Despite major investments in their security suites, organizations continue to be breached. Our Co-founder and CTO, Arik Liberzon, recently sat down with CyberNews to discuss the value of the adversarial perspective and where his inspiration from Pentera came from.
- Let’s go back to the very beginning of Pentera. What has the journey been like over the years?
- Can you introduce us to your Automated Security Validation approach? What are its key principles?
- Continuous Validation – Our deployments are constantly changing and our security must be able to keep up. Instead of waiting for a report from their annual pentests to understand the effectiveness of their existing security, users can call on a virtual, automated team of pentesters to validate their security at the push of a button.
- Emulate the Real Hacker – To effectively validate the security of your organization, your testing must get as close to the real threat as possible. Automated Security Validation relies on an agentless solution that safely exploits your in-production environment, without the use of playbooks, to provide the most accurate emulation of actual attacks across the entire attack surface.
- The Full Kill-Chain – The testing must progress every scenario until it’s completion so that security teams have an accurate assessment of how impactful each attack can be and where along the attack kill-chain is the most effective for mitigation.
- Safe by Design – Our Security Validation approach showcases exactly how hackers can exploit your network, what attacks they can execute, the potential for lateral movement, and what payloads they can use, all without any impact to your business continuity.
- Actionable Insights – Security validation cuts through the phenomenon of vulnerability fatigue, to reveal your true risk and provide a risk-based remediation roadmap with actionable insights that you can immediately execute to reduce exposure.
- Even though penetration testing is already ubiquitous, why is automated penetration testing not widely adopted?
- Have the recent global events altered your field of work in any way? Were there any new challenges you had to adapt to?
- In this age of frequent cyberattacks, what do you think are the key security practices both businesses and individuals should adopt?
- What are the most common vulnerabilities nowadays, that if overlooked, can lead to serious problems for a business?
- Which industries do you think should take penetration testing more seriously?
- In your opinion, what kind of tests and checkups should every company conduct regularly?
- Would you like to share what’s next for Pentera?