Simply doing more pentests in the traditional manner is not viable. While missing all
kinds of critical vulnerabilities, traditional pentests can even make the ones that are
found and reported difficult to keep up with. It’s frustrating to think of all the money,
labor and resources that are being spent by security teams and their contractors only
for those efforts to fall short in response to today’s and tomorrow’s cyber threats.
In the words of Roman Medina, CISO at Jefferson Bank in Texas, “I do think we may
miss critical issues or vulnerabilities if we stick to the same annual pentest year after
year. The way we pentest has to evolve. I am looking at starting a continuous pentest
service next year.”
It’s not possible to staff a large enough team to perform traditional pentests in a more
continuous manner. It’s time to reimagine how pentests are staffed and performed.
Organizations need scalable third-party solutions that harness technology combined
with manual, human testing in order to provide more flexibility, continuity and intelligence
than a traditional pentest.