The Cyber Security Review | Thursday, June 05, 2025
Fremont, CA: The public sector is having difficulty escaping an antiquated penetration testing (pentesting) paradigm that forces state, local, and higher education institutions, as well as federal civilian agencies, to deal with methods that are not scalable and can provide additional security risks. However, until organizations comprehend the factors that lead to these issues—bandwidth, efficiency, and security—they cannot solve these outdated security testing techniques.
Many public sector organizations assign their pentesting to a small team of five to seven individuals who work on particular targets for a set amount of time and then report back on their findings. Several weeks may pass during this procedure, not counting the time it takes security personnel to examine and react to the report after it has been filed.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Despite its seeming thoroughness, this method is useless due to its lack of scalability. Because there are typically hundreds of internal and external assets to test for any firm, security teams may be forced to take shortcuts and expose themselves to additional dangers. In contrast to proactive risk identification and mitigation, irregular testing, such as once or twice a year, results in significant risk accumulation and delayed, reactive reactions to threats.
Federal Civilian Agencies
Federal agency officials have been dealing with visibility concerns for years despite efforts to address them. This is problematic because by first comprehending the depth and breadth of their attack surface makes it easier to test and safeguard their surroundings.
A thorough asset inventory is necessary to create a testing plan for federal civilian agencies. This gives CISOs and vulnerability management executives the starting point to investigate ways to reduce and strengthen the attack surface. Selecting the best solution begins with knowing the entire attack surface, whether that means putting in place a plan for ongoing common vulnerabilities and exposure (CVE) and known exploited vulnerabilities (KEV) scanning, creating an internal red team, or hiring an outside vendor to carry out ongoing penetration tests to find and close gaps.
Defense and Intelligence Communities
Regarding penetration testing and vulnerability finding, the military and intelligence communities confront different obstacles while having a sizable external attack surface. The acceleration of the work-from-home trend caused by COVID-19 is one noteworthy recent difficulty. This led to a surge of individuals developing vital software from home networks, which sometimes need to be more secure.
The authenticated nature of many unclassified programs and environments made vulnerability reporting by the general public insufficient, which is when continuous testing by professionals emerged as a security need. Recognizing the need for professional researchers and ethical hackers to attempt to hack its environment, the Defense Digital Service (DDS) created the "Continuous Bounty" program, which is still in operation today.
More in News