I’m pretty lazy, but I’d at least run a port scan so I have something to submit in a report. That takes a few minutes to run and can be scheduled to run daily so there’s something in their logs.
That said, our audits always turn up something new (usually benign), so I’d be very suspicious of an “all clear” result.
Cornelius_Wangenheim@lemmy.world 4 days ago
echodot@feddit.uk 4 days ago
You hope it’ll set off alarms. Sometimes it doesn’t, mostly because they don’t have monitoring setup.
Cornelius_Wangenheim@lemmy.world 4 days ago
Pen tests aren’t cheap. Even basic ones are ~$20k. There’s only 2 types of companies that bother with them: ones that care about cybersecurity and ones that have to do it for compliance (PCI/CMMC/etc). Both will have some kind of IDS and a SIEM.
jol@discuss.tchncs.de 4 days ago
Or because you hacked into the wrong company. This has happened multiple times.
CaptainHowdy@lemm.ee 4 days ago
Most folks dgaf about certs, and I agree with them. Certs are BS. I only have certs because employers paid for them and in tech (especially security) there’s a LOT of free time if you know what you’re doing. Certs only prove you can pass a test.
Bold of you to assume most companies have intrusion detection systems and that their monitoring isn’t muted half the time.
Findings come from an automated report generated by a scanner that does literally all the work.
OP post is really not that far off. It’s an easy gig.
Source: I’ve worked on both sides.
expr@programming.dev 4 days ago
Uh, certs are a huge deal in cyber security. Absolutely useless in most fields, but cybersecurity is not one of them.
SaharaMaleikuhm@feddit.org 4 days ago
So pen testing is a scam? I knew it! Opening all my ports right now.
ameancow@lemmy.world 4 days ago
You’re implying that people who post on 4-chan have no clue how the real world works and no idea what business is like and how people make money!