Plan your dream trip with Cresta AI Agent at CCW Las Vegas – Learn more

  • Products
    Back
    PLATFORM
    AI Platform
    Cresta is the enterprise-grade Gen AI platform built for the contact center and trained on your data.
    • Cresta Opera
    • Integrations
    • Responsible AI
    PRODUCTS
    AI Agent
    Cut costs, not quality, with human-centric AI agents you can trust
    Agent Assist
    Harness real-time generative AI to empower agents with unmatched precision and impactful guidance.
    • Knowledge Assist
    • Auto-Summarization
    Conversation
    Intelligence
    Discover and reinforce the true drivers of contact center performance.
    • Cresta Insights
    • Cresta Coach
    • Cresta Quality Management
    • Cresta AI Analyst
  • Solutions
    Back
    USE CASES
    Sales
    Discover and reinforce behaviors that accelerate revenue growth
    Customer Care
    Deliver brand-defining CX at a lower cost per contact
    Retention
    Transform churn risks into
 lifelong promoters
    Collections
    Accelerate collections while minimizing compliance risk
    INDUSTRIES
    Airlines
    Automotive
    Finance
    Insurance
    Retail
    Telecommunications
    Travel & Hospitality

    Why Transcription Performance Is Holding Back Your AI Strategy

    LEARN MORE
  • Customers
    Back
    Customer Stories
    Learn how Cresta is delivering lasting value for our customers.
    • CarMax
    • Oportun
    • Brinks Home
    • Snap Finance
    • Vivint
    • Cox Communications
    • Holiday Inn
    • A Top Telecom
    • View all case studies

    Our Own Zero to One: Lessons Learned in Building The Brinks Home AI Agent

    LEARN MORE
  • Resources
    Back
    Resources Library
    • Webinars
    • Ebooks
    • Reports
    • Solution Briefs
    • Data Sheets
    • Videos
    • Infographics
    • Media Coverage
    • Press Releases
    Blog
    Industry News
    Help Center
    Solution Bundles

    AI Maturity Blueprint: A Practical Guide to Scaling AI Adoption in the Contact Center

    LEARN MORE
  • Company
    Back
    About Cresta
    Careers
    Trust
    Customers
    Partners

    We’re Going Global! Cresta Expands to APAC and EMEA

    READ THE POST
Request a demo
Request a demo
  • Cresta Blog
  • Best Practices

Security as a competitive advantage: evolving with the threat environment

Does your contact center have an AI assistant? Does the provider of your call center AI assistant perform independent third-party audits for more than five different security compliance frameworks? Do they patch vulnerabilities like the HTTP/2 Rapid Reset attack within four hours of patch release? Do they go beyond the standard penetration test and battle test their security and detection capabilities by sophisticated and determined attackers, such as a red team?

If not, your organization’s security may be vulnerable—that’s a bigger (and more costly) problem than ever before.

Third-party risk management: Quantifying the importance

With Verizon referencing 953,894 incidents and 254,968 data breaches in their new annual Data Breach Investigations Report (DBIR) and IBM reporting a new all-time high of $4.45M for the average cost of a data breach—increasing 5% year-over-year since 2020—it’s clear that security is growing increasingly vital in third-party risk management.

Verizon additionally reports the mean time to patch critical vulnerabilities is 49 days and that number has barely changed over the past years. For reference, Cresta aims to fix critical vulnerabilities much faster, like the HTTP/2 Rapid Reset attack, which we patched in less than 4 hours following patch release. This is to say, a seven-week wait time to patch critical vulnerabilities may be standard, but it’s not unavoidable; there are key steps that can be taken to drive security and compliance above and beyond the standard measures.

Taking security to the next level

In the current environment where costly data breaches proliferate and critical vulnerabilities take a month or more to address, security and compliance efforts beyond third-party audits, penetration tests, code/design reviews, vulnerability scans, phishing tests, security awareness training, patch management, and the like are required to adequately protect customer data. Most companies still rely exclusively on tightly scoped and time-boxed penetration tests to evaluate the security posture of their products.

Unfortunately nothing is “out of scope” for sophisticated attackers, and determined threat actors do not set a time-boxed attack window for themselves. Penetration testing is like boxing where red teaming—engaging a team of determined attackers to simulate malicious actors and test security—is like mixed martial arts.

With this in mind, Cresta engaged Calif.io for an objective-based assessment (a red team engagement) to battle test our defenses against realistic determined attackers.

Cresta’s commitment to security in action

Cresta’s red team engagement with Calif.io ran over six weeks and nothing was off limits, including a real-world simulation by experienced, competitive, award-winning attackers (Pwn2Own & Pwnie Award winners).

Calif left no stone unturned and numerous attacks surfaced over multiple weeks. After three weeks of unsuccessful attempts, an initial foothold was gained by determining a password used in the staging environment. Our security team was able to detect Calif’s access to our infrastructure in less than 24 hours.

According to IBM’s Security® Cost of a Data Breach Report 2022 it takes 207 days to identify a compromise on average. We were pleased to see our detection capabilities vastly outperforming the industry standard—but that was just the beginning.

Immediately after receiving the report, we mitigated the kill chain and started implementing additional hardening measures. We removed the initial access vector and added additional controls to prevent and detect similar attempts.

The red team engagement provided us invaluable insights to further harden our environments against determined threat actors. The exercise allowed us to not only test and improve our security posture as a company but also our detection capabilities.

Cresta believes in security as a competitive advantage; in an increasingly dangerous threat environment, we aim to continue pushing the standards to innovate and protect our customers. As you engage in any vendor selection process, be sure to ask about their security measures and choose a provider who demonstrates a clear commitment to security.

Author:

Robert Kugler

Author:

Brooks Beverstock

November 21, 2023

Cresta Achieves TISAX Compliance

READ MORE

Cresta’s Commitment to Security with GitHub

READ MORE

How custom summarization saves hours of after-call work

READ MORE

100 South Murphy Ave Ste 300
Sunnyvale, California 94086

Karl-Liebknecht-Str. 29A
10178 Berlin, Germany

100 King Street West
1 First Canadian Place, Suite 6200
Toronto ON M5X 1E8

Info
  • AI Platform
  • Customers
  • Resources
  • Partners
  • Trust
  • About
  • Careers
  • Blog
  • Support
  • Contact Us
Follow us
  • LinkedIn
  • YouTube
  • Twitter

Newsletter

Subscribe for the latest news & updates

© 2025 Cresta

  • Terms of Service
  • Privacy Policy
  • Employee Privacy Notice
  • Privacy Settings