Hacker News new | ask | show | jobs
by 001spartan 3162 days ago
This is exactly why penetration testers and red teams do these types of engagements. We like to emphasize that organizations need to assume they've been compromised by someone, and they need to constantly keep that in mind when they build security policies and technical controls. You can never keep a determined attacker out, but you can limit the damage that they can do, and make them spend more time getting in.