YMCA George Williams College - Penetration Testing
Penetration testing for peace of mind for YMCA George Williams College
YMCA George Williams College
YMCA George Williams College works to provide transformational support to practitioners, funders, and policy makers across the sector, to improve the quality and impact of provision and outcomes for children and young people across the UK.
The College engaged with Cybaverse to ensure their data was secure and to ensure their compliance with industry partner regulations.
Training web application
Personal information
Development day
Overview
YMCA George Williams College were looking to engage with a Cyber Security partner to conduct a comprehensive security review of their web application service offering and provide a development day to upskill internal staff. They needed to ensure the security of the personal information held on their web application and ensure their compliance with industry regulations.
Scoping and Pre-Testing
To accurately provide a quotation, a scoping call took place with one of Cybaverse's Account Managers and an experienced Penetration Tester. This enabled Cybaverse to comprehensively understand the needs of the business and the web application. This allowed for an accurate and bespoke proposal to be drawn up that met YMCA George Williams College's exact requirements.
After working through the competitive quotes, the client chose Cybaverse because of the range of services available and the option to have a retest and feedback following the initial test. This would help the business continue their strategy of building secure ecosystems of data with their partners.
It was assessed that YMCA George Williams College required a Web Application Penetration Test and 'discovery day' which allowed Cybaverse to full explain test findings and support with remediation.
If you are not just looking for a certificate and really want to understand and explore your issues, then choose Cybaverse.
Testing
Cyabverse, unlike other penetration testing companies, build a relationship with clients and see them as a partner rather than a one-off project, this is even more apparent throughout the testing period.
From scope to project completion, Cybaverse’s technical experts stay in constant contact with clients to keep the client up to date with testing progress, reporting critical findings and ensuring the client is receiving the most value out of the penetration test.
Methodology
Cybaverse use their extensive experience alongside industry guidelines such as the OWASP Top Ten to conduct the assessment of the web applications. Our tester first scopes the web applications by crawling the site and finding all pages and any search functions. This will build a picture of possible actor vectors.
Our consultants will always cover the OWASP Top-10 vulnerabilities that commonly affect web applications:
- Broken Access Control
- Cryptographic Failures
- Injection
- Insecure Design
- Security Misconfiguration
- Vulnerable and Outdated Components
- Identification and Authentication Failures
- Software and Data Integrity Failures
- Security Logging and Monitoring Failures
- Server-Side Request Forgery (SSRF)
Report and Support
Throughout the engagement, the YMCA George Williams College was kept continuously updated with progress for any high or critical findings, allowing the client the opportunity to begin remediating and working with Cybaverse to fix any immediate issues.
Cybaverse always present a clear, detailed, easy-to-read report making it easy for management to understand the risks the business faces. The report includes technical findings, detailing how the vulnerabilities were found to allow the client to recreate the proof of concept and follow remediation guidance.
In this instance, Cybaverse worked alongside the client, working through each finding and offering support and ensuring the swift remediation of any vulnerabilities.
Summary
Cyabverse, unlike other penetration testing companies, were able to offer the client a bespoke service that truly met their needs. The client was able to undergo testing and get a full report and debreif on the testing process, alongside support and guidance from a cyber security expert to ensure remediations were implemented quickly and effectively.
How we work
Contact
Have a call with a member of our professional accredited technical team to ensure your requirements are met and the service is delivered to the highest standard.
Contact
Have a call with a member of our professional accredited technical team to ensure your requirements are met and the service is delivered to the highest standard.
Scope
Have a call with a member of our professional accredited technical team to ensure the your requirements are met and the service is delivered to the highest standard.
Schedule
Book in dates that work around your plans and availability. We are as flexible as possible and have delivered services as quickly as 24 hours before.
Execution
The technical team keeps in touch throughout the process of the audit, test or accreditation to guide you through the process and ensure you are getting the desired results.
Report
A detailed report is delivered securely which is appropriately broken down for a non-technical and technical audience. After the report is delivered we are on hand to assist with remediation and future guidance.
Strategy
A strategic scoping call with one of our technical advisors will map out your cyber security strategy for the future. We offer free guidance and consultancy around your cyber security plan.
Roadmaps
Our leading consultants will work with you to build our a roadmap with continually enhancing your cyber security program aligned with your needs, timescales, staff and budgets.
Onboarding
During onboarding phase you will be introduced to the team of experts who will guide you through the process to ensure a smooth and easy start to the partnership.
Continuous Protection
Our team are on hand 24/7 to deter, detect, protect, respond and recover your business. We go above and beyond what is expected to ensure you can relax, knowing you are in safe hands.
Let's talk
We’re here to help! Submit your information or call the office on +44 (0)1243 670 854 and a member of our team would be happy to help.
Cybaverse are a team of highly skilled, motivated and qualified professionals businesses can depend on. Offering routine to bespoke services whilst striving to exceed customers expectations. We guide our clients to be a step ahead of the adversaries in the ever-evolving cyber security landscape.
We work with our clients to identify the best, most practical, cost effective, requirements for their business. During engagements, we strive to identify real-world issues, confirm vulnerabilities, and provide guidance to secure your computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
Cybaverse has a clear ethos which drives the company internally and externally, this excels our client experience and reputation.
Beyond Excellence - Going above and beyond to achieve the highest standards.
Consistently Dependable - Dedicated to supporting one another and our clients.
Paving New Paths - Constantly looking for ways to innovate and improve.
Charismatic Engagement - Have fun and be ourselves.