Speakers
Description
At SURF, we've been pilotting several types of offensive security testing for a few years now. This ranges from attack surface mapping, vulnerability scanning and cloud configuration assessment all the way to SOC-chain tests, pentests and red teaming. We are planning to group some of these efforts in a service to our members, also taking some roles in gathering fidings, making sure others can learn from those and managing follow-up by our members.
We would like to brainstorm with other NRENs how we can serve our members with this type of service. We imagine a session where several NRENs can share what they do, why and how (products, setup, governance) to then split into groups discussing specific topics. Questions we are facing that might be a start:
- When doing vulnerability scans, who has an up-to-date list of assets?
- What does a business case for doing this as an NREN look like? How do you pay for it?
- What open source tools can be used for the different types of tests, how do you host/procure them?
- Are our members ready for full-fledged red teaming exercises?
- How do we relate this to crisis exercises?