Offensive security should be a strategic pillar of a cyber security program and a way to evaluate the effectiveness of the program’s capital allocation. Commodity “pen testing” that does not inform defensive spend or strategic road maps needs to go the way of the dodo bird as do risk maturity assessments that formulate their input from policy reviews and personnel interviews. Bad data in, but data out. Offense should inform defense.
My eBook about using offensive security engagement and CTEM outputs as an input to Quantitative Risk Analysis is now live! Complete with a case study and implementation guide! Give it a read and let me know your thoughts! https://lnkd.in/gtU6MYVW