Nemko has, through its subsidiary System Sikkerhet, extensive competence and experience in evaluation and certification of information security. This competence has enabled an expansion into vulnerability assessment and penetration testing services from a new special laboratory now established at Arendal in Norway.
All product development includes the phases of design – producing – testing. For connected IT products, the testing part includes penetration testing, where the system is scanned for known vulnerabilities as well as being exposed to more sophisticated «attacks». The purpose of penetration testing is both to reduce the risk of breach to happen, but also to limit the damage if a breach actually happens.
The types of vulnerability assessment and penetration testing depends on both the product and its application. Examples are:
Both the number and severity of cyberattacks are increasing. Producers of IT equipment and systems as well as the end users are experiencing/discovering how vulnerable one may be for devastating attacks, ref. e.g. the cases reports here and bbc case report can be shown here.
For further information and/or request for services in this area, please contact Oyvind.Storhaug@nemko.com
* This blog is edited by Trond Sollie