Artwork

内容由qpcsecurity提供。所有播客内容(包括剧集、图形和播客描述)均由 qpcsecurity 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

The Real Skinny on Penetration Testing: Debunking the Myths

19:03
 
分享
 

Manage episode 434463233 series 2981977
内容由qpcsecurity提供。所有播客内容(包括剧集、图形和播客描述)均由 qpcsecurity 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Welcome to Breakfast Bytes with Felicia King. Today, we delve deep into the often-misunderstood realm of penetration testing. As business owners grapple with the necessity and costs associated with these tests, Felicia demystifies the process, drawing from her three decades of cybersecurity expertise.

In this episode, discover why traditional penetration testing might just be a costly theater act and learn the importance of continuous vulnerability assessments. Felicia shares compelling anecdotes and practical advice on how to genuinely safeguard your business without burning through your budget.

Join us as we explore the intricate dance between IT teams, automated tools, and the critical decisions that can make or break your company's security posture. This is not just another tech talk; it’s a narrative that could redefine how you view cybersecurity investments.

Quick recap

Felicia emphasized the importance of understanding the objectives of the test, and cautioned against overpaying for tests that may not be necessary or effectively scoped.

Next steps

• IT team to implement continuous vulnerability assessment and penetration testing platforms for regular, automated security checks.

• CTO/CSO to assess and oversee the implementation of security tools like Tenable One and Senteon for secure configuration management.

• Executive management team to allocate budget and provide support for IT department/MSP to implement necessary security changes and tools.

Summary

Test Scope and IT Consultancy Management

Felicia also advised that the test should be scoped correctly and conducted by the IT consultancy that manages the company's networks, servers, and applications. She cautioned against overpaying for tests that may not be necessary or effectively scoped.

External Testing Approach and Cots Definition

She argued that the approach of bringing in an external third party to conduct a test without proper consultation and scope can lead to incorrect results. She emphasized that this approach would be more effective in identifying and addressing vulnerabilities, and would provide demonstrable results. Felicia also clarified the term 'COTS' as defined by the National Institute of Standards and Technology in the context of information security technology.

Enhancing IT Configuration for Business Acquisition

She argues that this approach provides more meaningful and actionable information, enabling IT configuration personnel to effectively address identified gaps. Felicia also highlights the importance of using recognized and professional tools like Tenable One and Senteon for secure configuration management. She emphasizes that this approach offers a better return on security investment and is more beneficial for businesses seeking to be acquired.

IT Testing and Business Decision Makers' Guidance

She suggests that business decision makers should provide clear direction and funding for IT before such tests are conducted.

  continue reading

87集单集

Artwork
icon分享
 
Manage episode 434463233 series 2981977
内容由qpcsecurity提供。所有播客内容(包括剧集、图形和播客描述)均由 qpcsecurity 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Welcome to Breakfast Bytes with Felicia King. Today, we delve deep into the often-misunderstood realm of penetration testing. As business owners grapple with the necessity and costs associated with these tests, Felicia demystifies the process, drawing from her three decades of cybersecurity expertise.

In this episode, discover why traditional penetration testing might just be a costly theater act and learn the importance of continuous vulnerability assessments. Felicia shares compelling anecdotes and practical advice on how to genuinely safeguard your business without burning through your budget.

Join us as we explore the intricate dance between IT teams, automated tools, and the critical decisions that can make or break your company's security posture. This is not just another tech talk; it’s a narrative that could redefine how you view cybersecurity investments.

Quick recap

Felicia emphasized the importance of understanding the objectives of the test, and cautioned against overpaying for tests that may not be necessary or effectively scoped.

Next steps

• IT team to implement continuous vulnerability assessment and penetration testing platforms for regular, automated security checks.

• CTO/CSO to assess and oversee the implementation of security tools like Tenable One and Senteon for secure configuration management.

• Executive management team to allocate budget and provide support for IT department/MSP to implement necessary security changes and tools.

Summary

Test Scope and IT Consultancy Management

Felicia also advised that the test should be scoped correctly and conducted by the IT consultancy that manages the company's networks, servers, and applications. She cautioned against overpaying for tests that may not be necessary or effectively scoped.

External Testing Approach and Cots Definition

She argued that the approach of bringing in an external third party to conduct a test without proper consultation and scope can lead to incorrect results. She emphasized that this approach would be more effective in identifying and addressing vulnerabilities, and would provide demonstrable results. Felicia also clarified the term 'COTS' as defined by the National Institute of Standards and Technology in the context of information security technology.

Enhancing IT Configuration for Business Acquisition

She argues that this approach provides more meaningful and actionable information, enabling IT configuration personnel to effectively address identified gaps. Felicia also highlights the importance of using recognized and professional tools like Tenable One and Senteon for secure configuration management. She emphasizes that this approach offers a better return on security investment and is more beneficial for businesses seeking to be acquired.

IT Testing and Business Decision Makers' Guidance

She suggests that business decision makers should provide clear direction and funding for IT before such tests are conducted.

  continue reading

87集单集

所有剧集

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南