Mark Raeburn, Context: the evolution of pen-testing
Steve Mansfield-Devine · Computer Fraud & Security · 2013
Penetration testing is no longer an optional activity for most organisations – something to be done only after a security breach has occurred. Many regulations now require regular pen-testing and the more enlightened organisations understand that discovering their weaknesses is an intrinsic part of risk assessment and due diligence.