Davis runs on research data - genomic sequences, animal-health studies, ag-biotech field results and the sponsored-research systems that hold controlled information - and that data, not a storefront, is what an attacker comes for. CyberFortify runs manual network, cloud, research-application and pipeline penetration tests here, aligned to NIST SP 800-171 and CMMC, NSPM-33 research-security expectations and NIST CSF. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where it genuinely helps. Fixed price, audit-ready reporting, free retest.
// 01 Why Davis research organisations need penetration testing
A research environment is built to share, and that instinct is exactly what makes it hard to secure. Data moves between a sequencer, a shared filesystem, an HPC cluster and a graduate student's notebook because collaboration is the point. The same openness means a single over-permissioned account or a mislabelled dataset can hand an outsider years of work that was never meant to leave the group.
Davis holds an unusually dense stack of that risk: high-performance computing serving hundreds of research groups, genomics and animal-health pipelines, ag-biotech field data, and grant-funded programmes that increasingly carry controlled unclassified information for federal and defense sponsors. When a lab wins a contract that brings CUI, its systems quietly cross from open science into a regulated boundary - and the segmentation meant to hold that line is often assumed rather than tested. The failure mode is not a defaced website; it is exfiltrated research or a leaked controlled dataset that ends a funding relationship.
A vulnerability scanner does not find that class of problem. It flags an unpatched package on a login node; it cannot tell you that the node lets a user pivot into the CUI enclave, that an NFS export is world-readable across groups, or that an SSH key issued to a departed postdoc still opens a door. Those are access and boundary decisions, and confirming them takes a tester who understands both the science infrastructure and the controlled-data rules wrapped around it.
// 02 Compliance and research-security drivers in Davis
Research organisations in Davis answer to a controlled-data safeguarding standard, an assessment regime layered on top where funding is defense-related, and a set of research-security and export-control duties their sponsors now enforce. These are the requirements we most often map evidence against.
NIST SP 800-171 - safeguarding CUI
Nonfederal systems that store, process or transmit controlled unclassified information must meet 800-171's safeguarding requirements. Independent testing is how the access-control and boundary-protection objectives are evidenced in a System Security Plan and POA&M.
CMMC assessment
Where research is defense-funded, the Cybersecurity Maturity Model Certification adds a formal, assessed layer over 800-171. Penetration-test evidence supports the practices an assessor expects to see demonstrated, not just documented.
NSPM-33 research-security programme
Federal sponsors expect research institutions to stand up cybersecurity and research-security functions. Independent testing of the environments holding sponsored data is a defensible way to show the programme is operating, not merely written down.
ITAR / EAR data handling
Export-controlled technical data brings access-boundary and nationality-of-access duties. We test whether the technical controls actually confine that data to the intended enclave and users, rather than trusting policy alone.
HIPAA for clinical & human-subjects data
Research touching identifiable health information falls under the HIPAA Security Rule. We test the systems and interfaces holding that data and prioritise findings by what they could expose.
// 03 Penetration testing services for Davis
Davis engagements weight the compute and data layer over the corporate perimeter, because that is where the research lives. Network and cluster testing leads for HPC and CUI environments; cloud follows, since research repositories and pipelines increasingly run there; application and pipeline work covers the notebooks and web tools researchers expose.
Network & HPC pen testing
Login and submission nodes, scheduler exposure, shared-storage and NFS permissions, service-account and SSH-key sprawl, and segmentation between open research and CUI enclaves.
Cloud pen testing
Identity, storage exposure and tenant isolation across the cloud holding research data repositories, genomics pipelines and grant-funded compute - IMDS, over-scoped roles and public buckets.
Research-app & API pen testing
Jupyter and notebook servers, research web apps, data-portal and submission APIs - authentication, IDOR/BOLA on dataset access, and unauthenticated compute or data endpoints.
Pipeline & code review
Genomics and analysis pipelines and grant-funded software - hardcoded credentials, unsafe deserialisation, dependency risk and data-provenance integrity through the workflow.
Web application pen testing
Lab and project portals, data-request and collaboration platforms, tested against the OWASP Top 10 and the business-logic abuse that leaks datasets.
Red teaming
Goal-based simulation aimed at a specific dataset or the CUI enclave, testing whether exfiltration and lateral movement are detected before the data is gone.
// 04 How we deliver to Davis
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Davis sits roughly ten to eleven hours behind us. We have no California office and no local staff. What we do have is a rhythm built around that gap - our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs with your research-computing and security teams. Testing continues while your labs are quiet, so results are waiting when your day starts.
What runs remotely
Cloud, research-application, API, external and authenticated cluster-edge testing from our secure environment - the large majority of HPC, repository and CUI scope. Findings land in a shared channel as confirmed, and anything touching controlled data is escalated immediately.
What we do on-site
Internal, air-gapped or physically segmented enclave testing where a tester genuinely needs to be on the wire, plus workshops with research-security committees. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live research infrastructure we agree test windows around scheduled compute and long-running jobs, and a free retest proves the fixes.
// 05 Research sectors we secure in Davis
Davis's risk profile is shaped by a concentration of university research, life-science labs and the spin-outs commercialising their work.
// 06 Our methodology
Davis engagements follow the same audit-defensible process we run everywhere, tuned to the compute-and-data core of this market. Testing is grounded in the PTES and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP, including the API Security Top 10. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one.
Scoping & rules of engagement
Clusters, enclave boundaries, CUI systems, test accounts, compute windows and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped around the data - who can reach which dataset, over which path, with which key, and where the open-to-controlled boundary sits.
ATT&CK alignedManual exploitation
Weaknesses are exploited and chained under controlled conditions, cross-boundary access proven with seeded test records - never live research or controlled data.
Controlled exploitReporting & free retest
Executive summary, CVSS-scored detail and mapping to NIST 800-171, CMMC, NIST CSF or HIPAA - written for an assessment file, plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Davis
A scan-and-report vendor
Automated output rebadged as a penetration test, blind to the enclave boundary, unable to reason about who an SSH key belongs to or whether controlled data has drifted into open storage.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual exploitation aimed at the compute, storage and CUI boundary at the centre of research risk, findings mapped to your assessors' frameworks, fixed pricing and a free retest.
Davis engagements most often pair a network and HPC assessment with a cloud penetration test, since a research environment's risk splits between the cluster and storage on one side and the identity configuration underneath the repository on the other. Where a specific dataset or the CUI enclave is the crown jewel, we add red teaming to test whether exfiltration is detected before it completes.
// 08 Frequently asked questions
Can you test our HPC cluster and login nodes without disrupting running research jobs?
Yes - it is most of the work we are asked for here. We focus on the exposed edge of the cluster: login and submission nodes, the scheduler, and the shared-storage layer. We test whether a low-privilege user can reach another group's data over NFS, whether SSH-key and service-account sprawl grants standing access nobody tracks, whether the scheduler can be abused to run work on nodes a user should not touch, and whether a login node can be used to pivot toward a controlled enclave. Compute-bound jobs stay untouched - we test the access model, not your running science, and agree windows around scheduled runs first.
How do you test the boundary between our open research network and our CUI enclave?
We treat the enclave boundary as the primary target. We test it from the open research side a real attacker would occupy: whether segmentation actually holds, whether a shared identity, a jump host, a mounted volume or a management interface bridges the two, and whether controlled data has leaked into open repositories, notebooks or backups outside the boundary. We map what we prove against the NIST SP 800-171 access-control and boundary-protection families so the result drops straight into your System Security Plan and POA&M.
Which regulations and research-security expectations drive penetration testing in Davis?
For controlled unclassified information in nonfederal systems, NIST SP 800-171 sets the safeguarding requirements and independent testing is how the assessment objectives are evidenced; where the funding is defense-related, CMMC layers a formal assessment on top. NSPM-33 pushes sponsored-research programmes to stand up research-security functions, and export-controlled data under ITAR and EAR adds handling and access-boundary duties. Human-subjects and clinical research data brings HIPAA into scope, and most programmes anchor the whole effort to NIST CSF.
With your team in the Gulf, how does the time gap work for a Davis engagement?
We are straight about it: CyberFortify is a Gulf-based firm on UTC+3, roughly ten to eleven hours ahead of Davis, with no California office and no local staff. We reserve a deliberate daily overlap window - our late afternoon and evening is your morning - for stand-ups, live triage and read-outs with your research-computing and security teams. Testing runs on through the night while your labs are quiet, so confirmed findings are usually waiting when you sign in.
How fast can we get a quote for a Davis research-security engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written for a research-security or 800-171 assessment file - hand it straight to an assessor - and a remediation retest is included once your fixes ship.