The operations of most companies have become dependent on digital tools, which bring new risks and threats, primarily from various hacking attacks and exploitation of vulnerabilities in business systems. For this reason, A1 Hrvatska provides its business customers with an automatic penetration testing service, a state-of-the-art preventive protection system through which experts from this company continuously monitor, detect, and assess user systems, their exposure to attacks, and propose protective measures in accordance with the risk of attacks.
Cyber attacks are among the greatest threats to the daily operations of today’s companies, which have moved most of their business into the digital sphere. Among the biggest threats are DDoS attacks, ransomware, and malware, as well as outdated and poorly maintained infrastructure. Various studies show an upward trend in such attacks. According to Infosecurity magazine, the global number of DDoS attacks in 2022 was 74% higher than the previous year. Similar figures are confirmed by PwC’s research on global economic crime and fraud for 2022. Worldwide, 32 percent of companies with revenues up to $100 million experienced a cyber threat, 41 percent of those with revenues between $100 million and $1 billion, 42 percent of companies with revenues between $1 billion and $10 billion, and 32 percent of those with revenues exceeding $10 billion.
The automatic penetration testing service is a vulnerability assessment of the information system in which the tester acts like a hacker. The tester attempts to exploit identified vulnerabilities to gain unauthorized access to the system, access data for which they do not have permission, disrupt the operation of other users, or take control of the system. These vulnerabilities can exist in operating systems, services, but can also arise from improper system configurations or risky behavior of company employees or its end users. Such assessments are useful for confirming the effectiveness of companies’ defensive mechanisms, as well as for compliance with end-user security policies.
