Chapter 21
Ten Reasons Hacking Is the Only Effective Way to Test
IN THIS CHAPTER
Uncovering overlooked weaknesses
Understanding business threats with security assessments
Approaching your security testing from the perspective of a hacker isn’t just for fun or show. For numerous business reasons, it’s the only effective way to find the security vulnerabilities that matter in your organization.
The Bad Guys Use Good Tools and Develop New Methods
If you’re going to keep up with external attackers and malicious insiders, you have to stay current on the latest attack methods and tools that they’re using. I cover many of the latest tricks, techniques, and tools throughout this book.
IT Governance and Compliance Are More Than High-Level Audits
With all the government and industry regulations in place, your business likely doesn’t have a choice in the matter. You have to address security. The problem is that being “compliant” with these laws and regulations doesn’t mean that your network and information are secure. Payment Card Industry Data Security Standard (PCI DSS) comes to mind here. Systems within your PCI DSS cardholder data environment might be secure but someone might be able to drive a truck through your ERP application. Countless businesses run their vulnerability scans, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access