Security Audit - Penetration Test

Considering the increasing reliance on information and ubiquitous interconnectivity, enterprises today may only ensure the continuity of their operations by getting all risks under tight control.

Whatever the threats, they must be able to develop their business in a fast, secured and consistent way. Both our security assessment and penetration tests are integrated in our security audit mission.

Our security audit services can be subscribed in a flexible way according to your needs: predefined packages or customised projects; exhaustive investigation or specific narrow test; isolated one-shot probe or recurring program; simple conformance check or full penetration war-game…

We offer predefined Assessment Services packages:

  • Penetration test from internet in a real controlled hacking scenario
  • Advanced layer assessment with e-business flows vulnerability check and e-business application layer review
  • Global security assessment covering regulatory compliance, procedures, components configurations, physical security, architecture, access control…
  • Analysis of security posture versus best practices and identified vulnerabilities

Through regular measurements of the security posture and clear preventive and curative recommendations, ebrc Security Audit Services help the clients:

  • Preserve the integrity and confidentiality of the information
  • Preserve its reputation towards its clients as well as business partners
  • Deliver pertinent information about the reliability of their networks and applications to auditors
  • Enhance compliance with the regulation, especially for financial institutions
  • Protect against hostile acts coming from hackers as well as malicious employees
  • Prevent revenue loss due to vulnerable systems and processes

ebrc consultants are certified ISO 27001 lead auditor and implementation, which guarantees the compliance with the best international standards.
ebrc builds relevant security program in compliance with legal constraints, international (Basel II or MIFID, ,…) as well as national financial and privacy regulations (CSSF, CNPD,…)

Specifically for penetration tests, ebrc local experts follow the best international methodologies in the security field:

  • OSSTMM V3, international standard for network auditors, in which ebrc experts are ones of the few certified in Luxembourg
  • OWASP, specific to application testing
  • GIAC certification that illustrates our mastery of Wi-Fi security testing

< Information security policy                                                                 It Outsourcing Management Model >