Site navigation

NCSC Shares Advice on How to Really Challenge Pen Testers

Graham Turner

,

NCSC pen testing
The NCSC said secure design, network segmentation and effective monitoring can significantly restrict attackers’ progress.

The UK’s National Cyber Security Centre has outlined a series of measures organisations can take to make critical infrastructure systems more difficult for attackers to compromise.

Drawing on feedback from penetration testers working with operational technology, the NCSC said organisations should prioritise secure system design, network segmentation, logging and monitoring, and the use of appropriately experienced testing providers.

Penetration testers, often referred to as pen testers, are employed to identify vulnerabilities by attempting to gain access to systems and infrastructure. The weaknesses they uncover can then be addressed before they are exploited by malicious actors using similar techniques.

The NCSC said it asked pen testers: “What can organisations do to make your job harder?”

According to the feedback, one of the most important steps is to ensure systems are secure by design, with security treated as a core requirement from the beginning rather than added after deployment.

The NCSC said vulnerabilities are rarely absent from complex systems, but remediating them is typically easier when security has been built into the original architecture. This approach can also provide the foundation for technical controls designed to make attacks more difficult to carry out.

Network Segmentation

Network segmentation was highlighted as one of the clearest examples of secure-by-design thinking, particularly where it has been incorporated into the system from the outset.

Segmentation involves dividing a network into smaller sections through network design, virtual local area networks, firewalls or the use of separate accounts and user groups for different parts of the environment.

For organisations operating operational technology, the NCSC said there should be a clear separation between OT control systems and the wider IT infrastructure used across the business.

From a security perspective, segmentation can make it more difficult for attackers to move laterally through a network after gaining an initial foothold. Within OT environments, limiting that movement can help reduce the risk of disruption to physical processes and loss of system availability.

The NCSC added that segmentation should extend beyond simply separating IT and OT environments. Organisations should also control what information and access are permitted to cross the boundary between them.

Cross-domain approaches can be used to define areas of trust and tightly manage the movement of data between systems. Secure OT connectivity should minimise exposed connections, establish standardised access routes and strengthen network boundaries.

The use of privileged access workstations can also provide trusted devices for administrative activity, reducing the likelihood that users will take insecure shortcuts and making lateral movement more difficult.

The NCSC also emphasised the importance of logging and monitoring, particularly within systems that have already been securely designed and segmented.

According to the agency, good-quality monitoring can make life more difficult for penetration testers by allowing security teams to identify their activity as they move through different parts of a system.

However, the NCSC warned that collecting logs alone is not sufficient. Organisations must ensure they are gathering the right information and responding appropriately when alerts or suspicious events are detected.

“We can’t stress enough that even the best logging and monitoring capability is useless unless an organisation collects the right data, and responds to that data in the right way,” the NCSC said.


Recommended reading


Alerts should be properly investigated, while incident response plans should be developed, communicated regularly and tested with relevant teams.

The NCSC also recommended the use of purple team exercises, which combine red team offensive testing with blue team defensive activity. This approach can help organisations understand vulnerabilities uncovered during testing and ensure they are properly remediated.

Organisations planning to commission a penetration test were encouraged to consider providers included in the NCSC’s CHECK scheme, which lists companies approved to carry out authorised testing.

Where testing involves operational technology, organisations should ensure the provider has relevant experience of working with those environments.

The NCSC warned that testers without appropriate OT expertise could overlook vulnerabilities specific to industrial systems. In more serious cases, testing activity could unintentionally affect operational systems and create real-world consequences.

The agency said its recommendations do not represent a complete checklist for protecting systems against cyber threats, but could help organisations improve their resilience and make it more difficult for penetration testers and malicious attackers to progress through their infrastructure.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data