• Risk management and risk register for your organisation

    Risk management while sounding threatening and complicated is really very simple; you need to identify/list all the risks, prioritise them, and then find effective and economical ways to reduce these risks. This is also an important GDPR requirement. The steps needed to follow are Identifying risks: find out what could cause harm. A good group […]

  • Scope of the web application assessment (penetration test)

    sapna security has a team which has years of experience on web architecture and applications and their vulnerabilities. Accordingly we have created a strong web application assessment list which includes the following areas: Injection Authentication Session Management Cross Site Scripting (XSS) Insecure Direct Object References Sensitive Data Exposure Access control Cross-Site Request Forgery (CSRF) Unvalidated […]

  • March, September 2018 deadline for some SSL/TLS certificates

    Whats the fuss about? Google accused Symantec Corporation of series of failure to properly validate certificates. Google accordingly proposed that they will effectively withdraw Chrome browsers trust in all certificates issued by Symantec. Any resolution? Digicert acquired Symantec and a compromise was reached by Google to accept the certificates till some time. Symantec certificates will […]

  • Ethical hacking for UNICEF

    We recently conducted a penetration (ethical hacking) for a site of UNICEF. Our expert team members managed to find vulnerabilities as can be seen in the snapshot below. We have also finished the remediation process by helping close and/or lower these findings after fixes were done.

  • Password guideline for general users

    News portals are filled with reports on compromised accounts. We know friends who have had their Facebook, Yahoo, and other accounts hacked and can no longer access making them exposed to their sensitive emails, and even allowing hackers to pose as someone else. While application developers do their best to ensure safety, the first basic […]

  • Our internal staff training approach

    Internal staff training is an important step for any organisation for improving efficiency, skillset and policy/security awareness. The ICO even has a checklist for small and medium sized organizations https://ico.org.uk/media/for-organisations/documents/1606/training-checklist.pdf In Sept 2017 we started a new approach to our staff training session and system. The approach we followed was Created a training group which […]

  • Quick guidelines to GDPR

    Synopsis As many of you may be aware the General Data Protection Regulation (GDPR) was adopted on 27th April 2016 and becomes enforceable from 25 May 2018. GDPR applies to you if you are a data controller or processor of personal information. We appreciate that many organisations might not have the resources to manage GDPR […]

  • Our first commercial penetration test

    We successfully completed our first commercial penetration test last week. Our client had already got its system tested by another security agency and after fixes were made they asked us to perform another test. We found around 10 issues overall across network, Apache/PHP settings, XSS, and more importantly priority issues like SQL injections. SQL injections […]

  • Equifax faces multibillion dollar class action lawsuit over not doing enough to protect data

    Equifax discovered the vulnerability in July, but choose to reveal it publicly more than a month later. During this time three senior executives sold about $1.8 million in stock. The company was also widely criticized for its customer service approach in the aftermath of the hack, with users not know what data was hacked. Data […]