Morneau Shepell Secures More Than 600 Websites Without an Army of Penetration Testers

Category: News - Mon, 07 Nov 2016 - by Robert Abela

When you have to scan hundreds of web applications and identify exploitable vulnerabilities on all of them, Netsparker is THE essential easy-to-use tool that provides professional reports with a clear explanation and steps to remedy them.Mihai Petre, Security Analyst at Morneau Shepell.

Morneau Shepell LogoMorneau Shepell, an international pension administration and benefits company, was founded in the eighties as SOBECO. The company merged with Morneau in 1995 to become Morneau Sobeco. Later in 2006 Morneau Sobeco acquired Shepell FGI to become Morneau Shepell. Today Morneau Shepell serves more than 8,000 clients, ranging from small businesses to some of the largest corporations and associations in North America.

The Need to Scan over 600 Web Applications every Month

Morneau Shepell’s websites and web applications are built with .Net framework and run on a number Microsoft IIS servers. Web applications are used by both employees and business partners to gain access to the personal accounts and information of their clients’ to make pension investments and payments.

Why did Morneau Shepell choose Netsparker Web Application Security Scanner?

Prior to Netsparker, the company used Nessus as their primary web application security scanner; but as Security Analyst Mihai Petre highlights: “Existing tools used for testing published websites and web applications such as Nessus are not reliable. With the ever growing number of published websites, sorting through the scan results and verifying the findings was both a frustrating and a time consuming process.”

“We started looking for a more efficient solution that could help us automate most of the tasks and Netsparker was the obvious choice, because it automatically verifies identified vulnerabilities. Therefore our team did not need to allocate time to verify the scanner’s findings,” he added.

Netsparker Web Application Security Scanner is now being used to carry out monthly scheduled web application security scans using credentials, and also daily ones when the need arises.

“We have been using Netsparker for over three years at Morneau Shepell, since version 2 was released. We are very happy with Netsparker and as long as they keep on updating it frequently, we will stick to it,” emphasized Petre.

Damage Limitation Ensures a Smooth Running Business

If a web application were hacked and sensitive data leaked or stolen, the company could suffer severe financial and regulatory compliance problems.

When Morneau Shepell started using Netsparker three years ago, they realized that many of their websites needed improvements in mitigating SQL Injections, Cross-site Scripting (XSS) and other vulnerabilities.

Using Netsparker they identified and confirmed particular cases where sites were vulnerable and quickly deployed fixes. Now, the security team is confident that their web applications are secure.

“Now the scanning reports only include IIS configurations problems, detected as low alerts. Thanks to Netsparker we identified and closed all critical security vulnerabilities,” Petre concluded.

About Moreau Shepell

Established in 1966, Morneau Shepell serves more than 8,000 clients, ranging from small businesses to some of the largest corporations and associations in North America. With approximately 3,000 employees in offices across North America, Morneau Shepell provides services to organizations across Canada, in the United States and around the globe. Morneau Shepell is a public-traded company on the Toronto Stock Exchange (TSX: MSI).


Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

DOWNLOAD DEMO TRY ONLINE SCAN