Case Study

YMCA George Williams College - Penetration Testing

Penetration testing for peace of mind for YMCA George Williams College

The Client

YMCA George Williams College

YMCA George Williams College works to provide transformational support to practitioners, funders, and policy makers across the sector, to improve the quality and impact of provision and outcomes for children and young people across the UK.

The College engaged with Cybaverse to ensure their data was secure and to ensure their compliance with industry partner regulations.

Email Icon
Contact

Contact us

Please get in touch using the form below

Training web application

Personal information

Development day

Overview

YMCA George Williams College were looking to engage with a Cyber Security partner to conduct a comprehensive security review of their web application service offering and provide a development day to upskill internal staff. They needed to ensure the security of the personal information held on their web application and ensure their compliance with industry regulations.

Scoping and Pre-Testing

To accurately provide a quotation, a scoping call took place with one of Cybaverse's Account Managers and an experienced Penetration Tester. This enabled Cybaverse to comprehensively understand the needs of the business and the web application. This allowed for an accurate and bespoke proposal to be drawn up that met YMCA George Williams College's exact requirements.

After working through the competitive quotes, the client chose Cybaverse because of the range of services available and the option to have a retest and feedback following the initial test. This would help the business continue their strategy of building secure ecosystems of data with their partners.

It was assessed that YMCA George Williams College required a Web Application Penetration Test and 'discovery day' which allowed Cybaverse to full explain test findings and support with remediation.

If you are not just looking for a certificate and really want to understand and explore your issues, then choose Cybaverse.

Josef Fischer
Digital Products Lead

Testing

Cyabverse, unlike other penetration testing companies, build a relationship with clients and see them as a partner rather than a one-off project, this is even more apparent throughout the testing period.

From scope to project completion, Cybaverse’s technical experts stay in constant contact with clients to keep the client up to date with testing progress, reporting critical findings and ensuring the client is receiving the most value out of the penetration test.

Methodology

Cybaverse use their extensive experience alongside industry guidelines such as the OWASP Top Ten to conduct the assessment of the web applications. Our tester first scopes the web applications by crawling the site and finding all pages and any search functions. This will build a picture of possible actor vectors.

Our consultants will always cover the OWASP Top-10 vulnerabilities that commonly affect web applications:

  • Broken Access Control
  • Cryptographic Failures
  • Injection
  • Insecure Design
  • Security Misconfiguration
  • Vulnerable and Outdated Components
  • Identification and Authentication Failures
  • Software and Data Integrity Failures
  • Security Logging and Monitoring Failures
  • Server-Side Request Forgery (SSRF)

Report and Support

Throughout the engagement, the YMCA George Williams College was kept continuously updated with progress for any high or critical findings, allowing the client the opportunity to begin remediating and working with Cybaverse to fix any immediate issues.

Cybaverse always present a clear, detailed, easy-to-read report making it easy for management to understand the risks the business faces. The report includes technical findings, detailing how the vulnerabilities were found to allow the client to recreate the proof of concept and follow remediation guidance.

In this instance, Cybaverse worked alongside the client, working through each finding and offering support and ensuring the swift remediation of any vulnerabilities.

Summary

Cyabverse, unlike other penetration testing companies, were able to offer the client a bespoke service that truly met their needs. The client was able to undergo testing and get a full report and debreif on the testing process, alongside support and guidance from a cyber security expert to ensure remediations were implemented quickly and effectively.

Methodology

How we work

Consultancy Service
1
Scope
2
Schedule
3
Execution
4
Report

Contact

Have a call with a member of our professional accredited technical team to ensure your requirements are met and the service is delivered to the highest standard.

Learn more

Contact

Have a call with a member of our professional accredited technical team to ensure your requirements are met and the service is delivered to the highest standard.

Learn more

Scope

Have a call with a member of our professional accredited technical team to ensure the your requirements are met and the service is delivered to the highest standard.

Learn more

Schedule

Book in dates that work around your plans and availability. We are as flexible as possible and have delivered services as quickly as 24 hours before.

Learn more

Execution

The technical team keeps in touch throughout the process of the audit, test or accreditation to guide you through the process and ensure you are getting the desired results.

Learn more

Report

A detailed report is delivered securely which is appropriately broken down for a non-technical and technical audience. After the report is delivered we are on hand to assist with remediation and future guidance.

Learn more

Strategy

A strategic scoping call with one of our technical advisors will map out your cyber security strategy for the future. We offer free guidance and consultancy around your cyber security plan.

Learn more

Roadmaps

Our leading consultants will work with you to build our a roadmap with continually enhancing your cyber security program aligned with your needs, timescales, staff and budgets.

Learn more

Onboarding

During onboarding phase you will be introduced to the team of experts who will guide you through the process to ensure a smooth and easy start to the partnership.

Learn more

Continuous Protection

Our team are on hand 24/7 to deter, detect, protect, respond and recover your business. We go above and beyond what is expected to ensure you can relax, knowing you are in safe hands.

Learn more
Managed Service
Strategy
1
Roadmaps
2
Onboarding
3
Continuous Protection
4

Let's talk

We’re here to help! Submit your information or call the office on +44 (0)1243 670 854 and a member of our team would be happy to help.

Who are Cybaverse?
How can we support your business?
Why work with us?