August 11, 2016 By Charles Henderson 2 min read

Now that Black Hat and DEF CON 2016 are behind us, I can finally report what a great week we at IBM had. We had high hopes for the public launch of X-Force Red, of course, but the response exceeded our expectations.

The media coverage has been very positive and we’ve received great feedback from both customers and colleagues in the industry. Of course, this wouldn’t have been possible without a great team, to which I owe a huge thanks.

Improved Scoping Mechanisms

Everyone hates scoping a penetration test. If you’re a client, filling out complex scoping surveys about the count of webpages, classes or database servers eats up your time and does nothing to improve your security.

Instead of questionnaires, X-Force Red offers simple scoping mechanisms. For application and hardware projects, customers can select preset test durations based on the target’s size and risk profile. Similarly, network tests are scoped by targeted IP address blocks and source code reviews are scoped per line.

Three X-Force Red Models

X-Force Red can be engaged in three models: standalone tests, subscription and managed. The standalone offering is for organizations that want to purchase each test individually.

The subscription model allows an organization to dedicate a set of funds for testing over the next 12 to 36 months. When the need for security testing arises, there is no additional need for statements of work, contracts or any other legal paperwork that can slow down an engagement. The client simply picks the level and type of testing, and the project is scheduled. This is ideal for organizations that may not know what specific targets need to be tested at the beginning of the fiscal year.

The managed model builds on the subscription model by providing a dedicated resource to run the client’s testing program. The consultant is responsible for identifying testing targets, prioritizing them and selecting the proper testing level. Once the test is complete, the consultant also tracks and coordinates the client’s remediation efforts.

Four Testing Categories

As mentioned previously, we offer four categories of tests: application, network, hardware and human. A client can select any test, regardless of their engagement model.

  • Application: Manual penetration tests, code review and vulnerability assessments of web, mobile, terminal, mainframe and middleware platforms;
  • Network: Manual penetration tests and vulnerability assessments of internal, external, Wi-Fi and other radio frequencies;
  • Hardware: Security tests that span the digital and physical realms with Internet of Things (IoT), wearable devices, point-of-sale (PoS) systems, ATMs, automotive systems, self-checkout kiosks, etc.; and
  • Human: Simulations of phishing campaigns, social engineering, ransomware and physical security violations to determine risks of human behavior.

Human Touch

Any company can license a tool and sell automated scans as penetration tests. Anyone who has been around security testing for very long has seen many cases of this misleading practice.

Automation is cheap and will always have its place in security, but it is the human factor that makes true penetration tests so useful. Every one of our penetration tests rely on human ingenuity. CISOs and other security decision-makers should use human testers as a critical criterion for their security program.

As my team moves forward in this new initiative, we are excited about the possibilities ahead.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today