Penetration Tests: useful, pointless, harmful, required, ineffective? - Phillip Wylie - ESW #398
About this episode
Penetration tests are probably the most common and recognized cybersecurity consulting services. Nearly every business above a certain size has had at least one pentest by an external firm.
Here's the thing, though - the average ransomware attack looks an awful lot like the bog standard pentest we've all been purchasing or delivering for years. Yet thousands of orgs every year fall victim to these attacks. What's going on here? Why are we so bad at stopping the very thing we've been training against for so long?
This Interview with Phillip Wylie will provide some insight into this! Spoiler: a lot of the issues we had 10, even 15 years ago remain today.
Segment resources:
- Phillip's talk, Optimal Offensive Security Programs from Dia de los Hackers last fall
Show Notes: https://securityweekly.com/esw-398
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Video)
Breaking in with CrashFix, supply chain security, and CMMC phase 1 - Anna Pham,...
Enterprise Security Weekly (Video)
OT Security/business resilience, lack of incentives for securing software & the...
Enterprise Security Weekly (Video)
Bringing intelligence to assets, new White House cybersecurity strategy, and the...
Enterprise Security Weekly (Video)
Hardware-level zero trust, don't trust AI with your employees, and the news - Ma...
Enterprise Security Weekly (Video)