Recommendations to others considering ThreatSpike:
Be comfortable letting ThreatSpike do their thing and finding as many holes in your security landscape as they can. Then make sure you fix them with the help, advice and support of ThreatSpike should you need it. It's worth every penny of the cost to repeat the exercise at least once every year as one way or another the cost of a breach will almost definitely be significantly higher Review collected by and hosted on G2.com.
What problems is ThreatSpike solving and how is that benefiting you?
The purpose of this Red Team exercise was for ThreatSpike to perform a review of our ability to detect and withstand a targeted cyber attack. This included them identifying potential weaknesses and vulnerabilities in the security of our IT systems as well as testing employee resistance to social engineering attacks and malicious email threats. In order to simulate a real attack as closely as possible, it was important that ThreatSpike remain undetected by our colleagues or IT team during the exercise and they were very successful in this respect.
Clearly any attack but particularly any resulting in loss of data and or loss of use of our systems would be hugely detrimental to our reputation and our ability to provide continuity of service to our customers so the benefit to us of this exercise was to understand any weaknesses we may have in our IT landscape and address them as a priority. Review collected by and hosted on G2.com.