Carlsberg — Pentest for a world's leading brewer
**Client Overview:** Carlsberg Group is a major global brewery conglomerate, employing over 40,000 individuals and distributing its products in more than 150 countries. Carlsberg Ukraine operates breweries in Kyiv, Zaporizhzhia, and Lviv, offering a range of beverages, including beer and both alcoholic and non-alcoholic options under various brands such as Lvivske, Robert Doms, Carlsberg, Tuborg, Kronenbourg 1664, Arsenal, Kvas Taras, Somersby, Guinness, Seth&Riley's Garage, Warsteiner, Grimbergen, among others.
**Project Motivation:** The initiative was driven by the need for preventative measures and to align with the parent company's requirements as well as internal cybersecurity policies. Since the inception of its corporate IT systems decades ago, Carlsberg has consistently invested in safeguarding its IT infrastructure, including regular independent penetration testing.
**Solution Provided:** XRAY CyberSecurity has performed numerous penetration tests over a decade-long partnership, covering External Pentests, Internal Pentests, Wi-Fi Pentests, and Social Engineering assessments. These tests targeted various IT systems across multiple locations of the client, simulating different types of attackers, including Blackbox and Graybox scenarios.
**Methodologies Used:** Our penetration testing approach adheres to leading standards such as PTES, NIST SP 800-115, OSSTMM, and OWASP, enhanced by our own 15 years of experience.
**Tools Utilized:** During the penetration testing process, a comprehensive suite of standard pentesting tools was employed, but the key to success lay in manual analysis, which connected findings from individual vulnerabilities to escalate privileges and illustrate practical compromises of the IT infrastructure.
**Outcomes:** Following each penetration testing engagement, an Action Plan was created in collaboration with the Customer’s team, identifying priority tasks to enhance security based on the company's available human and financial resources. Subsequent re-tests validated the effectiveness and promptness of the vulnerability remediation efforts.