Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementSecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Explained: Firewalls, Vulnerability Scans and Penetration Tests

By Christopher Gerg
server room, cybersecurity, penetration testing,
November 12, 2019

Many organizations choose to implement just three fundamental safeguards to protect their organization from unexpected cybersecurity threats. The implementation of a secured perimeter and internal firewall network architecture and conducting Vulnerability Assessments and Penetration Tests (VAPT) are often seen as enough to protect critical business information. However, as we will discover and despite this approach being a good start, there is substantially more to information security than firewalls and VAPT.

Firewall and VAPT

The firewall is the first line of defense of a computer network; its purpose is to restrict unauthorized traffic from different layers of the network. A perimeter firewall is the entry point for incoming (ingress) and outgoing (egress) network traffic. An internal firewall protects the internal network layers by allowing or denying traffic. Securing the network architecture creates segregation that will only permit approved traffic across the network; all other traffic is blocked by default, this prevents unexpected data from traversing the wrong network segments.

A Vulnerability Assessment is a technical safeguard that aims to discover weaknesses within an organization’s IT infrastructure. The scan targets the entire network identifying all devices, servers and endpoints by IP address. The scan will identify the applications and operating systems that are in use. Gathered data is cross-referenced against a security database for known exploits and vulnerabilities. This will help to identify if a device is vulnerable or not.

Any non-compliant device is flagged and added to a vulnerability report. The report is used as a baseline for post-assessment activities. Identified weakness in the organization's environment needs to be resolved. Fixing issues with, for example, scheduling patching, software updates, firmware updates or blocking network ports should follow the vulnerability scan.

Organizations also undertake penetration testing; this is a real-world scenario when a specialist security engineer (often external) will attempt to breach your organization's computer network. This may be a physical ‘attack’ on the organization's premises, but it is often an ethical hacker attempting to compromise the internal computer systems. Penetration tests target known vulnerabilities and exploits in operating systems, software applications, misconfigured systems or weak end-user protection – such as passwords or AV.

The penetration test is a vital tool that helps intelligently manage IT vulnerabilities. It may help to achieve regulatory compliance or help preserve customer loyalty and protect the value of your brand. Both the VAPT should form part of a continuously evolving cybersecurity strategy.

Ensuring your network security and performing VAPT assessments is only a small part of what is required to create a progressive and robustly secure InfoSec strategy. There are many other facets needed to introduce substantive protective measures. A cybersecurity framework is required that is able to Identify, Protect, Detect, Respond and Recover to security threats.

Identify Security Risks

The first task to complete is a thorough Risk Assessment; the aim here is to identify all company assets such as the data, devices and hardware and software platforms. It will also identify business processes (governance), such as organizational communication flows, business resources and existing cybersecurity roles and responsibilities.

The data from the risk assessment is used to identify asset vulnerabilities and threats, both internal and external. An assessment of the potential business impacts will identify the organization's priorities, constraints and risk tolerances.

Protect

The next step is to create a remediation roadmap; a major step towards incorporating tighter security controls. The roadmap dictates how to protect the organization's infrastructure, highlights the priorities and recommends the sequence to complete the tasks. Much of the protection will initially relate to identity and authentication, ensuring that the identities and credentials of all users are valid and verified to protect physical and remote access to sensitive data.

The roadmap will also identify data security weaknesses and make recommendations about how data should be protected at rest and in transit. Security policies will be created to advise how to harden the organization's internal processes and procedures, including change management process, backup and restore procedures and the data destruction policy. Key recommendations are made within a Threat Advisory Bulletin, as well as advice on improving business continuity and disaster recovery procedures. It is here where the Information Security Awareness training requirements will be drafted for each department within the company.

Detect

The detection stage is conducted using vulnerability scans and penetration tests; this will help to pinpoint weaknesses in the computing and network infrastructure. These steps include identifying any additional technical and physical cybersecurity risks; it may also include the assessment of external third party’s providers such as managed service providers or security services.

Respond and Recover

Response planning and recovery processes are created to formulate an action plan which is to be followed in the event of an emergency or serious cybersecurity attack. It works similarly to disaster recovery or business continuity strategy where a pre-defined response is followed and each team member knows his or her roles and responsibilities.

A plan is drawn up that includes how to handle communications during a major incident, understanding who manages public relations, who manages internal communications. The technical processes that the engineers need to follow are also drafted at this stage.

The processes must be tested regularly and the results reviewed, analyzed and revised if necessary. Any mitigation activities must be drawn up for failures discovered during the tests, and the response plan and roadmap are updated accordingly.

To conclude…

There is much evidence to suggest that a firewall implementation and scheduling testing should be part of a much wider, all-encompassing cybersecurity strategy. The network security and penetration testing elements serve a key purpose overall, but they only make up a small part of a much larger security framework.

We have only scratched the surface on what information security is, but an ever-present theme is that InfoSec is part of a continuous improvement initiative, constantly tested and improved upon. Many organizations choose to outsource this responsibility to a security vendor who manages InfoSec for a large customer base.

The services you receive vary but often come with additional benefits such as Trusted Advisor check-ins to ensure your business is on track with its cybersecurity progress. Other key benefits include annual internal audit and roadmap check-up, disaster recovery testing, incident response testing, Phishing and social engineering tests, training and unbiased external penetration testing.

KEYWORDS: cyber security cybersecurity firewalls penetration testing threat assessment

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Christopher gerg

Christopher Gerg is the CISO and Vice President of Cyber Risk Management at Tetra Defense. He's a technical lead with over 15 years of information security experience, dealing with challenges of information security in cloud-based hosting, DevOps, managed security services, e-commerce, healthcare, financial and payment card industries. He has worked in mature information security teams and has built information security programs from scratch, leading them into maturity in a wide variety of compliance regimes.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Columns
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • c-suite

    How to Increase Collaboration Between IT and Executive Leadership Teams

    See More
  • Cybersecurity Intrusion Detection

    How Hackers are Exploiting COVID-19

    See More
  • server room, cybersecurity, penetration testing,

    Developing Scenarios for More Effective Penetration Testing

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!