Specialist supplier will support in searching – and then attempting to take advantage of – ‘vulnerabilities and exploitable information’
——————————————————————————
A dedicated Government Security Red Team is to assess departmental defences with exercises in which experts conduct digital and in-person reconnaissance and attempt to exploit vulnerabilities found, PublicTechnology can reveal.
Common in the worlds of cybersecurity and defence, the role of red teams is to better understand the effectiveness of an organisation’s defences by mimicking attackers or other hostile actors. Red-teaming exercises can often involve not just cyber penetration testing to analyse the security of IT systems – but also social engineering and in-person spying to ascertain possible means of gaining access, as well as the testing of physical security measures, such as locks and gates.
The Cabinet Office-based Government Security Red Team – known as GSRT or referred to as OPEN WATER – has just signed a six-month £150,000 deal with specialist supplier Cerastes, which will support the provision of “physical penetration exercises” targeted at three Whitehall departments.
These exercises will involve a process of collecting open-source intelligence (OSINT) and conducting in-person reconnaissance on each of the trio of target organisations – the identity of which has not been specified.
The aims of this information-gathering include “identifying vulnerabilities and exploitable information and/or pattern of life” details.
Related content
- Government’s cyber plan delivers ‘a complete revolution in how we provide assurance’
- EXCL: Cabinet Office alerted to data breach – and fails to respond for 10 days
- Departments to undergo independent audits of cyber resilience
This intelligence will then be used in “attempting to gain access based on the findings of OSINT and reconnaissance”.
“If access is successfully gained, then [the supplier will be] executing the scenarios as agreed between GSRT and target department and, in addition, looking for other opportunities for compromise which may not have been previously identified and to be agreed between the supplier, the GSRT and the department as the testing progresses,” according to commercial documents.
Cerastes will be expected to provide Cabinet Office security officials with a “detailed report including and consolidating all findings from the OSINT, reconnaissance and penetration phases as well as including recommendations for remedial actions to be considered for implementation by the department”.
The findings of these reports will also be presented to range of senior managers and security professionals at the departments targeted by the exercises. The security-testing initiative is intended to support the work of the ongoing National Cyber Security Programme, which is charged with overseeing the delivery of the UK-wide cyber strategy published by the government in early 2022.
It is not known which departments may be targeted by the hostile reconnaissance, how they might be chosen, or the extent to which they may be forewarned about what is to happen – although the text of the contract suggests that the GSRT will reach some kind of agreement with the agencies in question concerning the proposed testing “scenario”.
In response to an enquiry from PublicTechnology requesting these details and any other available information on this initiative, the Cabinet Office indicated that it did not comment on security matters.
‘Influenced and disrupted’
After its initial six-month term, “approval is being awaited” for a potential six-month extension to the department’s contract with Cerastes. This would be worth a further £150,000 to the central London-based outfit.
Staff provided by the company to fulfil the Cabinet Office engagement will earn £940 for a day for team-leader duties, £740 for work as an reconnaissance or testing operative, and £475 for researchers. All prices exclude VAT.
The deal, which covers the provision of the covers the provision of Cerastes’ ‘Hostile Perspective Security – Red Teaming and physical penetration testing’ service offering, was awarded via the now-defunct G-Cloud 12 framework.
“If access is successfully gained, then [the supplier will be] executing the scenarios as agreed between GSRT and target department and, in addition, looking for other opportunities for compromise which may not have been previously identified”
According its listing on the government’s online Digital Marketplace, the service purchased by the Cabinet Office provides customers with the ability to “accurately replicate any chosen threat’s planning and reconnaissance process, allowing the vulnerabilities seen from this hostile perspective to be identified, and where along their attack planning pathway your threats can be influenced and disrupted”.
Threat scenarios can be created to a bespoke script to best suit the buyer’s needs, following which Cerastes can offer vulnerability assessment of the online and physical world, and “intelligence-led testing” of security measures and processes, the firm’s listing added. The security company can also provide organisations with training to boost awareness of hostile actors and their methods.
Procurement records indicate that that company has won one previous public-sector deal: a £600,000 contract awarded in 2020 to provide the Home Office with support for its red-teaming activities over a period of almost three years.
https://oragoda.tistory.com/entry/2021-스키장-개장일-2022-개장-일정-비교
https://oragoda.tistory.com/entry/건축물대장-발급-무료열람-하는-방법
https://oragoda.tistory.com/entry/면역력-높이는-음식-top-3
https://oragoda.tistory.com/entry/도시가스-요금조회-및-계산-방법
https://madreviewer.tistory.com/tag/가원권
https://madreviewer.tistory.com/tag/갤럭시20a325
https://madreviewer.tistory.com/tag/원드라이브20동기화
https://k-studio.kr/신용점수-900점-신용등급-그리고-신용관리의-중요성/
Thank you for your help and this post. It’s been great.
Thank you for writing this post. I like the subject too.
아름다운스웨디시업소
대전나이트클럽
May I have information on the topic of your article?
https://klero.tistory.com/tag/사회적20거리두기20단계별20비교
You helped me a lot by posting this article and I love what I’m learning.
충무로출장업소
수원출장샵
이태원게이바
울산콜걸
https://pornmaster.fun/hd/香港中西区应该怎么找兼职小姐上门服务选妹网站m275-com真实上门服务香港中西区怎么找兼职小姐上门spa服务选妹网站m275-com真实上门服务香港中西区哪里有兼职小姐全套特殊服务-香港中西区哪里有兼职小姐一条龙大保健服务-香港中西区找附近人全套特殊服务-qsb
Upgrade Your Style with Bragle Sweaters – Uncover exclusive opulence with Bragle’s sweaters for women—the ideal blend of warmth and sophistication. Crafted from high-quality materials like cashmere and merino wool, each garment exudes refined elegance for those with a taste for high-end fashion. From iconic styles to trendy silhouettes, Bragle sweaters effortlessly adapt from casual to formal, keeping you warm and uncompromisingly elegant. Shop at **Bragle.com** to explore the selection and embrace the ultimate in luxury.
https://pornmaster.fun/hd/u0928u0902u0917u093e-u00e0esi-sex-in-jungle-hdmp4-amil-pampu-set-sexamil-aunty-milk-breesi-sexy-old-women-gand-marne-ka-videoareena-kapoor
https://pornmaster.fun/hd/to-please-bae-with
I really appreciate this post. I have been looking everywhere for this! Thank goodness I found it on Bing. You’ve made my day! Thx again
이태원스웨디시안마게이클럽
대전세븐나이트
https://itlearn.kr/파워포인트-무료설치-다운로드-방법/
Transform Your Look with Bragle’s Elegant Sweaters – Discover exclusive luxury with Bragle’s women’s sweaters—the perfect combination of warmth and sophistication. Made from luxurious fabrics like soft merino wool and cashmere, each design highlights refined elegance for those with a taste for upscale clothing. From timeless classics to modern chic, Bragle sweaters effortlessly adapt from casual to formal, keeping you comfortable and flawlessly fashionable. Shop at **Bragle.com** to shop the full range and indulge in the height of elegance.
벼룩시장 구인구직 및 신문 그대로 보기 (PC/모바일) | 구인구직 앱 어플 무료 설치 다운로드 | 모바일 벼룩시장 보는 방법 | 벼룩시장 부동산 | 지역별 벼룩시장 | 벼룩시장 종이신문 에 대해 알아보겠습니다. 섹스카지노사이트
충무로출장업소
양산시술출장마사지
강남콜걸
영등포안마살롱
전신스타킹
충무로출장업소
이태원스웨디시안마게이클럽
아름다운스웨디시업소
하동동해출장만남 소자본 창업
충무로출장업소
수원출장샵
여행지
https://itgunza.com/223
https://itgunza.com/435
https://itgunza.com/557
https://itgunza.com/380
https://itgunza.com/557
https://itgunza.com/1455
https://honeytiplabs.com/인스타그램-활동중-끄기-및-켜기-현재-활동중-현활/
https://honeytiplabs.com/사파리-방문기록-삭제/
https://ajaedotcom.tistory.com/entry/유튜브-음원추출-사이트
https://ajaedotcom.tistory.com/entry/도로명-주소-찾기-변환-검색하는-방법
강남안마시술소중계업체
영등포안마살롱
https://ddnews.co.kr/blog/2024/03/10/ebb2bceba3a9ec8b9cec9ea5ec8ba0ebacb8eab7b8eb8c80eba19cebb3b4eab8b0/
대전나이트클럽
청도페이스라인출장
https://nicesongtoyou.com/
하동동해출장만남 소자본 창업
영등포안마살롱
https://gorgopage.com/신한은행-닥터론의사-의대생-전공의-전문의-대출-조/
https://news.gorgopage.com/115
여행지
https://sportscom.co.kr/korea-japan-baseball-1117/
https://chotiple.tistory.com/tag/소상공인20손실보상금20신청
https://madreviewer.tistory.com/tag/볼보XC60가격
https://gorgopage.com/삼성케어플러스-에어컨-세척-세탁기-청소-이전설치/
https://nicesongtoyou.com/today-fortune/weekly-horoscope/
대전나이트클럽
영등포안마살롱
https://itmoney4you.com/남진-인천콘서트/
https://itgunza.com/355
영등포안마살롱
아름다운스웨디시업소
https://k-studio.kr/category/life/page/5/
https://news.gorgopage.com/93
여행지
https://download-install.com/entry/ECBBB4EC8B9CEAB084-EC958CEBA6ACEBAFB8-EB8BA4EC9AB4EBA19CEB939C
https://download-install.com/entry/EC98A4ED86A0ED81B4EBA6ADAutoClick-EC84A4ECB998-ED9484EBA19CEAB7B8EB9EA8-EB8BA4EC9AB4EBA19CEB939C
https://download-install.com/entry/ED8C8CED8C8CEAB3A0-PCEBB284ECA084-EB8BA4EC9AB4EBA19CEB939C
https://download.beer/wp-content/uploads/2021/01/Google-drive-image-2.jpg
https://infohelpforyou.com/재벌집막내아들/
https://infohelpforyou.com/구미-알바천국/
https://madreviewer.tistory.com/tag/와이즐리면도기후기
https://madreviewer.tistory.com/tag/와콤20인튜어스20프로20PTH-651
https://madreviewer.tistory.com/entry/스텔스-오미크론-증상-및-문제점
https://download-install.com/tag/이더리움
https://download-install.com/tag/무료20엑셀
https://mintfin.tistory.com/auth/login/old?redirectUrl=https3A2F2Fmintfin.tistory.com2Fmanage
https://mintfin.tistory.com/tag/로또당첨확률20높이기
https://klero.tistory.com/tag/정부2420바로가기
https://klero.tistory.com/tag/주취상태20뜻
https://klero.tistory.com/tag/7080노래20무료듣기
https://dnolife.net/software/memoit/
mexican online pharmacies prescription drugs: Mexican Easy Pharm – Mexican Easy Pharm
mexican rx online https://mexicaneasypharm.shop/# п»їbest mexican online pharmacies
buying from online mexican pharmacy
http://predpharm.com/# brand prednisone
prednisone 500 mg tablet
https://dappharm.com/# DapPharm
how to buy prednisone online
http://kamapharm.com/# Kama Pharm
buy prednisone online australia
https://cytpharm.shop/# buy cytotec online
can i purchase prednisone without a prescription