
The implementation process for Acunetix software involves several key steps, ensuring a smooth setup and integration into your security workflow:
Select Deployment Option: Choose between Acunetix Online (cloud-based) or Acunetix On-Premises (installed on your infrastructure) based on your data security preferences.
Configuration: Configure the software by setting up user permissions, adding target websites, and verifying ownership.
Launch Scans: Start scanning your web applications to identify vulnerabilities. The initial scan may take longer, depending on the size and complexity of your web applications.
Fix Issues: Address the identified vulnerabilities by following the remediation steps provided in the reports.
Retesting: After fixing vulnerabilities, retest to confirm that the issues have been resolved.
The duration of the implementation process can vary based on several factors, including the size and complexity of your web applications, the deployment option chosen, and the level of customization required. Generally, the initial setup and configuration can take a few hours to a couple of days. Subsequent scans and ongoing monitoring will depend on the frequency and scope of the scans.
Acunetix can be customized to fit specific business needs. Here are some of the customization options available:
Custom Headers: You can add custom headers to your scans, which is useful for whitelisting Acunetix in web application firewalls and other protection mechanisms.
Scan Policies: Acunetix allows you to create custom scan policies to tailor the scanning process according to your specific requirements.
Authentication Methods: The platform supports various authentication methods, including form-based, HTTP, and NTLM authentication, which can be configured to match your application's authentication process.
Integration with CI/CD Pipelines: Acunetix integrates with popular CI/CD tools like Jenkins, GitLab, and Azure DevOps, allowing you to customize the security testing process within your development workflow.
Custom Vulnerability Checks: You can create custom vulnerability checks to address specific security concerns unique to your web applications.
Acunetix's pricing structure includes several components, but there are no setup fees. Here are some details about additional costs:
Maintenance and Support: Acunetix offers different support plans, including standard and premium support. Premium support includes additional services like guided success and U.S.-based support.
Professional Services: For organizations needing extra assistance, Acunetix provides professional services, which can include custom integrations, advanced training, and security assessments.
Add-Ons: Acunetix offers several add-ons, such as Mend SAST (Static Application Security Testing), SCA (Software Composition Analysis), and container security.
Subscription Plans: The pricing varies based on the number of websites scanned. For example, scanning up to 5 websites costs approximately $4,500, while scanning 36-50 websites costs around $26,600.
Acunetix offers a variety of training and support options to help new users get started and make the most of the platform:
Online Training Courses: Acunetix provides interactive online training courses tailored to the user's experience level. These courses cover essential topics such as scan settings, crawling options, login sequence recorder, HTTP editor, and more.
Support Videos: For visual learners, Acunetix offers a range of support videos that walk users through key functionalities, including setting up scans, analyzing results, and improving web security posture.
Product Manuals: Detailed product manuals are available for both Acunetix Standard and Acunetix 360, covering everything from getting started to advanced configurations.
Customer Support: Acunetix provides extensive customer support, including email and phone support. Premium support plans offer additional services like guided success and U.S.-based support.
Acunetix implements robust security measures to protect data, ensuring compliance with industry standards and regulations:
Data Encryption: All data transfers, data at rest, and backups are encrypted using TLS 1.2, SSL certificates, and 256-bit AES encryption.
Data Center Security: Acunetix uses Amazon AWS for its data centers, applying custom security policies, configuring public and private subnets, and encrypting EC2 backups and S3 assets with AES-256.
Application-Level Security: All web pages use TLS (HTTPS) for data transmission. User account passwords are hashed and cannot be retrieved, only reset. Login pages have brute force protection, and API endpoints have rate limits.
Internal IT Security: All staff use disk encryption, PGP keys for secure communication, and two-factor authentication (2FA) for their accounts. A dedicated internal security team monitors for vulnerabilities.
Data Retention Policies: Acunetix allows users to configure retention periods for raw scan files and scan data, ensuring data is stored only as long as necessary.
Update Frequency: Acunetix frequently releases updates to ensure that users have access to the latest features, security checks, improvements, and bug fixes. These updates are crucial for maintaining the effectiveness of the platform in identifying and mitigating new security threats.
Update Management:
Automatic Updates: By default, Acunetix On-Premises is set to automatically check for updates, download, and install them. This ensures that the software is always up-to-date without requiring manual intervention.
Manual Updates: Users can opt to be notified of new updates and manually install them. This option allows for greater control over the update process, especially in environments where automatic updates might disrupt ongoing operations.
Data Ownership: Acunetix ensures that users retain full ownership of their data. For the On-Premises version, all data is stored locally, giving organizations complete control over how it is stored, secured, and managed. This includes scan results, reports, and any other data generated by the platform.
Data Portability:
Data Export: Users can export scan results and reports in various formats, such as PDF, HTML, and CSV, making it easy to share and analyze data outside the platform.
Data Retention: Acunetix allows users to configure retention periods for raw scan files and scan data. This helps manage data storage and ensures compliance with organizational policies.
Acunetix offers flexible terms for scaling up or down to accommodate changing organizational needs:
Subscription Plans: Acunetix provides various subscription plans based on the number of websites to be scanned. Organizations can easily upgrade or downgrade their plans as their needs change.
Custom Quotes: For larger or more specific requirements, Acunetix offers custom quotes, ensuring that the solution fits the organization's budget and needs.
On-Demand Scalability: Acunetix 360 On-Premises can be deployed on cloud environments like AWS, Azure, or Google Cloud, allowing for on-demand scalability without the need for additional hardware.
Renewal: Acunetix licenses are typically annual, and renewal notifications are sent out before the expiration date. Users can renew their licenses to continue using the software without interruption.
Cancellation: Users can cancel their subscriptions at any time. For Acunetix Online, data is retained for 60 days after the license expires, after which it is permanently deleted. For Acunetix On-Premises, data retention and deletion are managed by the organization.
Grace Period: After the license expires, there is a 7-day grace period during which users can still access their data and start new scans.
Acunetix meets several key compliance standards, making it suitable for organizations with stringent security and regulatory requirements:
OWASP Top 10: Acunetix scans for vulnerabilities listed in the OWASP Top 10, helping organizations address common web application security risks.
PCI DSS: The platform supports Payment Card Industry Data Security Standard (PCI DSS) compliance by identifying vulnerabilities that could affect cardholder data security.
HIPAA: Acunetix helps healthcare organizations comply with the Health Insurance Portability and Accountability Act (HIPAA) by securing electronic protected health information (ePHI).
ISO 27001: The platform supports compliance with ISO 27001, an international standard for information security management systems (ISMS).