When I look at how the security domain has evolved over the last decade, I can’t help but be incredibly impressed and humbled by all the fantastic work of leveling up security to modern DevOps, CI/CD and cloud practices. But as I take a closer look, offensive security (pen testing, red teaming, ethical hacking), long believed to be one of the most effective ways to zero in on real exploitable vulnerabilities with business impact, is frankly stuck in ancient history.
It’s almost completely manual and primarily offered as a service, not a…