Scaling Security: How U.Porto and Ethiack Protected 5,000+ Assets with AI-Powered Intelligence

Link copied!
Jorge Monteiro

Jorge Monteiro

CEO

Ethiack

August 21, 2025

Securing a Vast and Dynamic Academic Digital Landscape

Universidade do Porto, a leading institution in high-level education, operates within a complex and expansive digital environment. Its attack surface is characterized by being "Huge, Dynamic, and Exposed”, encompassing a wide array of digital assets, including web applications, various software applications, extensive data repositories, and the challenges Shadow IT poses. This broad exposure necessitates a robust and continuous cybersecurity strategy to protect its academic integrity, research, and student data.

The Challenge: Navigating a Broad Attack Surface with Diverse Threats

The primary challenge for Universidade do Porto was effectively managing and securing its vast and constantly evolving digital footprint. The institution faced a spectrum of vulnerabilities, from well-known Common Vulnerabilities and Exposures (CVEs) and software bugs to critical misconfigurations and unauthorized access points. The threats were equally diverse, ranging from opportunistic “script kiddies” and ideologically motivated hacktivists to financially driven cybercriminals, all seeking to exploit weaknesses in their systems.

Their specific needs included:

  • External Testing (Black-Box): A requirement for comprehensive black-box penetration testing to simulate real-world external attacks, assessing vulnerabilities from an attacker's perspective without prior knowledge of the internal systems.
  • Accuracy & Speed: The imperative for precise identification of vulnerabilities, combined with the rapid execution of assessments, crucial for an environment with such a dynamic attack surface.

The Solution: Ethiack’s Platform for Continuous Attack Surface Reduction

Ethiack partnered with Universidade do Porto to provide a solution that met their needs for speed, accuracy, and external testing. Leveraging its advanced platform, Ethiack offered a comprehensive approach to discover, treat, and mitigate vulnerabilities associated with the University’s extensive online exposure.

The solution involved:

  • AI-Powered Black-Box Pentesting: Ethiack’s platform conducted a single, yet highly effective, AI-driven penetration test, designed to quickly and accurately identify vulnerabilities accessible from an external perspective.
  • Continuous Monitoring and Information Provision: The platform provided essential, ongoing information to the University’s InfoSec team, enabling them to discover, prioritize, and address vulnerabilities proactively.
  • Focus on Attack Surface Reduction: The core of the solution was to provide tools and insights that directly contributed to the daily tasks of reducing the University’s overall attack surface.

What Has Changed: Enhanced Visibility and Proactive Security Operations

The implementation of Ethiack’s platform brought about significant improvements in Universidade do Porto’s cybersecurity operations. Over a seven-month timeline (September 2024 - present), the university gained unprecedented visibility and control over its digital security. Here are the main improvements:

  • Vast Asset Coverage: The platform effectively managed and monitored 1,000 critical assets within a broader landscape of 5,000, demonstrating its scalability and capacity to handle large, complex environments.
  • Streamlined Vulnerability Management: While specific findings are not disclosed, the continuous nature of the platform’s insights enabled the university to systematically address vulnerabilities.

The Ethiack platform offers a range of essential information for discovering, treating, and mitigating the vulnerabilities associated with our online exposure. It is an essential tool for daily tasks focused on reducing our attack surface.

José Augusto SilvaHead of InfoSecUniversidade do Porto

Through this partnership, Universidade do Porto transformed its approach to cybersecurity, moving towards a more proactive and efficient model for managing its vast and dynamic digital assets, ensuring the continued security of its high-level educational services.

Don’t wait for the attack.

Secure Your Future with Ethiack

Try Ethiack

If you're still unsure convince yourself with a 30-day free trial. No obligation. Just testing.

signup(datetime.now());

def hello(self): print("We are ethical hackers")

class Ethiack: def continuous_vulnerability_discovery(self: Ethiack): self.scan_attack_surface() self.report_all_findings() def proof_of_exploit_validation(self: Ethiack): self.simulate_attack() self.confirm_exploitability() self.validate_impact()

while time.time() < math.inf: ethiack.map_attack_surface() ethiack.discover_vulnerabilities() ethiack.validate_exploits() ethiack.generate_mitigations() ethiack.calculate_risk() ethiack.notify_users() log.success("✓ Iteration complete")

>>> show_testimonials() They found vulnerabilities no one else did. Fast, real, and actionable results. It's like having a red team on call. >>> check_socials()

signup(datetime.now()) meet(ethiack)

def actionable_mitigation_guidance(ethiack): ethiack.generate_mitigation_steps() ethiack.prioritize_fixes() ethiack.support_teams() def attack_surface_management(ethiack): while time.time() < math.inf: ethiack.map_attack_surface() ethiack.monitor_changes() def quantifiable_risk_reduction(ethiack): ethiack.check_risk_metrics() ethiack.calculate_delta() return ethiack.report_real_risk()

Activate AI penTesting

Start a Free 30-day trial
Ethiack — Autonomous Ethical Hacking for continuous security Continuous Attack Surface Management & Testing