Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

ESRM – Penetration testing and fixing need to get out of 90s model

by The Gurus
November 26, 2020
in Editor's News
Share on FacebookShare on Twitter

The traditional penetration testing model is not effective any more, as the model is not balanced in terms of cost benefit and in ensuring flaws are fixed.

Speaking at the Enterprise Security and Risk Management conference in London, Rui Shantilal, founder and managing partner of Keep-It-Secure-24, said that penetration testing has changed in the last ten years to match the actions of the attacker, but asked if enough was being delivered.

He said that “frameworks,tools, techniques and methodologies” have changed, but so too have the methodologies of attacker and in the 1990s, to test security you hired a company who gave you the results of the test and give you a report. “Nowadays it is pretty much the same, internet and tools have evolved but the process is the same,” he said.

“Current momentum is challenging for the penetration testing model, as in the 1990s the number of vulnerabilities was so low that it was irrelevent and not important to test every day. When we used to do traditional penetration testing, the hardest piece to know was when to start.”

He said that there are different types of attackers: the script kiddies who do not spend a lot of time on the attack; those who do spent time; and those behind targeted attacks. Between the first two, Shantilal said that they are covered with standard penetration testing, and eventually we may be able to do the testing in the same time frame.

“What about APT though, the attacker can do reverse engineering of traffic and decrypt cookies and understand what is inside organisation and that is not possible in five, ten or 15 mandates, so if you are worried about APT do AP testing,” he said.

He also claimed that if a problem is detected, is the user actually sure it has been mitigated? He said users should expect a “nice report” and they should get a presentation from the lead penetration tester on everything that they found.

“There are the reasons why the traditional penetration testing model is not effective any more, as the model is not balanced in terms of cost benefit. You dont get what you pay for,” he said. “It should look like: testing, reporting, managing and validating where you can manage your priorites and can simulate a flaw so you can check the resiliency of your controls.”

Shantilal also asked how many businesses would take that report and send it unencrypted within the company? He asked if a business knew how to extract the metrics on the process, knew what kind of vulnerabilities were more typical and who needs to be trained to mitigate those issues?

He said: “Penetration testing is a project not a process, but security a process not a one off approach.”

Tags: APTHackerPenetration TestingService
ShareTweet
Previous Post

Regin – most sophisticated or more hype?

Next Post

Sony Pictures breach gets worse as poor password hygiene revealed

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol