NL

How cyberattack simulations expose security weaknesses

Date: 16-01-2025

As a business owner, you need to strike the right balance between investing too much and too little in cyber resilience. Cybersecurity may not be your core business, but you do not want a cyberattack to disrupt it either. Imagine hackers shutting down your production line, disrupting software used by your customers in their factories or stealing sensitive business data. The consequences could be devastating.

To identify the risks faced by a specific organisation, SBL uses continuous threat exposure management software from Picus Security. This software simulates the methods used by real attackers to determine how effectively your organisation is protected. In this article, we explain how this works.
 

How do hackers operate?

Hackers were once mainly hobbyists who attacked organisations for excitement or ideological reasons. Those days are over. Today, cybercriminals are often professionals with one primary objective: making money. They are no longer individuals operating from an attic while wearing a hoodie, but organised criminals working from countries where prosecution is difficult.

These criminals use automated tools that continuously scan the internet for weaknesses in corporate networks. They know that software consists of tens of thousands of lines of code and that vulnerabilities inevitably occur. Their tools specifically search for:

  • Servers that have not received the latest security updates
  • Microsoft 365 environments that can be accessed using stolen credentials
  • Insufficiently secured backup systems
  • Production environments connected to the internet


Once attackers find a single weakness, they try to move deeper into the network. Their objectives may include:

  • Stealing business data and demanding a ransom
  • Deploying ransomware that disrupts the entire organisation
  • Conducting espionage on behalf of competitors
  • Sending fraudulent invoices from your systems
     

“My business is not interesting to hackers”

This is a dangerous misconception that we often hear from SMEs in the manufacturing industry. Hackers do not discriminate: their automated tools scan the entire internet for vulnerable systems. Whether you run a small family business or a large multinational, you are a potential target.

Smaller organisations are often easier targets because they generally have fewer security measures in place. Consider what would happen if production stopped for several days or confidential business information became public. The impact on a smaller organisation can be greater than on a large company that is better equipped to absorb such disruption.
 

How do we test your security?

SBL uses a specialised platform from Picus Security. You can think of it as an ethical hacker that we deploy within your environment in a controlled and safe manner. Like a real attacker, the software tests different attack techniques to assess whether your security controls can prevent or detect them.

Imagine your corporate network as a large factory. The Picus platform acts as a security inspector that:

  • Checks all doors and windows, representing your firewalls and other security controls
  • Determines whether it can move from reception to the production floor, representing possible attack paths through your network
  • Tests whether critical areas are properly secured, representing the protection of essential systems


What is attack path validation?

Attack path validation identifies the routes an attacker could use to move through your network. For example, suppose an attacker gains access through a workstation running outdated software. Could they use that access to reach sensitive business data or even the systems that control your production machinery?


Are simulated attacks detected and acted upon?

An important question is whether your security systems raise an alert when we perform these tests. If our simulated attacks can enter your environment without being noticed, a real attacker may be able to do the same.

Most modern IT systems include security controls designed to identify suspicious behaviour:

  • Microsoft 365 can issue alerts for unusual sign-in attempts or access from unfamiliar locations
  • Firewalls record incoming connection attempts and block suspicious IP addresses
  • Endpoint security software such as Microsoft Defender can detect malicious software
  • Network monitoring tools can identify unusual volumes of incoming or outgoing data


However, an alerting system is only effective if someone reviews the alerts and takes appropriate action. We therefore assess three things:

  1. Whether your security systems detect our simulated attack activities
  2. Whether the resulting alerts reach the appropriate person or team
  3. Whether that person or team knows how to respond

Suppose an attacker attempts to enter your network. Your firewall detects the activity and sends an email to the IT service provider. If nobody reads the message or takes action, the attacker may be able to continue operating undisturbed. It is therefore important not only that your security systems generate alerts, but also that you have an effective process for investigating and responding to them.


Do you also test the production environment?

This is an understandable question, but we do not test production systems directly. We do not want to risk accidentally disrupting a production line. What we can test is whether an attacker could gain access to the network segment to which the production systems are connected. Once an attacker has reached that network, the distance to the production systems may be very small.


What are the benefits?

After the assessment, you will understand:

  • Where weaknesses exist within your security controls
  • Which routes an attacker could use to move through your network
  • Whether your security systems detect attacks
  • Which improvements are needed to strengthen your security


This ethical hacking approach allows you to take preventive action before real attackers discover your organisation. Prevention is better than cure, especially when the continuity of your production processes is at stake.

Would you like to learn more about how we can help protect your organisation against cyberattacks? Contact SBL Cyber Monitoring. We would be pleased to discuss the security measures that best suit your organisation.
 

Interactive session about the Picus security scan

On 30 January 2025, SBL Cyber Monitoring and Picus Security organised an interactive session at the HSD Campus. During the session, we explained how the Picus security scan works, the benefits it provides and how organisations can use it to assess and improve their security controls.

Would you like to learn how a Picus security scan can help your organisation identify weaknesses and validate its security measures? Contact SBL Cyber Monitoring to discuss the possibilities.