Frequently Asked Cybersecurity Questions
At Tozetta we understand cybersecurity can be a complex and challenging topic for many organizations. That's why we've put together a frequently asked cybersecurity questions page to answer all your questions. Our expertise in ethical hacking, running pentests, cybersecurity awareness training and cybersecurity advice allows us to give you the best answers.
Pentesting
7What is a pentest?
A pentest, or penetration test, is a controlled attack on an IT system to test its security and uncover any weak spots. This is done by an ethical hacker, also known as a white hat hacker, with the goal of improving security and reducing potential risks.
With a pentest you uncover vulnerabilities in your web application, mobile application or corporate network early. Want to know more about pentesting? Read our blog on “What is pentesting?” or get in touch with Tozetta!
Why run a pentest?
Having a pentest carried out gives you insight into the weak spots in your system. This allows you to address these vulnerabilities before someone with bad intentions can exploit them. It helps prevent sensitive information from falling into the wrong hands and prevents reputational damage to your organization.
In our blog on reputational damage after a hack you can read more about the consequences of cybercrime and why pentesting is worthwhile.
What types of pentests are there?
There are various types of pentests, including network pentests, web application pentests, mobile application pentests and API pentests. Each test focuses on a specific aspect of your IT system and gives insight into the security in that area. It's common for multiple types of pentests to be carried out during one engagement, since many companies have several aspects within their IT system.
Want to know more about the pentest process? On our running a pentest page we tell you everything about it!
What is the difference between blackbox, greybox and whitebox pentesting?
Pentesting can be carried out in different ways, with the two most common methods being blackbox and whitebox.
- •With blackbox pentesting, the tester is treated as an external attacker who has no prior knowledge of the system.
- •With whitebox pentesting, the tester is treated as an internal user who already has a lot of information about the system.
- •Greybox pentesting is a combination of both methods, where the tester has some prior knowledge of the system, but not as detailed as with whitebox pentesting. This way the tester can better find the system's vulnerabilities and thus improve the system's security.
At Tozetta we can carry out all three methods, depending on the specific needs and wishes you have as a client. We're happy to have a no-obligation conversation to help you in this decision-making process. Feel free to get in touch to schedule an appointment!
How long does a pentest take?
The duration of a pentest depends on the type of test and the complexity of the system. Generally a pentest takes a few days to a few weeks or even months. The duration is always discussed with the client beforehand. Feel free to get in touch for a QuickScan with an accompanying hour estimate.
The duration of the pentest can also strongly depend on the budget. An ethical hacker logs the time he spends getting into your organization. The more time the ethical hacker gets, the more thoroughly the pentest can be carried out and the more methods the pentester can apply.
Pentesting starts at a day and can go up to several weeks or months, but can take as long as the client would like.
What do you get after a pentest?
After the pentest, a report is drawn up with the test results. The report contains recommendations for improving online security and an overview of the vulnerabilities found in the tested environment. The report is intended for the organization's management and can be used as a basis for improving digital security.
At Tozetta, the vulnerabilities are given a risk classification. This lets you get straight to work fixing the vulnerabilities. Once you've fixed the vulnerabilities, we run an improvement scan. We want to be sure the weak spots have actually been resolved.
Are the results of the pentest confidential?
Yes, the results of a pentest are confidential and are only shared with the client.
Sometimes we're also asked to coordinate with the client's IT/ICT partner. If this is approved, we're happy to have that conversation and make sure the vulnerabilities are resolved as quickly as possible.
Website security
5How do I secure my website against hackers?
There are various measures you can take to secure your website against hackers. For example, you can regularly install updates, use strong passwords and install an SSL certificate. It's also important to regularly run a web application pentest to detect and fix any vulnerabilities.
Read more here about running a pentest.
What are the most common vulnerabilities in a web application?
Examples of common vulnerabilities in web applications include SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and improper authorization checks. It's important to detect and fix these vulnerabilities to secure your web application.
How can I protect my website against DDoS attacks?
To protect your website against DDoS attacks, you can, for example, use a DDoS protection service or a firewall. You can also host your website with a provider that offers DDoS protection. It's important to regularly test whether your website is resilient against DDoS attacks.
What is a firewall and do I need one?
A firewall is a security measure that can filter and block incoming and outgoing network traffic. Whether you need a firewall depends on various factors, such as the size and complexity of your network, and the risk of attacks. In general it's advisable to use a firewall as an extra layer of security.
What are the best security measures for building a website?
Some best practices for building a secure website are regularly updating software, using strong passwords, implementing an SSL certificate, running web application pentests, applying access control and limiting functionality to what's strictly necessary.
Mobile app security
5How do I secure my mobile app against hackers?
To secure your mobile app against hackers, you can, for example, ensure strong authentication and authorization mechanisms, apply data encryption, implement security measures within the app itself, and regularly run a mobile app pentest. It's also important to regularly install updates.
Want to know more about running a pentest?
What are the most common vulnerabilities in mobile apps?
The most common vulnerabilities in mobile applications include insecure data storage, weak authentication and authorization mechanisms, insecure communication and improper error handling. It's important to detect and fix these vulnerabilities to secure your mobile app.
What are the best security practices for building a mobile app?
Some best practices for building a secure mobile app are enforcing strong authentication, encrypting stored and transmitted data, validating all input, and regularly running a mobile app pentest to catch issues before release.
How does a mobile app pentest work?
A mobile app pentest involves simulating an attack on the app to detect and fix vulnerabilities. This is done by an ethical hacker who uses various techniques to hack the app.
How often should I have a mobile app pentest carried out?
It's recommended to run a mobile app pentest annually or after major app updates, to detect and fix any new vulnerabilities.
API security
5What is an API and why is security important?
An API (Application Programming Interface) is a set of tools and protocols that connect software applications to each other. Securing an API is important to protect sensitive data and to prevent hackers from gaining access to your system through the API.
Malicious hackers can also abuse your API, which can rack up significant costs.
What are the most common vulnerabilities in APIs?
The most common vulnerabilities in APIs are insufficient authorization and authentication, insecure data transfer and improper error handling.
How can I secure my API against hacking attacks?
To secure your API against hacking attacks, it's important to take security measures such as using HTTPS, implementing authorization and authentication mechanisms, and regularly running security tests.
What is an API pentest and how does it work?
An API pentest involves simulating an attack on the API to detect and fix vulnerabilities. This is done by an ethical hacker who uses various techniques to hack the API.
How often should I have an API pentest carried out?
It's recommended to run API pentests regularly, depending on the sensitivity of the data processed through the API and the risks associated with it.
Cyber Security Awareness Training
6What is a cyber security awareness training?
A cyber security awareness training is a training aimed at increasing employees' awareness of cybersecurity. Employees get acquainted with the world of cybercrime and receive tips to prevent your organization from becoming a victim.
Why is a cyber security awareness training important?
A cyber security awareness training is important because employees are often the weakest link in an organization's security. By far most data breaches or hacks are caused by human error. By increasing awareness, employees can contribute to a safer working environment.
What are the benefits of a cyber security awareness training?
The benefits of a cyber security awareness training include increasing employee awareness, reducing the risk of cyberattacks and data breaches, and increasing the organization's safety and productivity.
What is covered during a cyber security awareness training?
During a cyber security awareness training, topics covered include phishing, social engineering, safe password use, and recognizing suspicious activity on the network.
At Tozetta, no cyber security awareness training is the same. We respond to the organization's specific request. To properly demonstrate the urgency and importance, we make sure to give practical examples relevant to your company.
How long does a cyber security awareness training take and how often should you repeat it?
The duration of a cyber security awareness training can vary from a few hours to several days, depending on the content and the organization's needs.
A cyber security awareness training should be repeated periodically to ensure employees' awareness stays up to date and to address new threats. Hackers are constantly finding new and better techniques. Employees need to stay continuously informed about this.
How do I schedule a cyber security awareness training?
At Tozetta we respond to your needs. By getting in touch, we schedule a no-obligation conversation. In this conversation we want to get to know your company a bit better. Based on our knowledge of your organization and the needs you have, we can put together a proposal.
In it you can expect prices, timing, dates and topics.
Didn't find the answer to your question?
We've grouped various security topics by category so you can quickly and easily find the information you're looking for. And if your question isn't listed yet, don't hesitate to get in touch. Our team of experienced ethical hackers is ready to help. Make use of our expertise and let us make your organization safer.