Blog

“We need to strike the balance between security and convenience” … but do we?

“We need to strike the balance between security and convenience” … but do we?

Posted on 2020-04-22by mattin Business Security


I often hear a common phrase from people both in the security industry and those who are now faced with dealing with cyber security in their business: “We need to strike a balance between security and convenience!”

Continue reading
New guides, welcome packs, and methodologies in the Volkis Handbook

New guides, welcome packs, and methodologies in the Volkis Handbook

Posted on 2020-04-07by Volkisin Volkis News


A couple of weeks ago we put up the Volkis Handbook. It is aimed at our customers, friends, employees, infosec colleagues and really anyone interested in the inner workings of Volkis.

Continue reading
Are you opening a security hole for your remote workers?

Are you opening a security hole for your remote workers?

Posted on 2020-04-02by mattin Business Security


On Tuesday Shodun showed that the number of RDP servers exposed to the internet has skyrocketed, going up by 30%. Just having RDP exposed to the internet is pretty much automatically considered a vulnerability in our penetration testing, as it’s a complex protocol that has a history of vulnerabilities (most recently BlueKeep), and exploitation can lead to administrator access to the system. Given that most RDP servers have to be connected to an Active Directory domain, often administrator access is all you need to completely compromise the network and all its data.

Continue reading
Volkis up and running!

Volkis up and running!

Posted on 2020-03-24by Volkisin Volkis News


Since the start we’ve had a remote-first philosophy and even with these troubled times we’re up and running providing penetration testing, security consulting, and strategy work. There are obviously a few things we can’t do for now such as internal penetration testing, physical intrusion, and onsite debriefs, but most of our services including external and web app penetration testing, red team, security strategy, and compliance are still running.

Continue reading
Why remote working isn’t the security nightmare you think it is

Why remote working isn’t the security nightmare you think it is

Posted on 2020-03-19by mattin Business Security


A couple of days ago we posted up tips and advice to deal with this period of remote working. It’s a scary time not just for our health but also for our security, with organisations suddenly needing to have everyone to stay away from the office and to work from home, safe from the coronavirus.

Continue reading
Security precautions for remote work – Quick wins

Security precautions for remote work – Quick wins

Posted on 2020-03-17by alexeiin Business Security


The sad truth of the world is that there are people out there who will take advantage of the COVID-19 crisis. As more organisations shut down their offices and ask employees to work from home, those that are less geared towards remote work will be targeted by threat actors.

Continue reading
Attacking the backups

Attacking the backups

Posted on 2020-03-13by mattin Business Security


There are a critical systems inside any organisation where the compromise of those systems are almost automatically business threatening. When performing penetration testing we try and think about the “crown jewels” as a bit of a target – if we get access to this the risk is pretty well self evident. Most of these systems are the obvious: financial systems, domain controller, key business process systems, safety systems, and often the web presence nowadays. One such system that is not considered nearly enough is the backup system.

Continue reading
Should you go for bug bounties or penetration testing?

Should you go for bug bounties or penetration testing?

Posted on 2020-03-03by mattin Business Security


At school I was taught that a good piece of writing should “say what you’re going to say, say it, then say what you’ve said”. In that vein, I’m going to talk about the advantages and disadvantages of bug bounties and penetration testing but it will all come down to this:

Continue reading
Trust hierarchies in your everyday life

Trust hierarchies in your everyday life

Posted on 2020-02-25by alexeiin Personal Security


Well, it finally happened! Last Sunday my phone died. Proper died, no response, no battery indicator, nothing. It’s a brick. 🙁 Naturally, being a slave to our little black rectangles that we carry in our pockets, I promptly went to purchase a new one and start setting it up. This is where most articles start preaching about the importance of backups, but you already know about that so I won’t go down that road. I will mention that backups did saved me days of my life and leave it at that.

Continue reading
The Five Whys and security vulnerabilities

The Five Whys and security vulnerabilities

Posted on 2020-02-20by mattin Business Security


When reading about the Toyota Production System and the Lean Methodology, a remarkably simple technique was talked about called the “Five Whys”. It was used by Toyota to solve the underlying problems, not just the symptoms. The technique was made popular by books such as The Lean Startup.

Continue reading