Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats //

Vulnerability Management

3/4/2019
05:55 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Debuts Pen Testing and Industrial Cybersecurity Assessment Services

New service offerings reinforce critical security controls, assess security weaknesses of enterprises and industrial organizations

SAN FRANCISCO (RSA® Conference 2019, Booth #6345 North Expo) – March 04, 2019 – Tripwire, Inc., a leading global provider of security and compliance solutions for enterprises and industrial organizations, today announced the debut of its penetration (pen) testing and industrial cybersecurity assessment services. By ensuring the security of critical assets and identifying vulnerabilities, Tripwire is building upon and strengthening the security programs of its customers.

With Tripwire’s new services, organizations can establish and maintain a strong foundation of security. The Penetration Testing Assessment leverages highly skilled cybersecurity experts who discover and then exploit vulnerabilities to assess the security of an organization’s IT environment. Similarly, the Industrial Cybersecurity Assessment provides specialized evaluation of vulnerabilities in industrial control system (ICS) environments, taking into account the operational technology (OT) requirements of utility, manufacturing, oil and gas, and critical infrastructure operators.

“We are expanding the ways Tripwire customers can partner with us in developing a strong security strategy,” said Tim Erlin, vice president of product management and strategy at Tripwire. “Pen testing and assessment services are a good launching point for building a robust security posture. We provide organizations a tangible understanding of their security weaknesses and risks up front, and then help them develop a robust security strategy including critical security controls such as secure configuration and vulnerability management. It’s important that organizations – even those with the most mature security programs – test their defenses and stay up to date on vulnerability protection."

Tripwire Penetration Testing Assessments

Tripwire’s pen testing services cover the following areas to ensure critical assets are secure: Network services and configuration

  • Web application
  • Wireless infrastructure
  • Client-side and internal infrastructure
  • Social engineering and physical security

To evaluate an organization’s security, Tripwire’s Penetration Testing Assessment examines how:

  • Authentication and data traffic flows throughout the network in order to establish the roles of various systems within the network
  • Different systems support the business functions of the organization
  • Communication moves between a system and its users, providing information needed to design protective control mechanisms

Tripwire Industrial Cybersecurity Assessment

To identify exposures in industrial environments, Tripwire’s team of security professionals review data from automated vulnerability scanners, proprietary tools and manual assessments. Vulnerabilities are then manually validated in order to determine:

  • If a vulnerability represents an actual exposure
  • How an exposure may impact systems on the network
  • If mitigating factors or prerequisites may prohibit a vulnerability from being exploited under certain conditions

With its deep industrial expertise, Tripwire can assess the following for vulnerabilities without disrupting operations:

  • Energy management systems (EMS)
  • Supervisory Control and Data Acquisition (SCADA) systems
  • Real-time Control System (RCS) architecture
  • Distributed control systems (DCS)
  • Programmable logic controllers (PLCs)
  • Network devices

For more information on Tripwire's assessment services please visit:  

  • Penetration Testing Assessment: https://www.tripwire.com/solutions/penetration-testing/penetration-testing-assessments/
  • Industrial Cybersecurity Assessment: https://www.tripwire.com/solutions/industrial-control-systems/industrial-cybersecurity-assessment/

About Tripwire
Tripwire is the trusted leader for establishing a strong cybersecurity foundation. Partnering with Fortune 500 enterprises, industrial organizations and government agencies, Tripwire protects the integrity of mission-critical systems spanning physical, virtual, cloud and DevOps environments. Tripwire’s award-winning portfolio delivers top critical security controls, including asset discovery, secure configuration management, vulnerability management and log management. As the pioneers of file integrity monitoring (FIM), Tripwire’s expertise is built on a 20+ year history of innovation helping organizations discover, minimize and monitor their attack surfaces.

Learn more at https://www.tripwire.com/, get security news, trends and insights at www.tripwire.com/blog, or connect with us on LinkedIn, Twitter and Facebook.

Contact: Tripwire, Inc.
Ray Lapena, +1 714-624-8862
Corporate Communications
[email protected]

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19668
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to preve...
CVE-2019-12882
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2017-6363
PUBLISHED: 2020-02-27
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for...
CVE-2017-6371
PUBLISHED: 2020-02-27
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.
CVE-2017-5861
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000020. Reason: This candidate is a reservation duplicate of CVE-2017-1000020. Notes: All CVE users should reference CVE-2017-1000020 instead of this candidate. All references and descriptions in this candidate have been removed to...