Vulnerability Assessments

  • Home
  • Vulnerability Assessments
Vulnerability Assessments

Why Vulnerability Assessments?

What was the last company you heard about that got hacked?  Do you know how the attackers got in?  Oftentimes the first step in an attack is to scan the victim’s systems for vulnerabilities to exploit.  Modern organizations need to regularly evaluate their own systems so administrators can close holes to improve security.  One way organizations can do this is to proactively run their own vulnerability scans to discover issues with systems, so the issues can be remediated before an attacker takes advantage of them

A vulnerability scanner is a computer program that assesses computers, networks, or applications for known weaknesses.  These weaknesses are vulnerabilities that attackers can exploit to gain unauthorized access or otherwise cause harm.  System administrators constantly patch systems to fix vulnerabilities, but sometimes administrators miss patches.  Vulnerability scans catch missed patches, and they can also catch misconfigurations.  A misconfiguration is when a system’s options have been set incorrectly or sub-optimally, which may lead to vulnerabilities.  Examples of misconfigurations include administrator credentials that have not been changed from the defaults, ports that are unnecessarily left open, and incorrect permissions that allow users access that they should not have. 

The Importance of Vulnerability Scans

If a system is missing patches and has misconfigured settings that makes it much more vulnerable to attack.  It’s important to note that patches don’t necessarily fix system misconfigurations, so a system that was deployed in a misconfigured state could stay that way indefinitely if no one ever notices the misconfiguration, even if it is patched regularly.  A vulnerability scan will reveal the issue so an administrator can adjust the system’s configuration to improve security.

 

Vulnerability scanning is important because systems on the Internet are constantly scanned and attacked.  Even if you aren’t running vulnerability scans on your Internet-facing systems, someone else is, and they don’t have your best interests in mind.  The global nature of the internet allows criminals in faraway places to attack your systems with relative impunity, and they are always scanning for unpatched systems to exploit.  Even if a patch already exists for a given vulnerability, criminals can exploit the lag time from the vulnerability becoming known and a patch being released to a given system being patched.  This is why patching systems in a timely manner is critical and running a vulnerability scan will help reveal missing patches that need to be applied.

 

The value of vulnerability scanning isn’t just limited to Internet-facing systems.  It’s also useful to run vulnerability scans on internal systems, so that any issues found can be fixed.  This improves the security of your internal network and could keep an attacker that has established a foothold inside your internal network from moving from system to system and escalating their privileges.

 

 

Related Posts

Disaster Planning

Ransomware attacks against small businesses are running rampant. Nearly half (43%) of all cyber attacks

Read More

Penetration Testing

Penetration tests let companies evaluate the overall security of their IT infrastructure. A company may

Read More

Compliance

IT security compliance occurs when organizations demonstrate that their cybersecurity system meets specific security regulations

Read More