Hacker News new | ask | show | jobs
by tptacek 2509 days ago
People do internal pentests even though everyone knows the pentesters will win; you still learn something from the experience.
2 comments

You’ll never be able to prevent privileged insiders, or their accounts, from being able to cause damage. But I have worked with organisations where internal tests were not able to compromise the most critical assets, and where the outcome of the tests was those assets become even more well protected. Which is really the best outcome you could be hoping for with these kinds of engagements, imo.
Of course, I was just being cute.