Hacker News new | ask | show | jobs
by nicholasjarnold 1286 days ago
So, to try and add some value to this conversation vs just reporting a personal anecdote... Do people here have suggestions for actually-good white-hat companies?

Can you recommend companies that you've personally worked with who employ knowledgeable security engineers (hackers) to perform real penetration tests and conduct valuable security scans resulting in value-add reports your engineering team can work with?

Not looking for naming and shaming...but rather "Who doesn't suck at doing this?".

2 comments

NCC Group is probably the biggest name because they go around Hoovering up companies that are usually above average in the competencies you asked about. And they can attract and retain talent.

Trail of Bits is another big name because they hire and retain talent across a large number of enterprise, emerging tech, and research verticals.

Other established firms include Atredis Partners, IOActive, Security Innovation. There are more one could list.

Sometimes these companies work with partners who ask to publicly disclose some artifact resulting from the test. Here is a collection of those reports aggregated by firm: https://github.com/juliocesarfort/public-pentesting-reports (Edit: note this is not a great way to evaluate any particular company, but it does provide an objective listing of companies that exist in the pentesting space).

Each firm will also have variability in their personnel for your project which can yield different results for two independent tests on the same target from the same firm.

we had a good experience with https://www.praetorian.com/services/penetration-testing/ earlier this year