Penetration Testing and Vulnerability Assessment
Penetration testing is authorized, controlled testing of your networks, applications and cloud environments to establish what an attacker could reach and how far they could get, reported as findings ranked by business consequence and tied to a remediation plan, rather than as a list of scanner output.
- Part of
- Finding out what an attacker could do before one tries, and being ready to act when one does.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations that have never had their environment tested by someone trying to get in.
- Companies asked by a customer, insurer or framework to evidence testing.
- Teams that have run scans for years and want to know which findings actually matter.
- Businesses launching or materially changing a customer-facing application.
A scoped, written engagement with rules of engagement agreed before anything is touched: what is in scope, what is out, when testing runs, and who is told if something sensitive is found. External and internal network testing, web and mobile application testing, cloud configuration review and, where the risk warrants it, social engineering.
Findings are validated by hand and written for two audiences: the engineer who has to fix each one, and the executive who has to decide what gets fixed first.
Scope
What Heights does
-
External network testing
What is reachable from the internet, what it exposes, and whether it can be used to get further.
-
Internal network testing
What a person with a foothold, a compromised laptop or a visitor on the guest network could reach from inside.
-
Web and application testing
Authentication, authorization, input handling and business logic in the applications your customers and staff use.
-
Cloud configuration review
Identity, storage, network and logging settings across your cloud accounts, checked against how they are actually used.
-
Vulnerability assessment
Authenticated scanning across the estate, with results validated and ranked by exploitability rather than by score alone.
-
Retesting
Confirmation that what was fixed is fixed, so the closing report reflects the environment as it is, not as it was.
The problem
Why this comes up
A vulnerability scan tells you what is present. It does not tell you which of a hundred findings would let someone in, which would let them move once inside, and which do not matter because a control further along stops them. Without that judgment, remediation is ordered by severity score and the real path stays open.
Customers, insurers and frameworks increasingly ask for evidence of testing, and a scan report handed over as a test is recognized for what it is.
Timing
When organizations engage this
- A customer contract or questionnaire requires an annual penetration test.
- A cyber-insurance renewal asks whether external testing has been performed.
- A new application is about to face customers or handle regulated data.
- Scan reports run to hundreds of findings and nobody knows where to start.
- A framework assessment, SOC 2, PCI DSS or CMMC, calls for testing evidence.
What you receive
- Rules of engagement agreed and signed before testing begins
- A findings report ranked by consequence, with reproduction steps for each
- An executive summary written for leadership and for whoever asked for the test
- A retest and closure letter once remediation is complete
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
The flagship
How this fits under vCISO leadership
Testing tells you where you stand today. The vCISO decides what to test, in what order, and turns the findings into a remediation plan the program can carry. Without that direction a test becomes a document; with it, the test changes what happens next.
Sectors
Where this comes up most
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Will testing disrupt our operations?
Not if it is scoped properly. The rules of engagement fix the windows, exclude fragile systems, and set a stop condition, and testing that could affect availability is scheduled with your operations people rather than around them.
Some checks are run against staging or a copy for exactly that reason. The report says which, so nobody mistakes a cautious test for a clean bill of health.
How often should we be tested?
At least annually for most organizations, and after any material change: a new customer-facing application, a cloud migration, an acquisition, a change of provider.
Continuous vulnerability assessment fills the gap between tests. The two are different instruments, one measures what an attacker can do, the other what is present, and a program needs both.
Who sees the findings?
The people you name in the rules of engagement, and nobody else. Reports are delivered through an agreed channel, not by email attachment, and sensitive findings are discussed in person before anything is written down in detail.
If testing turns up evidence of an active compromise, that is escalated immediately under the agreed path, ahead of the report.
Portfolio
Related services
- Incident Response and Breach Retainer Pre-arranged response when something happens: containment, investigation, recovery and the notifications that follow, led by people who already know your environment.
- Incident Readiness and Response Planning A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.