GET IN TOUCH

Speak to a pen test expert

Get in touch for a no obligation quote

1000 characters left
I prefer to be contacted by:
View our privacy policy
Book a penetration test today. Get in touch.

Overview

What is a build and configuration security review?

An insecurely configured network could give attackers an easy route into your organisation. Commissioning a qualified ethical hacker to conduct a build or configuration review helps to reduce this risk by identifying security misconfiguration vulnerabilities across web and application servers, web frameworks, and devices such as routers and firewalls.

Redscan’s CREST-accredited penetration testing team has extensive experience of providing build and configuration review services to help identify and address weaknesses.

Importance

The importance of regularly assessing system configurations

The fast pace of business growth and digital transformation means that it’s important to ensure your organisation’s cyber security keeps up. New systems, applications and devices can introduce security risks that could lead to an attacker gaining a foothold on your network and accessing critical data and assets. Many devices have weak out-of-the-box settings.

Review

What we review

Password policies
Access management
Wired and wireless network settings
Cloud configurations
Operating systems
Data storage
Security systems
Applications

Process

Our review process

A build and configuration review pen test systematically assesses devices, operating systems and databases across your networks. A typical engagement from our ethical hacking experts involves:

 

1. Data Collection

Our whitehat hackers use a combination of automated tools and manual processes to gather information about your network assets and how they are configured.

2. Configuration Analysis

Our build and configuration security team identify vulnerabilities by systematically analysing information collated across your network and comparing it to established baseline settings.

3. Reporting

Once an assessment is complete, we deliver a formal report and debrief outlining key findings and a prioritised list of remedial actions to help address any identified risks and exposures.

Request a build and configuration review quote

Get in touch
A range of security assessment services

Services

About our penetration testing services

Redscan’s CREST-accredited penetration testing services are designed to identify and safely exploit security vulnerabilities in infrastructure, systems and applications. As with our Build and Configuration Review services, all our assessments are designed to pinpoint hidden security risks and provide the support and guidance needed to address them.

Expertise

Our security qualifications

Types of penetration test

Network infrastructure testing

Network infrastructure testing

Redscan rigorously investigates your network to identify and exploit a wide range of security vulnerabilities. This enables us to establish if assets such as data can be compromised, classify the risks posed to your overall cyber security, prioritise vulnerabilities to be addressed, and recommend actions to mitigate risks identified.

Wireless testing

Wireless testing

Unsecured wireless networks can enable attackers to enter your network and steal valuable data. Wireless penetration testing identifies vulnerabilities, quantifies the damage these could cause and determines how they should be remediated.

Application and API security review

Application and API security review

Vulnerabilities contained within software are commonly exploited by cybercriminals and are easily introduced by under-pressure programmers. Redscan’s ethical hackers conduct automated and manual penetration tests to assess backend application logic and software and API source code.

Remote working assessment

Remote working assessment

If your organisation is embracing mass remote working for the first time, it’s important to ensure that it is doing so securely. Ensure your networks, applications and devices are protected and fully secured with a custom remote working security assessment.

Web application security testing

Web application security testing

Web applications play a vital role in business success and are an attractive target for cybercriminals. Redscan’s ethical hacking services include website and web app penetration testing to identify vulnerabilities including SQL injection and cross-site scripting problems plus flaws in application logic and session management flows.

Social engineering

Social engineering

People continue to be one of the weakest links in an organisation’s cyber security. Redscan’s social engineering pen test service includes a range of email phishing engagements designed to assess the ability of your systems and personnel to detect and respond to a simulated attack exercise.

Mobile security testing

Mobile security testing

Mobile app usage is on the rise, with more and more companies enabling customers to conveniently access their services via tablets and smartphones. Redscan carries out in-depth mobile application assessments based on the latest development frameworks and security testing tools.

Firewall configuration review

Firewall configuration review

Firewall rule sets can quickly become outdated. Redscan’s penetration testers can detect unsafe configurations and recommend changes to optimise security and throughput.

Meet some of our team

Faisal
“Our remit is to think creatively to find solutions that will help keep your organisation more secure. We’re continually improving our knowledge of how adversaries think so that we can better identify security weaknesses and enhance detection of new and emerging threats.”
Faisal
Security Consultant
Nima Zafari
“We’re focused on delivering the best pen testing security outcomes for our clients. That’s why we’ll work with your organisation every step of the way – from initial scoping of requirements through to remediating vulnerabilities. Communication is a vital part of our approach and we’ll work hard to help you achieve the results you need.”
Nima
Security Consultant
Philip Veness
“We aim to make sure that your organisation gets the best possible value from a pen test. We'll talk you through the assessment at every stage and answer any questions you might have along the way.”  

 

Philip
Security Consultant

Why choose Redscan?

A trusted partner for pen testing

  • One of the highest accredited UK pentesting companies
  • A deep understanding of how hackers operate
  • In-depth threat analysis and advice you can trust
  • Complete post-test care for effective risk remediation
  • Multi award-winning offensive security services
  • Avg. 9/10 customer satisfaction, 95% retention rate

            SC 2020 AwardsCyber Security Excellence Awards Winner 2020Teiss Awards 2020 WinnerComputing Awards 2019 Winner

Get a quick quote

Complete the form for a prompt response from our team.

Two Redscan team members analysing cyber security intelligence

1000 characters left
I prefer to be contacted by:
View our privacy policy

Resources

Discover our latest content and resources

From the blog
From the blog Case studies Latest news
17th May 2022
One fifth of businesses put at serious financial risk due to cyber-attacks
A fifth of businesses in the US and Europe have stated that they were almost made insolvent in the past year by a serious cyber-attack, according to new research.  
9th May 2022
Healthcare and education sectors most vulnerable to cyber-attacks
According to an analysis of data from the UK's Information Commissioner’s Office (ICO), healthcare and education are the sectors most vulnerable to cyber-attacks.
4th May 2022
Financial impact of ransomware is seven times the ransom paid
New research reveals that ransom payments are only a small part of the total cost of a ransomware breach, with the total cost estimated to be seven times higher than the ransom itself.
26th April 2022
Ransomware attacks cost UK universities over £2m per incident
A new report has revealed that increasing ransomware attacks are costing organisations in the UK’s higher and further education sector over £2m per incident.