Vulnerability, Threat and Risk Assessments CONSULTANTS EXPERTS PROFESSIONALS

A Threat Vulnerability Risk Assessment considers the client’s need to protect people and assets, minimize exposure to crime and breaches of security and overall business risk. What makes a risk, threat, and vulnerability assessment successful and effective? Why are assessments essential for organizational resilience? Our program starts by explaining the differences between risk, threat, and vulnerability and then demonstrates how assessments are absolutely essential for organizational resilience.

The risk assessment conducted is a top down analysis of an organization's security posture. Leveraging vulnerability data and security information gathered through other assessment components, along with data collected through targeted questionnaires and interviews, Illumant performs a quantitative risk analysis to determine the top threats to information security, biggest vulnerabilities, and largest opportunities for risk reduction through cost-benefit analysis.

Performing cybersecurity risk assessments is a key part of any organization’s information security management program. Everyone knows that there’s some level of risk involved when it comes to a company’s critical and secure data, information assets, and facilities. But how do you quantify and prepare for this cyber security risk? The purpose of an IT security risk assessment is to determine what security risks are posed to your company’s critical assets and to know how much funding and effort should be used in the protection of them.

The aim of a TRVA is to assess the business process in light of the safety and security environment and to identify vulnerabilities and risks to personnel, assets and facilities, prioritizing any response actions. In most cases, a qualitative assessment based on subjective experience is adequate for the assessment; however, in potentially high-risk situations, a more rigorous quantitative process will be required. A systematic approach to define directions in support of existing and future physical security objectives and requirements for a specific client is required.

Our firm specializes in completing Threat - Risk - Vulnerability Assessments (TRVA). The TRVA process is an established method for identifying and quantifying the information needed to make sensible decisions in the application of resources dealing with security and safety hazards posed to an organization. It is a methodical analysis of various factors that could cause harm to the organization, the safeguards in place to protect the organization and the derivative risk that the organization is facing.

Our professionals will help you implement effective information risk assessment, for example by:

  • Helping you identify the information assets that are most important to you
  • Evaluating your current approach to risk assessment and making recommendations for improvement
  • Conducting information risk assessments on your behalf, and developing an action plan to plug gaps identified
  • Undertaking an in-depth assessment of your most mission-critical information asset/s, and identifying the additional levels of security you'll need to apply in order to protect them.

Our professional team will develop a comprehensive report to ensure that all appropriate aspects of a client’s security requirements have been reviewed and accurately documented, with the understanding of the client’s strategic and tactical security program requirements.

Specific Areas of focus in our Assessment

  • Top down risk assessment
  • Inventory of critical assets
  • Calculation of risk
  • Assessment of Risk factors (Confidentiality, Privacy, Integrity, Availability)
  • Scanning to create a baseline of vulnerabilities and security risks
  • Best-of-breed open source and commercial vulnerability harvesting tools
  • Manual testing to find additional vulnerabilities not found by scanning tools
  • Penetration testing through custom-designed and pre-existing exploits to test real severity
  • Classification of severity of findings
  • Remediation recommendations
  • Benchmark analysis of results vs industry
  • Cost-benefit analysis of risk remediation efforts

Assessment Targets

Networks, systems, applications, services, ports, protocols from within firewalls boundaries – unfiltered analysis:

  • Sensitive Customer and Company Data
  • Mission Critical Systems
  • Web sites and web applications and Intranet Sites
  • Web applications (non-credentialed testing)
  • Firewalls, routers and load balancers
  • Internal routers
  • Servers
  • Applications
  • Databases
  • Laptops and Desktops
  • External Storage Devices i.e. USB Drive, Backups, etc.
  • 100,000+ known vulnerabilities, unique vulnerabilities from custom designs, configurations and software
ADVANCED ICT » Consultants and Auditors LLP.