Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats //

Vulnerability Management

3/4/2019
05:55 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Debuts Pen Testing and Industrial Cybersecurity Assessment Services

New service offerings reinforce critical security controls, assess security weaknesses of enterprises and industrial organizations

SAN FRANCISCO (RSA® Conference 2019, Booth #6345 North Expo) – March 04, 2019 – Tripwire, Inc., a leading global provider of security and compliance solutions for enterprises and industrial organizations, today announced the debut of its penetration (pen) testing and industrial cybersecurity assessment services. By ensuring the security of critical assets and identifying vulnerabilities, Tripwire is building upon and strengthening the security programs of its customers.

With Tripwire’s new services, organizations can establish and maintain a strong foundation of security. The Penetration Testing Assessment leverages highly skilled cybersecurity experts who discover and then exploit vulnerabilities to assess the security of an organization’s IT environment. Similarly, the Industrial Cybersecurity Assessment provides specialized evaluation of vulnerabilities in industrial control system (ICS) environments, taking into account the operational technology (OT) requirements of utility, manufacturing, oil and gas, and critical infrastructure operators.

“We are expanding the ways Tripwire customers can partner with us in developing a strong security strategy,” said Tim Erlin, vice president of product management and strategy at Tripwire. “Pen testing and assessment services are a good launching point for building a robust security posture. We provide organizations a tangible understanding of their security weaknesses and risks up front, and then help them develop a robust security strategy including critical security controls such as secure configuration and vulnerability management. It’s important that organizations – even those with the most mature security programs – test their defenses and stay up to date on vulnerability protection."

Tripwire Penetration Testing Assessments

Tripwire’s pen testing services cover the following areas to ensure critical assets are secure: Network services and configuration

  • Web application
  • Wireless infrastructure
  • Client-side and internal infrastructure
  • Social engineering and physical security

To evaluate an organization’s security, Tripwire’s Penetration Testing Assessment examines how:

  • Authentication and data traffic flows throughout the network in order to establish the roles of various systems within the network
  • Different systems support the business functions of the organization
  • Communication moves between a system and its users, providing information needed to design protective control mechanisms

Tripwire Industrial Cybersecurity Assessment

To identify exposures in industrial environments, Tripwire’s team of security professionals review data from automated vulnerability scanners, proprietary tools and manual assessments. Vulnerabilities are then manually validated in order to determine:

  • If a vulnerability represents an actual exposure
  • How an exposure may impact systems on the network
  • If mitigating factors or prerequisites may prohibit a vulnerability from being exploited under certain conditions

With its deep industrial expertise, Tripwire can assess the following for vulnerabilities without disrupting operations:

  • Energy management systems (EMS)
  • Supervisory Control and Data Acquisition (SCADA) systems
  • Real-time Control System (RCS) architecture
  • Distributed control systems (DCS)
  • Programmable logic controllers (PLCs)
  • Network devices

For more information on Tripwire's assessment services please visit:  

  • Penetration Testing Assessment: https://www.tripwire.com/solutions/penetration-testing/penetration-testing-assessments/
  • Industrial Cybersecurity Assessment: https://www.tripwire.com/solutions/industrial-control-systems/industrial-cybersecurity-assessment/

About Tripwire
Tripwire is the trusted leader for establishing a strong cybersecurity foundation. Partnering with Fortune 500 enterprises, industrial organizations and government agencies, Tripwire protects the integrity of mission-critical systems spanning physical, virtual, cloud and DevOps environments. Tripwire’s award-winning portfolio delivers top critical security controls, including asset discovery, secure configuration management, vulnerability management and log management. As the pioneers of file integrity monitoring (FIM), Tripwire’s expertise is built on a 20+ year history of innovation helping organizations discover, minimize and monitor their attack surfaces.

Learn more at https://www.tripwire.com/, get security news, trends and insights at www.tripwire.com/blog, or connect with us on LinkedIn, Twitter and Facebook.

Contact: Tripwire, Inc.
Ray Lapena, +1 714-624-8862
Corporate Communications
[email protected]

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13623
PUBLISHED: 2019-07-17
In NSA Ghidra through 9.0.4, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis r...
CVE-2019-13624
PUBLISHED: 2019-07-17
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
CVE-2019-13625
PUBLISHED: 2019-07-17
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
CVE-2019-3571
PUBLISHED: 2019-07-16
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
CVE-2019-6160
PUBLISHED: 2019-07-16
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.