The Dilution of Pentesting

By Daniel Miessler on December 13th, 2005: Tagged as Information Security | Rants
  • Penetration Testing is already seen as a commodity. Work plans that were $50,000 4 years ago are now awareded for $12,000. CFO's don't care. To make matters worse, you might be asked for a Risk Assessment, and be underbid by two guys a laptop and Nessus performing a Vulnerability Assessment and taking advantage of uneducated consumers.
  • Good points. :)
  • Rob
    Won't experience continue to separate the men from the boys? Maybe this will help the very best to service more customers more efficiently, and reduce customer costs.

    Besides, someone wrote that information security is not a permanent cashcow. When new o/s technologies arrive on the scene, much of the status quo will become obsolete. Nothing stays the same forever, except maybe for the idiocy. Since those new technologies will probably also protect users from themselves, perhaps even idiocy will be diluted as well.
  • Dave
    I think you've just found the line between Analysts and Engineers.

    A growing trend in security is to lower the costs of it. Companies are starting to hire one or two Engineers and leave the rest of the work to Analysts. Like the System Admin and Operator scenario.

    Sorry to spam the hell out of your blog today =)
blog comments powered by Disqus

 

twitter_icon

Sample Original Content


Information Security

Tutorials and Primers

Culture & Society

Technology & Science

Politics

Philosophy & Religion

Miscellaneous

Tools & Projects


Blog Archives