Technical Services

Technical Services

1

Penetration Testing

Our experienced Pen Testers assess the effectiveness of your existing security controls of the target systems. With state of the art tools and skills in attacking, our engineers simulate real-world attacks to the target systems and find the vulnerabilities and weaknesses; by drilling down we help to uncover the risks of your system operations. We not only test the items of the Open Source Security Testing Methodology Manual (OWASP) and other standard methodologies but we also blend our real industrial experiences in cybersecurity investigation into the services, while reinforcing your operations and services scenarios into the attacking scripts.

We provide white box, grey box and black box penetration tests to your Systems/Network/OS levels and to your Application/web Services and API, as well as your APPs for different OS platforms. Our services cover finding, fixing, and solving your problems and vulnerabilities across your entire operations and services.

2

ASV (Approved Scanning Vendor)

Approved Scan Vendor (ASV) companies are approved by PCI SSC to provide vulnerability scanning services. The quality and methodologies are regulated by PCI SSC and the results of scanning help organizations be compliant to the requirements of PCI DSS or 3DS. Secure Vectors provides all leading brands of ASV services by tools or by manual, and our engineers can help in using the tools or in solving the findings by providing recommendations in solutions or management. Different ASV tools have their own specialties and limitations; manual ASV costs more but produces fewer false positive findings, and our experience in different tools and problem solving can help you shorten your learning curve and time for problem solving.

3

Vulnerability Scanning

Quarterly vulnerability scans are required by PCI DSS and 3DS standards. The way and the tools used for completing the scans are crucial to your operations. From free tools to commercial solutions, Secure Vectors helps organizations complete the periodical requirements in maintaining their system security. We offer recommendations in choosing a proper way and tool for vulnerability scanning, and we also offer professional engineers to do the vulnerability scans for your operations. Suggestions and recommendations are also provided after the services to help you in problem solving.

4

Code Reviews

Code Reviews are required by PCI DSS and 3DS standards, and can be achieved manually or by automatic tools. Knowledge of secure coding is the base for code reviews — Secure Vectors provides trainings for internal staff and programmers in your operations. Good controls should be in place with procedures for development or change/release controls to ensure the quality and security of software developments; our consultancy services will help in establishing the procedures and integrating the code review processes into your management. Automatic review tools are recommended in the processes to get better results in coding security problems, and our services can recommend a good tool to fit in your development processes and meet the requirements of PCI DSS or 3DS.

5

Social Engineering

Social engineering is a useful penetration test to uncover operational weaknesses and also penetrate the vulnerabilities of human controls. It can be used as a test of the effectiveness of your organization's security awareness and the vigilance of your employees against personalized or "spear-phishing" threats that work to exploit trust and lack of security awareness. By mail phishing, web pages, phone calls and other traps or social engineering attacks based on the characteristics of your operations and services, our services try to find the weaknesses of your operations and provide later fixing solutions.

Contact Us!