“When you have to scan hundreds of web applications and identify exploitable vulnerabilities on all of them, Netsparker is THE essential easy-to-use tool that provides professional reports with a clear explanation and steps to remedy them.” Mihai Petre, Security Analyst at Morneau Shepell.
Morneau Shepell, an international pension administration and benefits company, was founded in the eighties as SOBECO. The company merged with Morneau in 1995 to become Morneau Sobeco. Later in 2006 Morneau Sobeco acquired Shepell FGI to become Morneau Shepell. Today Morneau Shepell serves more than 8,000 clients, ranging from small businesses to some of the largest corporations and associations in North America.
Morneau Shepell’s websites and web applications are built with .Net framework and run on a number Microsoft IIS servers. Web applications are used by both employees and business partners to gain access to the personal accounts and information of their clients’ to make pension investments and payments.
Prior to Netsparker, the company used Nessus as their primary web application security scanner; but as Security Analyst Mihai Petre highlights: “Existing tools used for testing published websites and web applications such as Nessus are not reliable. With the ever growing number of published websites, sorting through the scan results and verifying the findings was both a frustrating and a time consuming process.”
“We started looking for a more efficient solution that could help us automate most of the tasks and Netsparker was the obvious choice, because it automatically verifies identified vulnerabilities. Therefore our team did not need to allocate time to verify the scanner’s findings,” he added.
Netsparker Web Application Security Scanner is now being used to carry out monthly scheduled web application security scans using credentials, and also daily ones when the need arises.
“We have been using Netsparker for over three years at Morneau Shepell, since version 2 was released. We are very happy with Netsparker and as long as they keep on updating it frequently, we will stick to it,” emphasized Petre.
If a web application were hacked and sensitive data leaked or stolen, the company could suffer severe financial and regulatory compliance problems.
When Morneau Shepell started using Netsparker three years ago, they realized that many of their websites needed improvements in mitigating SQL Injections, Cross-site Scripting (XSS) and other vulnerabilities.
Using Netsparker they identified and confirmed particular cases where sites were vulnerable and quickly deployed fixes. Now, the security team is confident that their web applications are secure.
“Now the scanning reports only include IIS configurations problems, detected as low alerts. Thanks to Netsparker we identified and closed all critical security vulnerabilities,” Petre concluded.
Established in 1966, Morneau Shepell serves more than 8,000 clients, ranging from small businesses to some of the largest corporations and associations in North America. With approximately 3,000 employees in offices across North America, Morneau Shepell provides services to organizations across Canada, in the United States and around the globe. Morneau Shepell is a public-traded company on the Toronto Stock Exchange (TSX: MSI).
Netsparker Web Application Security Scanner is an industry leading automated web vulnerability scanner developed by Netsparker Ltd. Netsparker management and engineers have more than a decade of experience in the web application security industry that is reflected in their product. Netsparker is a very easy to use web application security scanner that automates most of the web application security scanning. An out of the box installation of Netsparker is able to scan a wide variety of web applications, therefore web security experts, penetration testers and QA engineers do not need to spend countless amount of hours tweaking and configuring the software. Netsparker is revolutionising web application security by being the only web application security scanner to automatically verify detected web vulnerabilities, thus reporting no false positives. Netsparker is used by world renowned companies such as Samsung, NASA, Skype, ING and Ernst & Young.