This article was originally published in the Kibernetska varnost magazine on 23 February 2024.
Security testing results are the basis for business, service and product improvements

“The biggest problems with internal network penetration tests are inadequate system settings, unsupported or unpatched software, and weak passwords,” says Grega Prešeren, CTO at Carbonsec d.o.o., a company specialized in security assessments and penetration testing of systems, applications, and devices.
Since companies usually implement advanced security mechanisms to stop an attack from the outside, one would expect that an attacker would not get to the internal network in the first place. How come you can make such observations?
Indeed, companies usually take reasonable care to protect their systems against attacks from the outside. We mostly work for large enterprises, and at least for them, this statement is true. This is why attackers use employees as a vulnerability and exploit them to enter the network. Advanced phishing attacks and other social engineering techniques can easily trick the users to share their credentials. It only takes one careless user to open the door to the business network.
You mentioned that you primarily work with large companies. Do you notice any differences depending on the industry?
Of course, we do. Specific industries have been subject to strict legal measures for quite some years. In general, cybersecurity is best taken care of in banking. We can also observe a lot of progress in the energy sector. The projects of testing industrial environments are on the rise, probably also due to the IP connectivity of these critical systems. Introducing the European NIS 2 regulation into local legislation will make a big difference. I believe that having a wider range of organizations that will have to comply with the regulation will reduce the differences in the level of cyber security and resilience between industries.
What changes do you expect to see in cybersecurity governance following the adoption of the new law?
One is undoubtedly a wider range of parties that will have to comply with the law and consequently take a more strategic approach to security management, which means more monitoring, testing and continuous improvement. This is also the goal of cybersecurity management – continuous improvement. In addition, the network of external security tests will be expanded due to supply-chain security monitoring. This measure will make a higher cyber security level an essential competitive advantage.
Is this a new trend – cyber security as a competitive advantage?
This is a trend, or better to say, a necessity because we all demand secure services and products. This is clearly reflected in the increased demand for security testing of modern IP-connected devices and hardware, which requires specialist and dispersed hacking skills.
What do you think are the three golden rules for successful protection against cyber-attacks?
We always recommend using network segmentation, strong and unique passwords for both users and systems and regular cyber resilience tests and improvements.