
Episode 166: Why Your Pentest Didn’t Make You Safer
About this episode
In this episode, we explore why many organizations invest in penetration testing yet see little improvement in their actual security posture. We discuss the common pitfalls of treating pentests as one-time events, how attackers operate very differently from scoped assessments, and why remediation—not the report—is what determines real safety. If you’ve ever wondered why “passing” a pentest didn’t translate into stronger defenses, this episode is for you.
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Get every episode summarized
Each time The Cyber Threat Perspective publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Cyber Threat Perspective

Episode 173: How to Find Insecure Active Directory Permissions with ADeleg
The Cyber Threat Perspective

Episode 172: The biggest security blind spots in Midsized companies
The Cyber Threat Perspective

Episode 171: The future of pentesting with AI
The Cyber Threat Perspective

Episode 170: The Evasive Adversary
The Cyber Threat Perspective