Demo of the CyCognito Platform

See the CyCognito platform in action to understand how it can help you identify, prioritize and eliminate your most critical risks. 

State of External Exposure Management, Summer 2024 Edition

Download the report now to stay ahead of emerging threats and strengthen your organization’s security posture for 2024. 

The Total Economic Impact™ of The CyCognito Platform

Read The Total Economic Impact™ of The CyCognito Platform — a Forrester study. Cost Savings And Business Benefits Enabled By The CyCognito Platform. 

 
Research

Research Results: The Challenges With Pen Testing for Cybersecurity

Raphael-Reich
By Raphael Reich
Was Vice President of Marketing at CyCognito
May 5, 2021

Penetration testing is one of the most well-known tools security teams use to defend against attackers and keep their organizations secure. But it’s also a technology from another century: penetration testing has its origins in the late 1960’s. 

Does pen testing still make sense in an era of digital transformation, where even the largest, most traditional companies are reinventing themselves to be digital-first businesses? The very same world where attackers take the path of least resistance to breach business data and applications, using weaknesses in overlooked and internet-exposed assets?

We wanted to understand the answer to those questions, so we worked with Dark Reading to survey over 100 large organizations about their penetration testing practices and perceptions, to see what they truly think about pen testing effectiveness for the modern IT ecosystem. Short answer: respondents at these organizations think that pen tests have huge blind spots, are done too infrequently, and are too expensive to be very effective as a security solution – despite the fact that they rely on them for exactly that.

We uncovered those insights (and more) by commissioning Dark Reading to survey security and IT professionals involved closely with penetration testing: from CISOs and CIOs to IT and security directors to security architects and pen test leads. 

Here are some highlights of what we uncovered:

Why do organizations pen test?

  • 70% to measure the organization’s security posture
  • 69% for breach prevention
  • 65% to ensure compliance with regulatory mandates

The biggest concerns with penetration testing? 

  • 60% say they get only limited test coverage and have too many blind spots
  • 47% report that their penetration tests only help them detect known threats, not new or unknown ones
  • 44% described the cost-per-asset tested as being too high

How much do organizations spend on pen testing annually? 

  • 12/% spend more than $1 million
  • 8% spend $500,001 to $1 million
  • 10% spend 250,001 to $500,000

That’s 30% of large organizations spending a quarter of a million dollars or more a year on penetration testing.

It’s probably not that surprising to anyone in the security industry that there are so many concerns with penetration testing as a solution for securing organizations. It’s a bit more surprising that with all those shortcomings and with such a large price tag, organizations continue to count on them to ensure they are secure. Based on the results of the research, it seems clear that penetration tests are simply not cut out for today’s new and emergent threat landscape or digital transformation.

Abandoning penetration testing may simply not be a viable approach for many organizations. But, every organization can get a great deal more value from their penetration testing investments by shifting a significant portion to an external attack surface management (EASM) solution. EASM platforms like the CyCognito platform provide a comprehensive, continuous, more cost-effective approach that will discover and help them secure their entire internet-exposed attack surface. 

Read the full report for additional findings and further detail on how the challenges with the cost, coverage, and cadence of penetration tests hinder their effectiveness in measuring security posture and preventing breaches.   


Topics



Search the Blog



Recent Posts






Tim Matthews
How to Budget for EASM
By Tim Matthews
November 18, 2024


Top Tags



CyCognito Research Report

State of External Exposure Management, Summer 2024 Edition

State of External Exposure Management, Summer 2024 Edition

Download the report now to stay ahead of emerging threats and strengthen your organization’s security posture for 2024.

O'Reilly Report

Moving from Vulnerability Management to Exposure Management

Moving from Vulnerability Management to Exposure Management

Download the report to learn about the historical trends behind the emergence of exposure management, how to develop a strategic plan and assemble a team to smoothly transition frameworks, and example tech stacks to consider for your organization.

Request a Free Scan

See Exactly What Attackers See

Get a Free Scan of Your Attack Surface

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally exposed assets on a portion of your parent company or a single subsidiary.