Location · Penetration Testing in San Bernardino, California

Penetration testing in San Bernardino for the public services that cannot go dark.

CyberFortify delivers manual, exploit-driven penetration testing to San Bernardino's county and city government, K-12 school districts, community colleges and community-serving healthcare - the systems that run payroll, benefits, student records, permitting and public safety for the largest county in the contiguous US. We test whether a ransomware intrusion would spread, whether your backups would survive it, and whether you could keep operating - mapping every finding to FERPA, the CIS Controls, NIST CSF and CCPA/CPRA.

Aligned with: FERPA · CIS Controls · NIST CSF · CCPA/CPRA · HIPAA · PCI DSS 4.0 · OWASP · PTES · NIST 800-115
FERPA
Student-record safe testing
CIS
Findings mapped to controls
100%
Manual testing
Free retest
Serving San Bernardino: County & city government · K-12 school districts · community colleges · public safety & dispatch-adjacent systems · courts & records · public health & behavioral health · transit & public works · permitting & utility billing · Inland Empire logistics Serving San Bernardino: County & city government · K-12 school districts · community colleges · public safety & dispatch-adjacent systems · courts & records · public health & behavioral health · transit & public works · permitting & utility billing · Inland Empire logistics
// Executive summary

San Bernardino runs the public services of the largest county by area in the contiguous US - and public bodies and school districts are among the most repeatedly-hit ransomware targets in the country. CyberFortify runs manual network and Active Directory, assumed-breach, cloud and web penetration tests here, built around one question - could an intrusion stop you operating, and could you recover. Findings map to NIST CSF, the CIS Controls, FERPA and CCPA/CPRA. Delivered remotely from our Gulf base on a daily overlap window, on-site where it helps. Fixed price, audit-ready reporting, free retest.

// 01 Why San Bernardino organisations need penetration testing

Ransomware crews have learned that public bodies and school districts pay - or, worse for residents, cannot afford the downtime. A county seat administering courts, public safety, benefits and permitting, and school districts holding records for tens of thousands of students, run services whose interruption harms the public directly. Payroll that does not run, a student information system that will not open on the first day of term, a benefits queue that stalls - these are not inconveniences, they are the failure the attacker is counting on.

The conditions are structural: legacy systems that cannot be patched on a vendor's timeline, tight budgets stretching lean IT teams too thin, and enormous user populations - staff, teachers, students and families - each one a credential an attacker can phish or fatigue into an MFA prompt. Once inside, the path runs through Active Directory: harvest a session, escalate, move laterally, find the domain controllers, and reach the backups before anyone notices.

A vulnerability scan will not tell you whether that path is open. It flags a missing patch; it cannot tell you that a single phished teacher account pivots from district wireless into the finance VLAN, or that your backups sit on a share that same account can encrypt. Those are questions about how your environment connects under attack - answering them takes a tester who walks the path, not a tool that lists ports.

// 02 Compliance and regulatory drivers in San Bernardino

Public bodies and schools answer to student-privacy law, resident-privacy statute, and a public-sector control programme that grant assessors and auditors expect to see evidenced. These are the requirements we most often map findings against.

R.01 · Education

FERPA - student education records

Districts and community colleges must protect education records against unauthorised access. FERPA treats an exposed record as a reportable event, so we prove which records an attack path would reach - never by touching a real student's file.

R.02 · Programme backbone

CIS Controls & NIST CSF

Local government and education programmes here run on the CIS Controls and NIST CSF. We map each finding to CIS Implementation Groups so a lean IT team can prioritise by control, not just by CVSS.

R.03 · Resident privacy

CCPA / CPRA & CPPA duties

Resident and family data brings CCPA/CPRA rights plus the CPPA's cybersecurity-audit and risk-assessment expectations across portals, payments and the identity systems behind them. Our privacy-regulation guidance compares the regimes.

R.04 · Health

HIPAA - county public & behavioral health

Where county public-health and behavioral-health services hold patient information, the HIPAA Security Rule requires risk analysis and periodic technical evaluation. Independent testing is how that evaluation is evidenced.

R.05 · Payments

PCI DSS v4.0 - Req 11.4

Permitting, utility-billing, court and tax payment portals must penetration-test the cardholder environment and prove segmentation under Requirement 11.4.5.

R.06 · Vendor assurance

SOC 2 for edtech & GovTech suppliers

SaaS platforms selling student, benefits or permitting systems into county and district buyers face security review before contract. SOC 2 reports rest on independent penetration testing.

// 03 Penetration testing services for San Bernardino

Engagements here weight the internal path over the perimeter, because ransomware resilience is decided inside the network - in identity, segmentation and recovery. Network and Active Directory testing leads; assumed-breach red teaming answers the "can we keep operating" question; cloud, web and mobile cover the front doors residents and students touch.

A.02

Network & AD pen testing

External, internal and Active Directory testing - Kerberoasting, ADCS abuse, privilege escalation and segmentation checks between district, finance and public-service networks.

A.07

Assumed-breach red teaming

Goal-based ransomware simulation from a single foothold - lateral movement, path to domain controllers and backups, and whether detection fires before operations halt.

A.04

Cloud pen testing

Identity, tenant isolation, storage exposure and service-account scope across the platforms hosting student, benefits and records systems.

A.01

Web application pen testing

Resident, parent and staff portals, permitting and payment applications, tested against the OWASP Top 10, IDOR and business-logic abuse.

A.05

API pen testing

Student-information, SIS integration and benefits APIs - broken object-level authorisation, token handling and scope enforcement across large user bases.

A.03

Mobile app pen testing

Parent, student and field-staff apps - local data storage, certificate handling and the API traffic behind the screen.

// 04 How we deliver to San Bernardino

We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and San Bernardino sits ten to eleven hours behind us, with no California office or local staff. What we have is a pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs with your IT team and cabinet. Testing continues while San Bernardino is offline, so confirmed results wait when the working day starts.

What runs remotely

External, cloud, web, API and mobile testing, plus internal assumed-breach work over a secured connection - the large majority of government, district and college scope. Confirmed findings land in a shared channel, and critical issues are escalated immediately.

What we do on-site

Internal network, wireless and physical segmentation testing where a tester genuinely needs to be on the wire, plus in-person tabletop exercises for cabinet, boards and IT. We travel when it adds value and say so when it does not.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. We schedule testing around instructional days, enrolment windows and payroll runs so live public services are not disrupted, and a free retest proves the fixes.

// 05 Sectors we secure in San Bernardino

San Bernardino's risk profile is shaped by a dense concentration of public bodies, large education systems and community-serving healthcare, with Inland Empire logistics at its edges.

County & city governmentBenefits · permitting · courts · records · public works
K-12 school districtsStudent information systems · payroll · parent portals
Community collegesEnrolment · financial aid · research & campus networks
Public safety & transitDispatch-adjacent systems · scheduling · fleet & ops
Public & behavioral healthPatient records · case management · clinics
Logistics & suppliersWarehousing · GovTech & edtech vendors

// 06 Our methodology

San Bernardino engagements follow the same audit-defensible process we run everywhere, tuned to the resilience question at the centre of public-sector risk. Testing is grounded in the PTES and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one.

01

Scoping & rules of engagement

Targets, network boundaries, in-scope districts, test accounts, calendar constraints and escalation paths agreed in writing first.

Fixed quote in 1h
02

Assumed-breach & threat modelling

We start from a single compromised credential and map the identity attack surface - who can reach what, which trust unlocks the domain, and where the backups sit.

ATT&CK aligned
03

Lateral movement & recovery validation

Privilege escalation, lateral movement and segmentation proven under controlled conditions - then whether backups are reachable, isolated and restorable. Access shown with seeded test records, never live student or patient data.

Controlled exploit
04

Reporting & free retest

Executive summary, CVSS-scored detail and mapping to FERPA, CIS Controls, NIST CSF, CCPA/CPRA or HIPAA - plus a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for San Bernardino

A scan-and-report vendor

Automated output rebadged as a penetration test, blind to identity attack paths, unable to tell you whether a phished account reaches your domain controllers or whether your backups would survive the intrusion.

CyberFortify

A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual assumed-breach exploitation aimed at the resilience question - can this district or county keep operating - findings mapped to your assessors' frameworks, fixed pricing and a free retest.

San Bernardino engagements most often pair an internal network and Active Directory assessment with assumed-breach red teaming, since the ransomware question splits between the identity paths an attacker walks and the detection and recovery that decide whether you keep running. We add a cloud penetration test where student, benefits or records systems have moved off-premises.

// 08 Frequently asked questions

Can you test whether a ransomware intrusion would stop our district or county operating?

Yes - that is the question we build the engagement around. We start from an assumed breach, as if one staff or student credential is already in an attacker's hands, and measure how far it reaches: which shares, systems and privileges it unlocks, whether it can move laterally into the domain controllers, and whether it lands on the backups. We then test the recovery side that most reports ignore - whether your backups are reachable from a compromised network, whether they restore cleanly, and how long payroll, student records and public services would actually be down.

How do you handle FERPA and student data during a test on a school district network?

We never exfiltrate or read live student education records. Access to the student information system is proven with seeded test accounts and screenshots of authorisation reaching data it should not, not by pulling real records. FERPA treats unauthorised access to education records as a reportable event, so our reporting is written to show exactly which records a given attack path would have exposed, mapped to FERPA and your district's obligations, so your team can evidence the risk without us ever touching a real student's file.

Which frameworks do you map findings to for San Bernardino public bodies and schools?

The programme backbone for local government and education here is usually NIST CSF and the CIS Controls, and we map every finding to CIS Implementation Groups so a lean IT team can prioritise. FERPA governs student education records for districts and colleges, CCPA/CPRA covers resident and family data, HIPAA applies where county public-health and behavioral-health systems hold patient information, and PCI DSS 4.0 Requirement 11.4 covers permitting, utility and court payment portals. We name the control each finding fails, not just a severity score.

You are not based in California - how does the time difference actually work?

We will be plain about it: CyberFortify is a Gulf-based firm on UTC+3, ten to eleven hours ahead of San Bernardino, with no California office or local staff. We hold a deliberate daily overlap window - our late afternoon and evening is your morning - for stand-ups, live triage and read-outs with your IT and cabinet. Testing continues overnight while your team is offline, so confirmed findings are usually waiting when the working day begins.

How fast can we get a quote, and can you work around the school or fiscal calendar?

Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. We schedule testing around instructional days, enrolment periods and payroll runs so live services are not disrupted, and a remediation retest is included once your fixes ship. The report is written to hand straight to an auditor, board or grant assessor.

Ready for a pen test in San Bernardino?

Book a free 30-minute scoping call. Our team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →