- Home
- /
- Success stories
- /
- Cybersecurity
- /
- Conserve Italy
Success story
Verified quality and safety
in Conserve Italia.
The Red Team Exercise service fully met the client’s needs. Together with specialists from deda tech , a realistic attack simulation was developed , defining targets, attack scenarios, and initial vectors.
Recognized as one of the leading agro-industrial companies operating in Europe, Conserve Italia is an all-Italian company and a member of Confcooperative (Confederation of Italian Cooperatives) that has established itself at the forefrontof the canning industry.
In over forty years, it has expanded internationally, with subsidiaries in France, Great Britain, Spain, and Germany, focusing its mission and business strategyon Italian agriculture to best promote the agricultural products of its cooperative members and provide consumers with guarantees of quality and food safety.
Tech refresh of the entire infrastructure for Hana.
Cloud @home service implementation for Backup + training and DR plan implementation.
Red Team activities with Penetration Test service + Adding storage in Cloud@home service.
Implementation of Disaster Recovery as a Service (DraaS) and Desktop as a service (DaaS) services.
SCENARIO
Conserve sparked a need in the company: to challenge itself, testing the cybersecurity strategyProposal and solution
Simulate an action by a threat actor intent on compromising the entire enterprise information system.
Getting this activity started required a meeting with deda tech specialists and Conserve’s IT department, a key moment to fully understand the client’s needs and expectations. It was chosen to simulate an action by a threat actor with little information about the target, where the attacker once identified the company and carried out the timely reconnaissance activity from open sources on the company’s assets (people, processes, exposed services), is intent on compromising as deeply as possible the entire corporate information system. Using one or more carriers, such as applications exposed on the Internet. Thus, the Red Team had definite goals to achieve:
- Compromising backup, antivirus, virtualization and Database systems;
- Compromising production systems;
- Gaining privileged access to systems;
- Exfiltrating business data;
- Circumvent active safety systems.
Having signed the indemnity and performed the kickoff, the Red Team notified the staff identified in the engagement phase to make the client aware of the time window in which they are acting. The activity tested the skills of deda tech’s Red Team, which was faced with a well-organized and managed network security infrastructure. The Red Team, through the discovery of a little-known misconfiguration was able to breach the outer perimeter and obtain persistence on the compromised system. Subsequent operations followed by conveying all traffic by means of a dns tunnel and once the necessary accesses were obtained, the Red Team had to make its way through a very large and complex network. The scenario found prompted the team to attempt to reconstruct how the system administrator had designed the infrastructure, and only through experience and strong subject matter expertise was it able to compromise additional parts of the infrastructure itself. Two were the winning elements:
- The relationship of trust, established over the years, between Conserve Italia and deda tech.
- deda tech Red Team’s expertise and certifications that recognize them in the market.
We’ve worked hard to establish an adequate defense posture, and it’s understandable to feel secure after all that work, but when it comes to cybersecurity, you can never be too secure—which is why we asked Deda Tech to conduct an aggressive penetration test that mimics a real attack. Their work has allowed us to better understand our hidden vulnerabilities and redefine a concrete strategy to improve our corporate security. I’m very pleased and satisfied with the work we’ve done together for Conserve Italia.

Achievements
Given the speed with which attack methods change and evolve, it is important to conduct Red Team activity at least once a year.Having a robust cybersecurity infrastructure is important in a historical context in which cyberattacks have become a daily occurrence.
At the same time, being aware of the characteristics of their infrastructure and the risks to which it is exposed allows companies to truly prepare for potential attacks; for this reason, activities such as penetration testing or red team exercises are essential for a growing company.
Thanks to these services, customers can simulate an emergency scenario to understand how their infrastructure might respond and how they should improve their security posture to prevent significant business disruption.
Once the activity was completed, Conserve Italia’s Blue Team met with deda tech’s Red Team to review the release report together.
Specifically, the report provides a detailed account of all the steps taken and commands executed during the activity, allowing the client to fully understand how deda tech’s Offensive Security specialists were able to gain access to their infrastructure.
This discussion was a pivotal and highly educational experience for both sides, as it allowed the client to identify its weaknesses, while enabling the supplier to analyze and propose the best services to ensure the security of future clients’ systems as well.
The effectiveness of the service is undoubtedly due in part to the mutual trust between deda tech and Conserve Italia, which fully embraced the recommendations provided by the Red Team (tools, programs, people); without them, it would not have implemented the improvements needed to enhance its corporate cybersecurity.
Conserve Italia has achieved its goals:
- Quantify the damage an intentional attacker is capable of bringing to the company;
- Test internal procedures for responding to a cyber attack;
- Test the capabilities of your Managed Detection and Response service;
- Know the improvements needed to increase corporate IT security.
Given how quickly attack methods change and evolve, it is important to conduct Red Team exercises at least once a year, varying the scenarios and initial attack vectors, so as to identify potential improvements in one’s systems each time.
For this reason, Conserve will continue to collaborate with deda tech to ensure it is always ready to meet new market demands and grow technologically as its business expands.
