
Your Pentest Is a Placebo – and Attackers Know It
Attackers love your pentest report: it calms you – and stops no one. Time to end the ritual.
Topic
When & Where
Details
Format:
Management lecture
Language:
German
Session description
Speaker: Arthur Raess
Your last pentest report doesn't tell you how secure you are – it tells you how secure you were on one day last year. Since then: new releases, new CVEs, changed configurations, new permissions. Attackers work exactly in this window. And this window cannot be fixed, shortened or audited away – it is built into the "snapshot" model itself.
That is why this talk is not about complementing the annual pentest. It is about replacing it.
Continuous pentesting is the pentest – just without an expiry date: our platform permanently attacks your systems with the same techniques real attackers use – autonomously, unannounced, every single day. Findings don't surface in a report twelve months later; they go straight to the teams who fix them. What was sec ...

