Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats //

Vulnerability Management

3/4/2019
05:55 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Debuts Pen Testing and Industrial Cybersecurity Assessment Services

New service offerings reinforce critical security controls, assess security weaknesses of enterprises and industrial organizations

SAN FRANCISCO (RSA® Conference 2019, Booth #6345 North Expo) – March 04, 2019 – Tripwire, Inc., a leading global provider of security and compliance solutions for enterprises and industrial organizations, today announced the debut of its penetration (pen) testing and industrial cybersecurity assessment services. By ensuring the security of critical assets and identifying vulnerabilities, Tripwire is building upon and strengthening the security programs of its customers.

With Tripwire’s new services, organizations can establish and maintain a strong foundation of security. The Penetration Testing Assessment leverages highly skilled cybersecurity experts who discover and then exploit vulnerabilities to assess the security of an organization’s IT environment. Similarly, the Industrial Cybersecurity Assessment provides specialized evaluation of vulnerabilities in industrial control system (ICS) environments, taking into account the operational technology (OT) requirements of utility, manufacturing, oil and gas, and critical infrastructure operators.

“We are expanding the ways Tripwire customers can partner with us in developing a strong security strategy,” said Tim Erlin, vice president of product management and strategy at Tripwire. “Pen testing and assessment services are a good launching point for building a robust security posture. We provide organizations a tangible understanding of their security weaknesses and risks up front, and then help them develop a robust security strategy including critical security controls such as secure configuration and vulnerability management. It’s important that organizations – even those with the most mature security programs – test their defenses and stay up to date on vulnerability protection."

Tripwire Penetration Testing Assessments

Tripwire’s pen testing services cover the following areas to ensure critical assets are secure: Network services and configuration

  • Web application
  • Wireless infrastructure
  • Client-side and internal infrastructure
  • Social engineering and physical security

To evaluate an organization’s security, Tripwire’s Penetration Testing Assessment examines how:

  • Authentication and data traffic flows throughout the network in order to establish the roles of various systems within the network
  • Different systems support the business functions of the organization
  • Communication moves between a system and its users, providing information needed to design protective control mechanisms

Tripwire Industrial Cybersecurity Assessment

To identify exposures in industrial environments, Tripwire’s team of security professionals review data from automated vulnerability scanners, proprietary tools and manual assessments. Vulnerabilities are then manually validated in order to determine:

  • If a vulnerability represents an actual exposure
  • How an exposure may impact systems on the network
  • If mitigating factors or prerequisites may prohibit a vulnerability from being exploited under certain conditions

With its deep industrial expertise, Tripwire can assess the following for vulnerabilities without disrupting operations:

  • Energy management systems (EMS)
  • Supervisory Control and Data Acquisition (SCADA) systems
  • Real-time Control System (RCS) architecture
  • Distributed control systems (DCS)
  • Programmable logic controllers (PLCs)
  • Network devices

For more information on Tripwire's assessment services please visit:  

  • Penetration Testing Assessment: https://www.tripwire.com/solutions/penetration-testing/penetration-testing-assessments/
  • Industrial Cybersecurity Assessment: https://www.tripwire.com/solutions/industrial-control-systems/industrial-cybersecurity-assessment/

About Tripwire
Tripwire is the trusted leader for establishing a strong cybersecurity foundation. Partnering with Fortune 500 enterprises, industrial organizations and government agencies, Tripwire protects the integrity of mission-critical systems spanning physical, virtual, cloud and DevOps environments. Tripwire’s award-winning portfolio delivers top critical security controls, including asset discovery, secure configuration management, vulnerability management and log management. As the pioneers of file integrity monitoring (FIM), Tripwire’s expertise is built on a 20+ year history of innovation helping organizations discover, minimize and monitor their attack surfaces.

Learn more at https://www.tripwire.com/, get security news, trends and insights at www.tripwire.com/blog, or connect with us on LinkedIn, Twitter and Facebook.

Contact: Tripwire, Inc.
Ray Lapena, +1 714-624-8862
Corporate Communications
[email protected]

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "SpearPhish! Everyone out of the office!"
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13584
PUBLISHED: 2019-07-17
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.
CVE-2019-13585
PUBLISHED: 2019-07-17
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.
CVE-2019-13631
PUBLISHED: 2019-07-17
In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-13614
PUBLISHED: 2019-07-17
CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server...
CVE-2019-10100
PUBLISHED: 2019-07-17
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.