A university is the hardest kind of network to defend: it must stay open, its population turns over every year, and almost nobody using it works for central IT. CyberFortify runs manual network, web, API and cloud penetration tests across Pomona's education and research estate, aligned to FERPA, the GLBA Safeguards Rule, NIST CSF and, where federal research is involved, NIST SP 800-171. Delivered remotely from our Gulf base on a daily overlap window, scheduled around the academic calendar. Fixed price, audit-ready reporting, free retest.
// 01 Why Pomona institutions need penetration testing
Most organisations reduce risk by closing things down. A campus cannot. Pomona's polytechnic tradition means laboratories, workshops and student projects that exist precisely so people can connect equipment, run their own code and experiment - and an institution that locked that down would have stopped doing its job.
The result is an estate with no clean perimeter. Tens of thousands of students, faculty, researchers and contractors arrive and leave on an academic rhythm, bringing unmanaged laptops and phones onto networks that were built to welcome them. Individual colleges and departments run their own servers, applications and grant-funded infrastructure, often without telling anyone centrally. One federated login sits in front of hundreds of services, which is excellent for users and means a single stolen credential travels a very long way.
What an attacker wants from that environment varies more than people expect. Student records and financial-aid data have obvious value. So does research - particularly anything federally funded or commercially sensitive, where the theft is quiet and may never be noticed. And a ransomware operator simply wants the institution to stop functioning during enrolment or finals, when the pressure to pay is highest. A vulnerability scanner will not tell you that a student account can reach a department's grade system, or that an assertion from one service provider is accepted by another. Those are logic and trust questions, and confirming them takes a tester.
// 02 Compliance and regulatory drivers in Pomona
Higher education answers to an unusual mix: an education-records statute, a financial-services rule most institutions do not expect to apply to them, and research obligations that arrive attached to federal funding.
FERPA
The Family Educational Rights and Privacy Act governs education records and who may see them. Institutions must control and account for access, and independent testing is how many evidence that the controls actually hold.
GLBA Safeguards Rule
Handling student financial-aid data brings institutions within the Safeguards Rule's definition of a financial institution - requiring a written information-security programme and regular testing. It surprises many campuses.
NIST SP 800-171 & research security
Federally funded work involving controlled unclassified information carries 800-171 obligations, with the enclave holding that research needing demonstrable separation from the open campus.
NIST CSF & CIS Controls
Most institutions anchor their programme to NIST CSF or the CIS Controls, both of which expect independent validation rather than self-assessment alone.
CCPA / CPRA
Data outside the education-record boundary - alumni, donors, event attendees, commercial services - falls under California's consumer-privacy regime and its risk-assessment duties. Our privacy-regulation guidance compares them.
PCI DSS v4.0 & HIPAA
Tuition and event payments put a cardholder environment in scope under Req 11.4, and campus health and counselling services bring HIPAA obligations alongside FERPA.
// 03 Penetration testing services for Pomona
Campus engagements lead with identity and internal network, because federation and open connectivity are where a small foothold becomes a large one. Web and API testing follows for the student-facing systems, and cloud covers the research and departmental workloads that grew up outside central IT.
Network pen testing
Internal, wireless and Active Directory testing, plus segmentation checks between student, administrative, research and lab networks.
Web application pen testing
Student portals, financial-aid and enrolment systems, departmental applications and learning platforms, tested for authorisation and business-logic abuse.
API pen testing
The interfaces behind student information systems and integrations with third-party education platforms - object-level authorisation and scope enforcement.
Cloud pen testing
Identity, storage exposure and role scope across research computing and the departmental subscriptions nobody centrally inventoried.
Mobile app pen testing
Campus and student apps - local data storage, credential handling and the API traffic behind the screen.
Red teaming
Goal-based simulation, including phishing at population scale and ransomware scenarios timed against the academic calendar.
// 04 How we deliver to Pomona
Plainly stated: CyberFortify is a Gulf-based firm on UTC+3, and Pomona sits about ten to eleven hours behind us. There is no California campus office and no local staff. What there is instead is a fixed daily overlap window - our late afternoon and evening against your morning - held open for stand-ups, live triage and read-outs. Testing continues while the campus is quiet, which many institutions prefer, and results are ready when your team starts.
What runs remotely
External, web, API, cloud and mobile testing from our secure environment, plus internal testing over a controlled remote foothold. Findings land in a shared channel as they are confirmed, and anything touching student records or research data is escalated immediately.
What we do on-site
Wireless surveys, lab and workshop network testing, and physical segmentation work where a tester genuinely needs to be on the wire - plus in-person briefings for governance committees. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. We schedule around enrolment, examinations and research deadlines, and a free retest proves the fixes landed.
// 05 Industries we secure in Pomona
Education and research lead here, with a supporting economy of events, civic services and distribution around them.
// 06 Our methodology
Pomona engagements follow the same audit-defensible process we run everywhere, weighted towards identity and lateral movement because that is how campus compromises actually unfold. Testing is grounded in the PTES and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one.
Scoping & rules of engagement
Targets, in-scope departments, research boundaries, test accounts, calendar constraints and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped around identity and trust - who authenticates where, which service providers accept which assertions, and what an ordinary campus device can reach.
ATT&CK alignedManual exploitation
Weaknesses are exploited and chained under controlled conditions, with cross-account access proven using seeded test records - never live student, health or research data.
Controlled exploitReporting & free retest
Executive summary, CVSS-scored detail and mapping to FERPA, GLBA Safeguards, 800-171 or NIST CSF - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Pomona
A scan-and-report vendor
Automated output rebadged as a penetration test, which flags a missing patch on a lab machine but cannot reason about whether a federated assertion is trusted where it should not be.
CyberFortify
A Gulf-based, CREST-pathway team that is candid about the time difference and structured around it. Manual exploitation aimed at federation, lateral movement and the boundaries protecting records and research, findings mapped to the frameworks your auditors and funders use, fixed pricing and a free retest.
Pomona engagements most often pair an internal network assessment with web application testing of the student-facing estate, since the campus risk story usually runs from a phished credential to a system that trusted it too readily. Where an institution wants to know whether it would keep operating, we add red teaming against a ransomware scenario.
// 08 Frequently asked questions
How do you test single sign-on and federated identity on a Pomona campus?
Federation is where a campus concentrates its risk, so we test it as its own target. We examine how SAML and OIDC assertions are produced and consumed, whether assertion signatures and audiences are properly validated, whether a service provider will accept an assertion minted for somewhere else, and how session lifetime and re-authentication behave across the many applications behind one login. We also test the account-recovery and help-desk reset path, because at university scale that is frequently the easiest way in.
Can you test a campus network that is open by design without breaking it?
Yes, and the openness is the point rather than a problem to be argued away. A university network carries unmanaged student devices, guest and eduroam traffic, departmental servers nobody centrally owns, and lab equipment that cannot be patched. We map what an ordinary device on that network can actually reach, then test the boundaries that are supposed to hold - between student wireless and administrative systems, between one department and another, and around the systems holding records. Testing runs in agreed windows with clear abort conditions so teaching and research are not disrupted.
Which regulations drive penetration testing for Pomona colleges and universities?
FERPA governs student education records and expects institutions to control access to them, and independent testing is how many institutions evidence that control. Less widely known, the GLBA Safeguards Rule reaches institutions through student financial-aid data and calls for a written security programme with regular testing. Federally funded research involving controlled unclassified information brings NIST SP 800-171 into scope. Most programmes are anchored to NIST CSF or the CIS Controls, and CCPA/CPRA applies to data outside the education-record boundary.
You are not based in California - how does the time difference actually work?
We should be direct about it: CyberFortify is a Gulf-based firm operating on UTC+3, roughly ten to eleven hours ahead of Pomona, and we have no California campus presence or local staff. We hold a fixed overlap window every day - our late afternoon and evening against your morning - for stand-ups, live triage and read-outs. Testing carries on while your campus sleeps, which suits institutions that would rather see activity outside teaching hours, and findings are waiting when your team logs in.
How fast can we get a quote for a Pomona engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. We can schedule around semester boundaries, enrolment periods and research deadlines. The report is written to hand straight to an auditor or a governing board, and a remediation retest is included once your fixes ship.