an industry newsletter which featured Nipper and outlined the basic features of the tool. It sounded interesting but at that time it wasn’t a tool that I felt we needed and didn’t take it any further.


Why did you decide to use Nipper Studio?

We first evaluated Nipper Studio in July 2012 when we had a requirement to audit several routers and switches for a large client. After running a few reports I realised the tool was exactly what we were looking for, as all our previous reviews of network devices were done entirely manually. Nipper Studio was the only product we could find that provided this level of detailed configuration audit review. The reports generated from Nipper Studio were easy to read and thorough and it saved us hours of manual work. We have continued to use Nipper Studio to assist with network security audits for our clients and also in-house to audit our own network security devices.

How do you use Nipper Studio at client sites?

One of the great things about Nipper Studio, from a Penetration Tester’s point of view, is that the software can be downloaded onsite and installed in minutes, without causing any disruption to their networks. Furthermore, because Nipper Studio does not store any configuration information and, unlike scanning tools, does not need to connect to the network, using it poses no additional security issues to the organization. 

Once we have Nipper Studio installed it enables us to automate much of the review process without compromising the quality and accuracy of our results. During an engagement we can use the tool to help find vulnerabilities in the device in a fraction of the time it would take us to do manually.

As a result of the extensive amount of devices supported, Nipper Studio enables us to provide a more consistent and accurate set of results, irrespective of the manufacturer or model of device under review. Also because we can install Nipper Studio on multiple machines we are able to use the license for various different customer engagements throughout the year. 

How have your customers benefited from you using Nipper Studio?

It became obvious to us that our clients were facing a problem. They would often come to us asking for us to review the configuration and security of their switches, routers and firewalls. However it is a lengthy and painstaking process to manually audit every network device in a system, especially in the larger organizations. As a result, it was not cost effective to review more than a small sample of an organization’s infrastructure.

Using Nipper Studio means that our clients can now afford to have the security of all their  infrastructure devices checked, rather than just a sample.

How has using Nipper Studio benefited First Base Technologies as a business?

Using Nipper Studio has presented us the opportunity to expand our security reviews at a realistic price. This means our clients expectations have been exceeded while still staying on time and in budget. This gives us an advantage in the market and ultimately helps retain our existing customers and attract new ones.