8 | | SEPTEMBER - 2023IN MY OPINIONNetwork penetration testing is discussed in a variety of government and trade fora, but remains an under-developed aspect of most large enterprise cybersecurity programs. When companies speak of penetration testing, they often mean hiring a third party to perform a limited number of tests. A typical third party will charge a large enterprise $300-400K to perform six to eight scaled tests in a year. Large government and private sector enterprises have thousands of applications - hundreds of which are either critical or external-facing. Only a very tiny percentage of applications will be tested despite patches, upgrades, and enhancements being applied across the enterprise on a regular basis. Any of those changes could result in the introduction of new vulnerabilities and malicious exploits, which remain undetected.Dominion Energy's Corporate Intelligence and Security (CIS) organization, which converges its cyber and physical security functions with its threat intelligence collection and processing mechanisms, pursued an evolution of its penetration testing program, starting in 2019. The core of the program is the vendor-led penetration testing exercises. CIS uses vendor partnering to conduct tests on a limited number of regulatory-required or critical new systems. The third party generates a report and findings are evaluated and remediated. Over the years, we have used a number of different firms and, most recently, have been utilizing Accenture after they purchased the firm Revolutionary Security which had our contract at the time. Accenture brought to bear a deeper, more robust set of capabilities and talent which provided effective results for Dominion Energy. The sheer number of applications and systems which are tested is necessarily small relative to the size of the company and the amount of constant growth and innovation within its information network.Dominion Energy recognized the need for more frequent penetration testing and adopted the approach of adding in-house staff to the cyber security team. Since it is increasingly difficult to recruit and retain experienced penetration testers with the requisite level of technical knowledge, skills, and abilities into a large company, Dominion Energy took the approach of hiring very capable personnel, with a strong IT background, and training them in-house. While the team is small in size, because they are in-house and have the full-time job of penetration tester, they are able to review many more systems, ADVANCING CYBER-SECURITY TO A NEW LEVELBy Adam Lee, Vice President, CSO, Dominion EnergyAdam Lee
< Page 7 | Page 9 >