Increasing cyberattacks prompt need for fast, frequent penetration testing, expert tells businesses

Many businesses and government agencies now recognize that it is not enough to just look out for weaknesses in their computer systems, according to an industry player, saying these organizations now see the importance of adopting more active and thorough methods to prevent cyberattacks.
Organizations need to quickly and regularly fix security issues in their systems and use automated checks to ensure those fixes work, especially since online threats are constantly increasing, Michael Tan, Asia Pacific vice president for sales at global cybersecurity software company听Pentera, said in an interview with听叠耻蝉颈苍别蝉蝉奥辞谤濒诲听on Thursday.
鈥淲e need to come from the attackers鈥 point of view,鈥 he said on urging constant validation measures beyond breach and attack simulations (BAS) and samples, which he added are 鈥渘ot solely feasible anymore鈥 given rapid technologies.听
The Philippines was the second most attacked country by web threats last year, with 39,387,052 internet-borne threats detected, according to data from Kaspersky. The country placed fourth in 2021.
It also saw 2,409,085 brute force or trial and error attacks among remote workers, 52,914 financial phishing cases among businesses, 24,737 crypto-phishing cases, 15,732 mobile malware cases, and 50 mobile banking Trojan cases last year.听
Mr. Tan noted companies with interoperating security solutions inevitably create non-patchable gaps that cybercriminals can see and attack.
Pentera鈥檚 2023 survey report on the state of pentesting, or penetration testing, said 88% of organizations still report cyberattacks amid large investments, where an average of 44 security solutions are in place for a single enterprise.听
It also noted the increasing importance of cyber insurance as the top reason for pentesting at 36%.听
However, the biggest barrier to pentesting is its risk to business continuity, amid 82% of companies already pentesting in some form,听Pentera听said.听
While pentesting is moving beyond regulatory compliances,听Pentera听has seen a unique opportunity to introduce one-day point-of-view testing in enterprises鈥 live production environments, which Mr. Tan noted as a one-day challenge for the company.听
鈥淚f a solution will create downtime, it鈥檚 out of the way,鈥 he said on employing continuous on-premise software solutions, alongside application programming interfaces integration in its cloud services. 鈥淟ast year, this was impossible.鈥听
Mr. Tan mentioned that most of the vulnerabilities听Pentera听has seen included misconfigurations, password weaknesses, and policy settings. 鈥淢itigation is more than just patching [these],鈥 he said.听
Following its entry to the Philippine market in January,听Pentera听has partnered with Netpoleon, an APAC-based security provider, to distribute听Pentera鈥檚 solutions and aggressively expand its customer base in the region, Mr. Tan said.听
鈥淲e are coming out with regular online training with partners and new functionalities and features every few weeks,鈥 he said on keeping up with rapid technologies.听
The company is targeting to service the financial sector and other distributed industries with small security teams and outdated or legacy systems, such as automotive and manufacturing plants, he added.听
However, Mr. Tan noted the importance of initially addressing cyber hygiene among enterprise employees before stacking security solutions.听
鈥淪ecurity technology is moving so fast,鈥 he said. 鈥淵ou might make it more complicated.鈥听
鈥淭he government needs to have more initiative to create security awareness,鈥 he added, citing that the weakest link in the growing cybersecurity landscape is always the people.
鈥淢ore work and awareness need to be done.鈥 鈥 Miguel Hanz L. Antivola


