Penetration Tests: useful, pointless, harmful, required, ineffective? - Phillip Wylie, Marina Segal - ESW #398
About this episode
Penetration tests are probably the most common and recognized cybersecurity consulting services. Nearly every business above a certain size has had at least one pentest by an external firm.
Here's the thing, though - the average ransomware attack looks an awful lot like the bog standard pentest we've all been purchasing or delivering for years. Yet thousands of orgs every year fall victim to these attacks. What's going on here? Why are we so bad at stopping the very thing we've been training against for so long?
This Interview with Phillip Wylie will provide some insight into this! Spoiler: a lot of the issues we had 10, even 15 years ago remain today.
Segment resources:
- Phillip's talk, Optimal Offensive Security Programs from Dia de los Hackers last fall
It takes months to get approvals and remediate cloud issues. It can take months to fix even critical vulnerabilities! How could this be? I thought the cloud was the birthplace of agile/DevOps, and everything speedy and scalable in IT? How could cloud security be struggling so much?
In this interview we chat with Marina Segal, the founder and CEO of Tamnoon - a company she founded specifically to address these problems.
Segment Resources:
-
Gartner prediction: By 2025, 75% of new CSPM purchases will be part of an integrated CNAPP offering. This highlights the growing importance of CNAPP solutions. https://www.wiz.io/academy/cnapp-vs-cspm
-
Cloud security skills gap: Even well-intentioned teams may inadvertently leave their systems vulnerable due to the cybersecurity skills shortage. https://eviden.com/publications/digital-security-magazine/cybersecurity-predictions-2025/top-cloud-security-trends/
-
CNAPP market growth: The CNAPP market is expected to grow from $10.74 billion in 2025 to $59.88 billion by 2034, indicating a significant increase in demand for these solutions. https://eviden.com/publications/digital-security-magazine/cybersecurity-predictions-2025/top-cloud-security-trends/
-
Challenges in Kubernetes security: CSPMs and CNAPPs may have gaps in addressing Kubernetes-specific security issues, which could be relevant to the skills gap discussion. https://www.armosec.io/blog/kubernetes-security-gap-cspm-cnapp/
-
Addressing the skills gap: Investing in training to bridge the cybersecurity skills gap and leveraging CNAPP platforms that combine advanced tools are recommended strategies. https://www.fortinet.com/blog/business-and-technology/navigating-todays-cloud-security-challenges
-
Tamnoon's State of Remediation 2025 report
In this week's enterprise security news,
- Knostic raises funding
- The real barriers to AI adoption for security folks
- What AI is really getting used for in the wild
- Early stage startup code bases are almost entirely AI generated
- Hacking your employer never seems to go well
- should the CISO be the chief resiliency officer?
- proof we still need more women in tech
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-398
Get every episode summarized
Each time Enterprise Security Weekly (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Audio)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, &...
Enterprise Security Weekly (Audio)
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interview...
Enterprise Security Weekly (Audio)
Can employees safely use AI agents? AI pentesting agent liabilities, and the new...
Enterprise Security Weekly (Audio)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the n...
Enterprise Security Weekly (Audio)
