Hacker News new | ask | show | jobs
by dmos62 37 days ago
Selective training makes sense. But, I heard a pentest professional provide this counter-argument: if you tell management which individuals failed the test, even if your intention is to provide those people with the training they lack, the management might, due to ignorance, shift blame for suboptimal security on those people, label them as lazy/incompetent/etc, and ultimately not put the necessary processes (testing, training) in place which are the true determinants of penetration rates. The idea is that you get inefficiency by selecting for training broadly, but you prevent extreme sabotage by ignorant management.