Thursday | 16 October, 2008
Computerworld
Classroom breaches of top enterprises spur industry debate
Are student pen testers a threat to security professionals?
Darren Pauli 18/10/2007 11:03:53

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Gray hat hackers, offering dirt cheap penetration tests for as little as $500, have helped taint the image of professional penetration testers.

In an article which appeared in Computerworld's sister magazine, Chief Security Officer (page 38, July, 2006), Gartner security analyst John Pescatore said hackers, often students, have driven some professional testers out of the business by undercutting prices by more than 80 percent.

However he warns that cheap tests are risky for business because they do not construct exercises that reflect the complexities of a corporate network.

Mark Weatherford, CISO for the state of Colorado said in the same article that business must tighten network security and plug vulnerabilities to get the most out of a penetration test, and to avoid damaging poorly built systems.

"People think that you can push the easy button and it will happen, your problems are clear. It just points out that your system can be exploited. Big deal," Weatherford said.

"I consider a pen test to be the supreme test for a mature organization. It's important to remember that pen tests are invasive and can break things."

Have an opinion on this story? Click to e-mail Darren Pauli.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about MySQL, IT People, Gartner
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Enterprise Wireless WLAN Security

Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links