Webinar Series: Purple Teaming - Validating Detection & Response Capabilities
In my 11 years of helping customers pen test their network, oftentimes I have seen that companies choose to test only the bare minimum. I understand that companies have a need to satisfy some compliance like PCI or reassure customers and security budgets can be tight. However, why not get more value out of your pen test?Artificially constrained tests may seem reasonable, cheap and quick. However they create a false sense of security and really don’t give insight into true technical risks. You are already paying the money for a test, why not broaden the scope for a little more money? The benefits outweigh the costs:
Defenders think in terms of lists and hackers think in terms of diagrams for the target. Commodity pen testing is again thinking in terms of a list. If a vendor asks “How many external IPs do you have?” you should automatically eliminate that vendor. That question points to a commodity pen test. How often do real hackers ask or receive that information? Commodity vendors are taking customer money to just provide a scan + exploit. I call that approach the “Scan+Exploit+Report+Invoice” approach. Would a real hacker approach a target in such a manner in today’s world of strong security and awareness? It really upsets me that vendors collect a check and just go through the motions. A good security steward needs to understand their real-world risks. Passing a quick test or being compliant doesn't necessarily mean you're secure; just ask Equifax, Target or other recently breached companies.Often, my company tests after a commodity pen tester and we find all kinds issues that they missed. Customers will say “We’ve been using XYZ for years, and they never found anything like this.” Of course we found more, we think and act like hackers. It would be terrible if a customer planned their security around the commodity pen test that missed something important and then were breached. That would create some very hard questions from executives.At NetWorks Group we love pen testing and see it as a valuable exercise. Give us a call and we’ll show you how we help customers understand real-world risks and how you’ll look to a hacker.
Security news, tips, webinars, and more straight to your inbox.