Case Studies

True tales of customer success with Sentinel

At Sentinel, we build technology solutions to solve business needs. Maximize a customer's investment in technology, while building secure paths for the future. Resolve business issues to build competitive advantages. Learn more about how Sentinel projects yield positive results!

City Government Improves Its Password Protection

Wed Mar 02, 2022

Environment

The customer had solutions from a variety of vendors in their IT environment, including Cisco for their networking routers, switches, firewalls, and wireless. They had Microsoft O365 deployed through an Azure cloud setup, as well as NetApp to handle their storage and Cohesity for backup.

Challenge

While the customer had built a robust security infrastructure with firewalls, SOC & SIEM monitoring, and endpoint detection, they weren’t entirely sure about the strength of their overall security posture and wanted to find out if there were any weaknesses that could potentially be exploited during a cyber attack.

Solution

Sentinel proposed conducting both an internal and external penetration test to help uncover any security gaps within the customer’s environment. The external pen test simulated an attack attempting to breach the customer’s network and escalate access to obtain private or sensitive information. The internal pen test used a laptop shipped to the customer to simulate an attack from within their network and gain access to private or sensitive information.

Results

The penetration tests uncovered some major flaws within the customer’s security infrastructure, largely stemming from their password policies. A Fortis analyst cracked the passwords of multiple users and obtained a large amount of private information, including employee social security and credit card numbers. The customer was shocked by the size and scope of sensitive data collected by Fortis and took immediate action to remedy this security weakness. A new policy increased the number and variety of characters required for all user passwords. Cisco Duo was also deployed in their environment, creating a multi-factor authentication requirement for users when logging into the local network and applications.

One year after these changes were made, Fortis conducted another penetration test on the customer’s environment and was unable to gain access. The customer continues to work with Sentinel on a regular basis to further improve their IT environment with complex projects and initiatives.