Public Sector Focus

04.04.16

Web application security in the public sector

Advertorial Feature

With the uptake of cloud computing and the advancements in browser technology, web applications and web services have become a core component of many business processes, and therefore a lucrative target for attackers. Over 70% of websites and web applications however, contain vulnerabilities that could lead to the theft of sensitive data, credit cards, customer information and Personally Identifiable Information (PII). 

High profile cyber-attacks regularly make the headlines, exposing citizens to financial loss and worry, and costing organisations millions. Consequently web security is becoming higher on the IT agenda for UK organisations in both the private and public sectors – particularly those with a cloud-first approach. According to PWC's latest Global Economic Crime Survey, over half of UK organisations say they expect to be the victim of cyber-crime in the next two years, suggesting it will become the UK’s largest economic crime. 

The statistics 

The UK 2015 information security breaches survey (carried out by Department for Business, Innovation and Skills published in June 2015) noted that a staggering 90% of large organisations surveyed, admitted to having experienced at least one data breach within the last year, with 74% of small business reporting a breach. The most severe online security breach for big business reached a staggering £3.14 million. With security breaches on the increase, web vulnerability testing has become a critical minimum security requirement for all organisations. 

But it’s not only private organisations that are at risk, the public sector is just as vulnerable. A new Nesta report states that councils should become ‘digital by default’ by 2020, including by moving all transactional services online and fully digitising their back offices. Even though this will bring huge benefits, councils need to address a number of concerns about cyber security, privacy, and consent to retain public confidence in the security of data. 

I have a firewall - that should do it 

Unfortunately there is a misguided mentality that installing a firewall is sufficient to stop an attack. Although an important step in an organisation’s security posture, any defense at network security level will provide no protection against web application attacks since these are launched on port 80/443, which must remain open in order to allow visitors to visit your website. The attacker can then go straight through the firewall, past operating system and network level defences and right to the heart of the application and sensitive data. In addition, web applications are often tailor-made and therefore tested less than off-the-shelf software and are more likely to have undiscovered vulnerabilities. 

The solution: Regular automated vulnerability scanning 

Using a web vulnerability scanner like Acunetix Vulnerability Scanner ensures vulnerabilities are detected before a hacker can exploit them. A Vulnerability Scanner is used to crawl all web-based business-critical assets, automatically analysing them for perilous vulnerabilities and flaws that could expose the organization. The scanner detects and reports on vulnerabilities in applications irrespective of the architecture they are built in (such as PHP and ASP.NET) as well as being able to scan and detect vulnerabilities in applications built using popular CMS systems such as WordPress, Drupal and Joomla!.

Important Scanner Features:

1) Crawling and Scanning

A fundamental process during any scan is the scanner’s ability to properly crawl an application. Look out for a scanner that can crawl complex web application architectures including JavaScript-heavy HTML5 Single Page Applications while being able to scan restricted areas automatically and with ease. 

2) Detecting vulnerabilities

With vulnerability detection, it’s accuracy that counts. Being able to scan a large number of vulnerabilities is important, however it’s the ability to scan accurately, with low false positives, that counts. Acunetix’ unique AcuSensor Technology deploys sensors inside the source code, which relays feedback to the scanner during the source code’s execution thus not only reducing false positives, but also being able to pinpoint the exact line of vulnerable code.

3) Reporting and Remediating

Once the scans are performed, the scanner will populate the information in a set of Internal Management reports as well as a range of Compliance and Classification reports for regulatory standards and best practice guidelines. 

About Acunetix

Acunetix is the market leader in automated web application security testing, founded to combat the rise in attacks at the web application layer. Its products and technologies are the result of a decade of work by a highly experienced development team specializing in security. Acunetix Vulnerability Scanner is the tool of choice for many customers globally in the Government, Military, Educational, Telecommunications, Banking, Finance, and E-Commerce sectors, including many Fortune 500 companies. www.acunetix.com 

Acunetix Vulnerability Scanner is available both as an online and on premise solution. It is included in the UK Government’s latest G-Cloud procurement framework, G-Cloud 7. Acunetix offers their Online Vulnerability Scanner as Software-as-a-Service (SaaS), through the Digital Marketplace. https://www.digitalmarketplace.service.gov.uk/g-cloud/services/7192777907076465 

Comments

Stephen   05/04/2016 at 18:28

Excellent insight and very interesting!

Add your comment

public sector executive tv

more videos >

latest public sector news

Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower e... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. ... more >
Colleges set to receive £200m in Funding

19/08/2020Colleges set to receive £200m in Funding

Over 180 colleges are set to receive a share of £200m, in order to repair and refurbish buildings and campuses. The funding makes up p... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

Prevention: Investing for the future

Prevention: Investing for the future

Rob Whiteman, CEO at the Chartered Institute of Public Finance (CIPFA), discusses the benefits of long-term preventative investment. Rising demand, reducing resource – this has been th... more > more last word articles >

the raven's daily blog

Cleaner, greener, safer media: Increased ROI, decreased carbon

23/06/2020Cleaner, greener, safer media: Increased ROI, decreased carbon

Evolution is crucial in any business and Public Sector Executive is no different. Long before Covid-19 even became a thought in the back of our minds, the team at PSE were looking at innovative ways to deliver its content to our audience in a more dynamic and responsive manner. We’re conscious to take the time to both prot... more >
read more blog posts from 'the raven' >

comment

Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Being on the receiving end of some “thanks” can make communit... more >
How community-led initiatives can help save the housing shortage

19/06/2019How community-led initiatives can help save the housing shortage

Tom Chance, director at the National Community Land Trust Network, argues that community-led initiatives are a productive way of helping to solve... more >
Aberdeen's green transport fleet attracting international attention

19/06/2019Aberdeen's green transport fleet attracting international attention

Aberdeen City Council’s hydrogen spokesperson, councillor Philip Bell, highlights the Granite City’s determination to play a leading ... more >
A fifth of public sector workers have never received a thank you from the people they serve

13/06/2019A fifth of public sector workers have never received a thank you from the people they serve

A fifth of the country’s public sector workers say they have NEVER received a ‘thank you’ for doing their job as Public Service... more >

interviews

Artificial intelligence: the devil is in the data

17/12/2018Artificial intelligence: the devil is in the data

It’s no secret that the public sector and its service providers need to invest in technology to help make better use of their resources. Bu... more >
Digital innovation in the public sector: The future is now

17/12/2018Digital innovation in the public sector: The future is now

One of the public sector’s key technology partners has recently welcomed a new member to its team. Matt Spencer, O2’s head of public ... more >
New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

05/11/2018New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

The new chief executive of one of the new unitary authorities in Dorset has outlined his approach to culture and work with employees, arguing tha... more >
Keeping the momentum of the Northern Powerhouse

15/10/2018Keeping the momentum of the Northern Powerhouse

On 6 September, the biggest decision-makers of the north joined forces to celebrate and debate how to drive innovation and improvement through th... more >