Summary
For those of us working in operational technology here at the NCSC, part of our job is to engage with penetration testers. Also known as ‘pen testers’, it’s their job to try to break into systems, poke holes in your infrastructure and find any weak spots. These can then be patched to improve the system’s resilience against attackers who have the same skills, but bad In this blog, we’ll explain what pen testers told us when we asked: ‘What can organisations do to make your job harder?’ Build systems that are secure by design The pen testers all felt that when vulnerabilities are found (and they are rarely absent), it’s much easier to implement remediations if the system is ‘secure by design’, meaning it has been designed with security as one of the key requirements from the outset. Designing systems this way lays the groundwork for many of the technical controls that make attacks One of the clearest examples of ‘secure by design’ is the adoption of network segmentation, particularly where it has been considered as part of the system design rather than added later. Network segmentation involves splitting a network up into smaller segments, either through high-level network design, the use of VLANs or firewalls, or through the management of users or groups with separate accounts for different network areas.