Computer Security: Hot Review Summer, Cool Deployment Autumn
This summer has seen a plethora of different assessments of the Organization’s security posture and stance. While an external vulnerability scan of CERN’s Internet presence and a red-teaming penetration test are still ongoing, the Computer Security Office, in collaboration with the IT Department, is continuing to mitigate the findings of the 2023 cybersecurity audit, the […]
This summer has seen a multitude of assessments of the Organization's security posture. While an external vulnerability scan and a red-teaming penetration test are ongoing, the Computer Security Office is working to address findings from the 2023 cybersecurity audit, the 2025 review of CERN's active directory, and a password cracking exercise.
The scan evaluates 8689 public websites and 2713 interactive servers for weaknesses, vulnerabilities, and misconfigurations. The WhiteHat Challenge, an annual exercise, involves cybersecurity and computer science students from partnering institutes to identify problems in CERN's web infrastructure. The red-teaming exercise, which began with seven objectives in 2020, is aimed at infiltrating CERN to demonstrate potential damage.
Lessons from this exercise have led to additional security measures, including enhanced password policies and the deployment of two-factor authentication. The IT Department and Computer Security Office are preparing to implement more security measures once all accelerators are stopped.
Written by urgent.news from CERN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.