Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - How to Keep Your Website Safe in 2015
News & Analysis

How to Keep Your Website Safe in 2015

ISBuzz TeamBy ISBuzz TeamDecember 22, 2014Updated:July 5, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
penetration testing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With web vulnerabilities putting millions of websites at risk every day, organisations typically turn to automated scanners to protect their websites. Despite automated scanners being the preferred approach for protection, they don’t do enough. There’s still a common misconception that fully-automated website vulnerability scanning bring the same results as manual web application penetration testing.

There is a vital need for a deep level of IT and security expertise that only comes from human skills, as demonstrated by a recent analysis conducted by the universities of KU Leuven (Belgium) and Stony Brook (New York). The analysis tested websites “protected” with various trust seals provided by reputable security vendors, including Symantec, McAfee, Trust-Guard, and Qualys, delivering automated vulnerability and malware scanning services.

Free eBook: Modern Retail Security Risk – Get your copy now.

The research showed that “seal providers perform very poorly when it comes to the detection of vulnerabilities on the websites that they certify.” This weakness is inherent in almost all fully automated solutions, which can only go so far before their output needs to be analysed by a qualified pentester.

Vulnerability scanning can be a cheaper option than penetration testing, but the latter brings significant added-value as, with the former, you can simply download any of a number of vulnerability scanners and run them against a website yourself. These will generate an automatic report providing numerous actual and potential vulnerabilities and weaknesses – and probably a number of false-positives, which are time-consuming as you need to verify every single issue the scanner detects or, even worse, false-negatives.

Some automated solutions may assign a medium risk to 403 or 500 error pages returned by the web server that are not vulnerabilities but just error pages. Website administrators then start ignoring all medium-risk vulnerabilities from daily scanning reports and miss important information about real vulnerabilities.

Security scanners are probably a must-have tool for large companies that perform some of security testing internally and automated vulnerability scanning can be also very useful to keep internal teams up to date, but neither is not capable of replacing a penetration test.

True pentesting starts from where a vulnerability scan finishes as a pentester takes the reports from probably several different scans and uses his personal skills and experience to weed out false positives, identify missed vulnerabilities, recognise weaknesses in the business logic, which scanners cannot efficiently detect, and see how otherwise minor technical flaws can be chained together to effect a major breach.

Sometimes vulnerabilities exist and remain unpatched for a “good reason” but scanners will generate generic information about a patching technique. A qualified pentester, however, is capable of understanding the business needs and processes, so they can suggest a solution that will not affect business continuity.

As a solution to the gap between automated and manual security testing, High-Tech Bridge launched ImmuniWeb® – a hybrid approach to web security testing, which combines manual and automated web security testing to accurately detect the most complex security flaws missed by scanners and other automated solutions.

To read the full blog post, please visit

By Ilia Kolochenko, CEO, High-Tech Bridge

Ilia KolochenkoBio: Ilia Kolochenko has a university degree with honors in Mathematics and Computer Science from Geneva, his city of origin. Ilia Kolochenko started his career as a penetration tester, he also was a security expert and team leader working for various financial institutions and large companies in Switzerland and abroad. His military service in artillery troops took place in Frauenfeld, Switzerland. At the end of 2007 he founded High-Tech Bridge, aiming to deliver efficient and effective penetration testing to companies of all sizes. In 2010 Ilia Kolochenko created a concept of hybrid security assessment of web applications, called ImmuniWeb, that was globally launched in 2014. Being web application security expert and chief architect of ImmuniWeb, he is personally involved into ImmuniWeb’s daily operations, implementing new features and functions. Ilia Kolochenko is regularly quoted in various IT security and business journals, he was interviewed by CNBC, Financial Times, BBC and many other reputable medias.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}