The Dilution of Pentesting

By Daniel Miessler on December 13th, 2005: Tagged as Information Security | Rants
  • Dave

    I think you’ve just found the line between Analysts and Engineers.

    A growing trend in security is to lower the costs of it. Companies are starting to hire one or two Engineers and leave the rest of the work to Analysts. Like the System Admin and Operator scenario.

    Sorry to spam the hell out of your blog today =)

  • Dave

    I think you’ve just found the line between Analysts and Engineers.

    A growing trend in security is to lower the costs of it. Companies are starting to hire one or two Engineers and leave the rest of the work to Analysts. Like the System Admin and Operator scenario.

    Sorry to spam the hell out of your blog today =)

  • Rob

    Won’t experience continue to separate the men from the boys? Maybe this will help the very best to service more customers more efficiently, and reduce customer costs.

    Besides, someone wrote that information security is not a permanent cashcow. When new o/s technologies arrive on the scene, much of the status quo will become obsolete. Nothing stays the same forever, except maybe for the idiocy. Since those new technologies will probably also protect users from themselves, perhaps even idiocy will be diluted as well.

  • Rob

    Won’t experience continue to separate the men from the boys? Maybe this will help the very best to service more customers more efficiently, and reduce customer costs.

    Besides, someone wrote that information security is not a permanent cashcow. When new o/s technologies arrive on the scene, much of the status quo will become obsolete. Nothing stays the same forever, except maybe for the idiocy. Since those new technologies will probably also protect users from themselves, perhaps even idiocy will be diluted as well.

  • http://dmiessler.com/ Daniel

    Good points. :)

  • http://dmiessler.com Daniel

    Good points. :)

  • http://www.alexhutton.com/ Alex Hutton

    Penetration Testing is already seen as a commodity. Work plans that were $50,000 4 years ago are now awareded for $12,000. CFO’s don’t care. To make matters worse, you might be asked for a Risk Assessment, and be underbid by two guys a laptop and Nessus performing a Vulnerability Assessment and taking advantage of uneducated consumers.

  • http://www.alexhutton.com Alex Hutton

    Penetration Testing is already seen as a commodity. Work plans that were $50,000 4 years ago are now awareded for $12,000. CFO’s don’t care. To make matters worse, you might be asked for a Risk Assessment, and be underbid by two guys a laptop and Nessus performing a Vulnerability Assessment and taking advantage of uneducated consumers.


Top

Popular

Information Security / Technology

Politics

Philosophy & Religion

Technology & Science

Culture & Society

Miscellaneous

Arguments

Projects

Collections

Twitter

What I'm Reading

Favorite Books and Essays

Top Blog Categories

Inputs