Contributor:
Jeremy Tillery, Manager, Cybersecurity Services
A large organization (the Organization) providing healthcare services to millions of users expanded through the integration of multiple businesses, increasing the size and complexity of its technology environment. To better understand the security of its evolving infrastructure, the Organization engaged Cherry Bekaert to perform a comprehensive penetration test of its internal and external environments.
Testing Security Beyond Routine Compliance Activities
The assessment ultimately revealed an important lesson: while the organization had implemented many security controls aligned with recognized cybersecurity frameworks, compliance activities alone had not identified several exploitable attack paths that presented a clear risk of significant security compromise.
As organizations grow, so does the complexity of their networks, identities and technology environments. Following its expansion, the Organization wanted an independent assessment of its security posture to identify vulnerabilities and validate the effectiveness of its existing controls.
The organization already maintained many of the security practices expected of a modern cybersecurity program, including routine vulnerability scanning, patch management, endpoint protection and alignment with established cybersecurity frameworks. However, these activities primarily validated known vulnerabilities and compliance requirements.
What they could not demonstrate was whether an attacker could combine multiple configuration weaknesses to gain unauthorized access to critical systems.
Simulating Real-world Attack Scenarios
Cherry Bekaert conducted a comprehensive assessment that included:
- External network penetration testing
- Internal network penetration testing
- Web application testing
- Open-source intelligence (OSINT) analysis
Rather than relying solely on automated vulnerability scanning, our penetration testers manually evaluated how an attacker could move through the environment by exploiting identity controls, system configurations and trust relationships that automated tools typically do not assess.
The engagement also provided an opportunity to evaluate how effectively the organization’s existing monitoring capabilities detected real-world attack activity throughout the assessment.
Compliance Didn’t Tell the Whole Story
The engagement produced two equally important findings.
First, the organization’s external environment demonstrated a strong security posture. Cherry Bekaert validated that there were no exploitable vulnerabilities across its internet-facing infrastructure.
The internal assessment, however, told a different story. While the vulnerability assessment identified numerous findings requiring remediation, those findings were not what ultimately enabled the simulated compromise. Instead, Cherry Bekaert identified and chained together several identity and configuration weaknesses that allowed our team to demonstrate complete administrative control of the organization’s Active Directory environment.
Those attack paths had not been identified through the organization’s routine vulnerability scanning because they were not traditional software vulnerabilities. Rather, they resulted from configuration and identity weaknesses that required manual testing and an attacker mindset to uncover.
The engagement reinforced a critical distinction: Compliance helps organizations establish security controls. Penetration testing validates whether those controls effectively protect against real-world attack techniques.
The assessment demonstrated that an organization can implement many recommended security practices, satisfy framework requirements and still possess exploitable attack paths that are invisible to automated scanning alone.
Strengthening Security Beyond Compliance
Cherry Bekaert’s assessment gave the Organization a clearer view of both its strengths and its hidden risks. While independent testing validated that the external environment did not contain exploitable vulnerabilities, the internal assessment revealed identity and configuration weaknesses that routine vulnerability scanning had not detected.
By manually testing how an attacker could move through the environment, Cherry Bekaert demonstrated how multiple lower-level weaknesses could be combined into a significant business risk, including a path to complete administrative control of the Organization’s Active Directory environment. By the conclusion of this engagement, we:
- Validated External Security: Independent testing confirmed there were no exploitable vulnerabilities within the organization’s external attack surface.
- Identified Hidden Attack Paths: Manual penetration testing uncovered identity and configuration weaknesses that routine vulnerability scanning had not detected.
- Strengthened Remediation Efforts: The organization received a prioritized roadmap focused on addressing the attack paths that presented the greatest risk rather than simply remediating vulnerability counts.
- Enhanced Security Monitoring: The engagement provided valuable insight into which attack techniques existing monitoring tools detected and where additional visibility could improve future threat detection.
- Reinforced the Difference Between Compliance and Security: Perhaps the most significant outcome was demonstrating that compliance activities and vulnerability management provide an important security foundation, but they do not always reveal the configuration and identity risks that attackers exploit in real-world environments.
Compliance Is the Starting Point, Not the Finish Line
Compliance remains an essential component of every cybersecurity program. However, compliance alone cannot determine whether an organization is truly resilient against modern attack techniques or secure.
By combining experienced penetration testers with manual analysis, executive reporting and practical remediation guidance, Cherry Bekaert helped this healthcare organization identify hidden risks, strengthen its security posture and gain greater confidence in its ability to defend against real-world threats.
Your Guide Forward
Compliance confirms your controls exist, but only real-world testing proves they hold up against a determined attacker. Discover how Cherry Bekaert’s Penetration Testing Services can uncover the hidden attack paths routine scanning misses and help you strengthen your security posture before an attacker finds the gaps first.