Test with all the layers
Working for a bank. Pin testers can’t get access so they request that we add a rule in the firewall to allow them in. Management says we are paying a premium so we need to test everything.
Failing with firewall access, they ask for drop the ACL In the routers and switches.
Failing that, please remove the MS firewall on the servers.
Failing that, we need admin access, and then-
Oh look at all the vulnerabilities we found! We can see your data!
Out comes the report with all the vulnerabilities and we look like we are not doing our job. Fed auditors look at the report and lower the bank rating. Management finally took a hit for stupidity.
Pin testing is when you don’t change any security and they HAVE to prove they can compromise it.
Network assessment is where you give them access.
Know the difference.
Had an auditor as me when we had our last pin test.
“ We get get tested every few seconds, and it is free. Want to see the logs?”