Network Penetration Testing for a Mining Company

Network Penetration Testing for a Mining Company

Industry
Mining

Summary

A global mining company whose processes depend heavily on computer automation systems wanted to verify the protection of its IT environment as cybersecurity breaches in the industry became more common. With no security testing experts on staff, the Customer engaged INNERLUXES for its first network penetration test. The gray-box pentest found multiple high- and medium-severity flaws, rated the network security as low, and — after remediation — a retest confirmed a high security level.

About the Customer

The Customer is a global mining company with facilities in the United States and Europe, with a long-established presence in its field.

The Challenge

As news about disruptive cybersecurity breaches in the industry became more common, the Customer decided to check the protection of its own IT environment. Since the company's processes largely depend on computer automation systems, it was crucial to ensure that hackers couldn't interfere with their work. Another goal was to see whether any vulnerabilities could compromise the Customer's financial data and operations. With no security testing experts among its IT staff, the Customer was looking for a competent vendor to perform the first penetration testing of its extensive network.

The Solution

Having found INNERLUXES's penetration testing proposal and sample reports convincing, the Customer contracted INNERLUXES to test the security of its internal network, including Wi-Fi access points and Active Directory services. Considering the extensive scope, the pentesters recommended applying the gray-box approach.

Through vulnerability scanning and penetration testing of the internal network, the team revealed nine security flaws of high severity and six of medium severity, and evaluated the network security level as low — potential attackers with average to little technical skill could have found plenty of ways to gain unauthorized access to the Customer's IT assets. Most of the detected gaps came down to two issues:

  • Unprotected SCADA systems. The SCADA systems that help orchestrate and optimize mining operations lacked proper protection. INNERLUXES recommended isolating SCADA hosts in a separate closed network and strictly limiting access so they are reachable only through a jump server.
  • Outdated and unsupported operating systems and software in different network segments — Microsoft Windows, Microsoft SQL, Apache Tomcat, VMware, and more — accounting for thousands of known vulnerabilities. An attacker could have easily identified software versions and found exploits to launch DDoS, spoofing, remote code execution, man-in-the-middle, and other attacks. INNERLUXES recommended updating systems to current versions and keeping an inventory of all installed software for regular updates and patches; if legacy systems must stay, placing them in a DMZ would be necessary.

INNERLUXES provided detailed reports describing the vulnerabilities and the required corrective measures. After the Customer's in-house IT specialists fixed the critical issues, INNERLUXES performed another round of testing; the retest confirmed the high security level of the Customer's network.

As this was the Customer's first serious security checkup, INNERLUXES recommended undergoing a full-scale IT security assessment for a 360-degree view of gaps in existing policies, processes, and technology, and pointed out the importance of social-engineering testing (phishing and vishing simulations) to evaluate and improve employees' resilience to malicious emails and calls.

The Results

  • The Customer learned about the critical vulnerabilities that hackers could have exploited to infiltrate its IT environment.
  • Thanks to INNERLUXES's comprehensive guidance during and after the project, the Customer could better understand its cybersecurity posture, efficiently fix the security flaws, and plan feasible investments in its cyber defense.
  • Satisfied with the cooperation, the Customer plans to engage INNERLUXES in other security testing projects.

Technologies and Tools

Nessus, Burp Suite, Acunetix, Nmap, SSLScan, DirB.