I head infosec for a “Series A - C” B2B company and a fairly standard request from a potential customer is to see not only our own penetration test reports but third party penetration test results, as well. As a result, we run automated pen tests on weekends and before major releases. We also work with an application security firm every 6-12 months. For what it’s worth, we don’t do anything nearly as intense as defense contracting or handling financial info.
That said, I liked the article - thanks for sharing.
If I were handling private customer data or money, I'd absolutely pen test early. Comes back to that "what do you have to lose" consideration re: context. If the worst that happens is my own service goes down, I might delay it.
Comments
I am not sure you want to delay penetration testing until you are post IPO.
Agreed.
Caveat: do you need to do pen testing every release? I'm guessing, not. YMMV.
If you're a defense contractor (as some other commenters mentioned), your priorities are probably quite different.
I head infosec for a “Series A - C” B2B company and a fairly standard request from a potential customer is to see not only our own penetration test reports but third party penetration test results, as well. As a result, we run automated pen tests on weekends and before major releases. We also work with an application security firm every 6-12 months. For what it’s worth, we don’t do anything nearly as intense as defense contracting or handling financial info.
That said, I liked the article - thanks for sharing.
Np! Thanks for sharing.
Glad to hear security is taking the front seat some places. Anecdotes like this help me expand my world view. <3
If I were handling private customer data or money, I'd absolutely pen test early. Comes back to that "what do you have to lose" consideration re: context. If the worst that happens is my own service goes down, I might delay it.