Hacker News new | ask | show | jobs
by cratermoon 1503 days ago
It would be overgeneralizing to say they are all just there to sell testing that allows vendors to check a box on RFPs or contract requirements, but in my experience they mostly exist to generate a testing report and include with it a pitch to sell a product or service that (how convenient!) can solve the problems found in their pentest report.

I've had to wave off a few managers who got unsolicited emails from vendors saying they found or know of vulnerabilities in their site(s) and for just $MANY they can fix them.

1 comments

Interesting...