Cybersecurity Compromise Assessments

Unrivaled incident response expertise and frontline threat intelligence fuel elite investigators to uncover if your organization has been previously compromised, ongoing incidents have gone undetected and if unmonitored assets are at risk.

Cybersecurity Compromise Assessments

A key component in understanding the total valuation of a company is determining its security profile and associated risks, even from within its network. Any compromise assessment should revolve around the following questions: 

  • Has the organization been previously compromised and, worse, was it undetected? 
  • Are obscure malicious events or incidents active within the enterprise IT environment? 
  • Do shadow IT networks exist within the enterprise that contain unmonitored assets?

With Kroll’s cybersecurity compromise assessment, our world class experts investigate to detect past and ongoing cyber incidents within an organization’s internal environment and provide mitigation steps to resolve any security events. This assessment can help facilitate better-informed business acquisitions and help determine whether an organization is currently at risk or has been previously compromised.

 

What Is a Compromise Assessment?

A compromise assessment is an exploratory incident response investigation in which experts use specialized forensic tools and investigative tactics to analyze an organization’s environment, pinpointing signs of attacker activity, both past and present.

This assessment can also enable organizations to highlight critical weaknesses in their cybersecurity controls and practices and put mitigation steps in place where necessary.

 

Why Perform a Compromise Assessment?

  • An Independent Security Health Check
    An effective and comprehensive compromise assessment can provide a deeper understanding of current and past activity on your network and help prevent future breaches. 
  • More Informed Business Acquisitions
    When acquiring a business, gaining an accurate and up-to-date picture of its cybersecurity status is critical. As well as helping to validate a merger or acquisition, the insights provided by a compromise assessment can contribute to establishing the value of the target company. 

Compromise Assessment Steps

Kroll’s compromise assessment process includes:

Initial Triage

A preliminary review of an organization’s IT environment from an endpoint sensor deployment perspective, establishing a baseline for the network.

Telemetry Analysis and Review

This stage is vital for determining whether there is any evidence of known indicators of compromise (IOCs), such as signs of active intrusions or malware that could enable remote access and data exfiltration capabilities.

Endpoint Detection and Response

If appropriate, this stage involves high-level health assessments of endpoints, powered by Redscan’s remote enterprise-wide managed detection and response (MDR) capability.

Advice and Guidance

Once the initial review is complete, our experts provide support for any active security events that may be present on the network.

Summary findings of the assessment may include, but are not limited to, the following:

  • End-of-life operating system reporting
  • Remote access software and related tool reporting  
  • File transfer software and related tool reporting
  • Egress network traffic reporting
  • Relevant endpoint software CVE reporting
  • Active directory account reporting

We leverage our forensic and incident response expertise in responding to 3,000+ engagements every year to assist in addressing current threats and advising on further incident response actions and any other additional investigative steps required. 

 

What If Activity Is Detected During a Compromise Assessment? 

A cybersecurity compromise assessment can uncover both past and current activity on a network. If this type of activity is actively identified during the course of the compromise assessment, Kroll can immediately pivot, leveraging the same tooling and endpoint coverage, into incident response and undertake forensic analysis on affected hosts. This involves:

  • Containment and threat actor ejection
  • Remotely collecting relevant forensic artifacts 
  • Determining the time frame and scope of potential sensitive data exposure, data exfiltration or compromised accounts 
  • Providing recommendations for containment and remediation to ensure your organization is more secure going forward 

Compromise Assessment vs. Vulnerability Assessment

Performing a compromise assessment differs from a vulnerability assessment in a myriad of ways. While both are crucial, each serves a different purpose in ensuring the security of a network.

Compromise Assessments: Wide-Ranging Insight Into Past and Present Malicious Activity
Vulnerability Assessments: Proactive Evaluation for Identifying Weaknesses
 

A compromise assessment determines the current security status of a network, including any active threats or indications of past malicious activity. This provides organizations with wide-ranging insight into their security, allowing them to reduce the risk of future attacks and identify ineffective security practices that could be compromising their security.

 

A vulnerability assessment is performed to proactively evaluate a network for weaknesses through assessment tools and manual attack techniques. This can help improve an organization’s security posture and make it less susceptible to a breach. While these types of engagements are designed to search for security vulnerabilities, unlike compromise assessments, they do not detect existing compromises and related underlying attacker activity.

 

Compromise Assessment in a Retainer

A compromise assessment delivered by proven experts can provide critical insight into the security of your network—and assure the continued security of your organization. Kroll clients can include a compromise assessment in Kroll’s cyber risk retainer, as part of M&A due diligence review, or a network merger, post-acquisition. A cyber risk retainer provides prioritized access to elite investigators and the flexibility to allocate credits to all other cybersecurity solutions offered by Kroll. 

img

Let's solve for the future