Manufacturing · Industrial

Penetration testing for Zeppelin, a global CAT dealer

A long-term engagement of recurring Blackbox, Greybox and Whitebox testing across Zeppelin's external, internal and wireless infrastructure.

Industry
Construction · Mining
Branches
220 worldwide
Employees
10,000+
Approach
Long-term · Recurring

Zeppelin creates powerful solutions in construction and mining machinery (e.g. CAT/Caterpillar dealer), agricultural machinery, rental, construction logistics and site management, drive and energy, engineering, and plant construction. They also develop new digital business models for the construction industry.

Zeppelin Group operates 220 branches worldwide with over 10,000 employees and net sales of 3.9 billion EUR in fiscal 2023.

The need for external expertise on an ongoing basis to ensure uninterrupted operation of the corporate network infrastructure and a high level of protection against cyber threats.

A long-term engagement was launched with periodic assessments of different cyber threat types. Blackbox, Greybox, and Whitebox penetration testing was regularly performed against the external network, internal network, and wireless infrastructure.

ExternalInternalWirelessBlackbox · Greybox · Whitebox

Our pentesting methodology is based on leading standards — NIST SP 800-115, PTES, OSSTMM, OWASP — and improved by our own 15 years of experience.

NIST SP 800-115PTESOSSTMMOWASP

During pentesting, a full set of common pentester tools was used — but the main key to success was manual analysis: interconnecting individual vulnerability exploitation results to escalate privileges and demonstrate practical IT-infrastructure compromise.

Comprehensive and continuous penetration testing of Zeppelin provided an in-depth assessment, identifying vulnerabilities and practical attack vectors and demonstrating potential damage.

Results at each stage were instantly transmitted to engineers maintaining the network infrastructure for priority remediation. Subsequent re-testing was continuously conducted, providing a high level of protection against cyber threats.

Move forward with confidence

Have a similar
challenge in mind?

We'll scope a senior-led penetration test against your specific environment — and deliver Technical, Executive and Action-plan reports that translate findings into business decisions.

  • Reply within one business day
  • NDA on request — no obligation
  • Speak directly with our Head of OffSec
  • Tailored scope & clear pricing

Tell us about your project

We'll get back within one business day.