Fifth Annual State of Pentesting Report – Caroline Wong, Cobalt
Cobalt announced its fifth annual State of Pentesting Report. This year’s report highlights the impact of talent shortages and budget cuts on security teams’ performance and plans for 2023. Cobalt is releasing a Pentest Management Platform (PMP) to increase the efficiency and quality of pentesting programs. PMP enables in-house security teams to cover the entire lifecycle of a pentest from planning, launching, and collaborating on tests to writing reports, tracking vulnerabilities, and remediation efforts.
Transcript
This is texturing TV. Hi everyone. Welcome back to text John TV.
I'm really happy to have my friend Carolyn Wong who has not been on in way too long here with me on Textron TV, but we've got her back actually just quick plug. Oh and another week or from the time you're seeing this we will be out in San Francisco at RSA conference. And once again, we'll be doing our depth SEC Ops or devops connective sick, ops of that and Caroline, of course as always is one of our features.
Featured speakers there and looking forward to having her and I'm sure she's doing a lot of other things that we shall tell us about. But let me introduce you with Carolyn. It's so good to see you.
How are you? You look great. You look great great.
It's it's a pleasure. So look, not everyone knows who you know that I mean, I've told them you're my friend and that should be enough for them. But just in case they don't know who Carolyn long is why don't you give a little background?
So I'm currently the chief strategy officer at Cobalt. We are a pen test as a service company. I began working in the information security field in 2005 leading security teams over at eBay and at Zynga.
I authored a book called security metrics The Beginner's Guide in 2011. That book was inaugurated into the cybersecurity Canon Hall of Fame in 2022. I also host a podcast called humans of infosec and I teach cybersecurity courses on LinkedIn learning.
Absolutely and very successful cybersecurity courses aren't LinkedIn learning. I might add. io for those who may want to go visit the site and they've kind of Cobalts kind of pioneered the the let's call it crowd source.
pen testing space and really kind of set the mark there. So many other things though caroling you both involved with OAS. Are you not?
Yep? You mentioned Professor mom. Fantastic Mom right wife.
All right. Well, those are the best roles in like that's what yeah, so just a great friend. So it's good to have you here Carolyn we have been following or getting reports from you now, probably three or four years at least on the annual Cobalt state of pen testing report.
And I think the new one is out for 2020 three. And we're thrilled to have you come on here and tell us all about it. I'm so proud of this report.
I've been involved in writing and helping and contributing to this research report since the initial version in 2019. So this is our fifth annual the thing about Cobalt is we do a lot of pen testing sometime in 2023. We will actually deliver our 10,000 pen test and we have really cool data a bunch of really cool data the 2023 annual state of pen testing report includes data from the more than 3,000 pen tests that we conducted in the year 2022.
So that's across web and API and mobile and network and Cloud configurations. We've got a data pool just for 2022 of more than 16,000 findings in addition to Of that Cobalt customer manual pentas data. We also conduct a survey.
So we surveyed a thousand Global Security Professionals. Who were not Cobalt clients? So it's really important to us to get kind of the Cobalt client data-driven view as well as survey data from professionals who are living this life doing this work day by day and getting their perspective on what it feels like absolutely.
You know the beautiful thing about doing these annual reports is the cumulative nature of the of the data, right? I mean, it sounds like 2022 is a bank of year for you for collecting that data, but as we compare it to 2021 in 2020 and 2019 Etc you really you can start seeing patterns. Developing you start seeing Trends coming and going and ebb and flow of it.
It's it's fantastic. I'm obsessed with data you already to work with a data set of this scale is so exciting to me and this year one of the things that's highlighted in. The report is that three of the most common findings with potential for serious damage include stored cross-site scripting incorrect?
Insecure direct object references and outdated software versions and for folks who are interested in learning more about that. We include information on what are those what can an attacker do with those security vulnerabilities as well as what types of actions should organizations be taking in order to prevent those types of vulnerabilities from being existing and from being exploited? So look cross cross.
Excuse me. I'm getting Tongue Tied now cross-site scripting. Not new right?
We've seen this. It's it's been a Mainstay on oats forever and everything else. Outdated software still probably responsible for 80% Of breaches and incidents and because people don't have impatched or updated their software the middle one was new to me though insecure.
What I do are is the country um, and and I I goofed it as well insecure direct object references. So the idea is that attackers are bypassing authorization by changing a parameter. So they're pointing directly to an object in a database.
com slash Caroline. So if an attacker can supply input to a web app that then points to something directly in the database that is what's considered an insecure direct object reference. So with at the end of the day, it's an access control issue.
We recommend some of the similar things actually that we recommend for cross-site scripting which is validate user inputs and avoid these direct object references. And when you do do a direct object reference, make sure you're also doing an access control check to see if that user is actually authorized to access the thing that they're requesting. Got it, right interesting.
So I learned something new today. Yeah, it was, you know, it's very related. It was highlighted in the 2013 version of the owasp top 10, you know since 2003 we've had.
I don't know half a dozen versions and it was highlighted in that one. Although, you know, certainly it continues to be prevalent today. And when our pen testers are finding these types of issues.
They are often marking them as medium or high severity. So these these can really turn into a big deal. They can have potential for real damage.
Absolutely for sure. Caroline What do you what would you think? What was the biggest surprise for you coming out of this year's report?
So this year one of the things that we did a little differently with the survey is we kind of asked folks. So we we always have these two components component number one is the pentest data and the vulnerability data from the year before component. Number two is a survey and this year one of the things that we explored was.
All the tech layoffs and how that's affecting security and Tech professionals and we actually found that there's a difference between what folks are experiencing based on if they're located in the US or if they're located in Europe or the United Kingdom. The biggest takeaway is that layoffs seem to be affecting us folks. more so but that being said teams across the globe are constrained and everyone is especially in a year like 2023 being asked to do more with less love.
Yeah. You know, it's interesting though. I I had a good conversation on this subject.
I think it was yesterday. You know the magic of recording, who knows but it was it was recently. and I I think for so many of our colleagues in the tech space Caroline who maybe you've only been in tech for 10 years or less they've known nothing but excuse my language fat times Right Beast or famine war or peace time?
Right. These are different modes of being but it's just that well, it's the cycle. It's the circle of life is Disney would say right this is the cycles of how these things go, but what we can't lose fact what we can't lose track of is two things number one even with all of these layoffs when you look at the size of these tech companies measured by their employees by number by number of employees.
The amount of growth that we've seen in the last two or three years. And X the United layoffs were seeing right now. Yep, right.
So yes, it's sucks. If you were one of the people laid off and hopefully you found another job and if you have skills, you probably have hopefully but we shouldn't I'm afraid people get too wound up in oh my God. This is this war is going on and there's this and that's what a terrible terrible time to be alive.
It's still a great time to be alive and there's still a lot of great stuff coming up and happening right now that I think it get us all excited. Number two. I and this is an interesting.
I read an article. I forget if it was in the Journal of the times, but that They're calling it The Great rebalancing. Right, so we went through the great resignation.
Yes during covid, right? Everyone said, ah, I don't need it here. I'm out of here.
I'm gonna work from wherever I want do whatever I want because everybody wants me. I've got pen testing skills. I've got cyber skills.
I've got developer skills. The world is my oyster and and you had companies throwing money. I don't care.
You want to work in Montana working my time, Idaho. Great, right. I'll pay you whatever you want.
I need you. Most of those jobs went to tech companies right to a hiring these people. Now though with the tech companies cutting back a little bit other companies that we don't think of as tech companies, but every company's attack company today.
Yes, okay are getting back are getting back into the game and they're able to hire cybersecurity people and developers and devops engineers and srees and all these folks that they need to run their businesses and their business is frankly have not been a sensitive to what happened to Silicon Valley Bank and some of these other things that are so affected the tech sector How's that I couldn't agree more. Okay context right exactly. As you said you look at the growth of some of these companies over the past two or three years some of the almost absurd growth in some cases and and it's already Crossing even even in state of pen testing every year we try and kind of put our pen test and vulnerability data next to Perspectives from individuals in the field and what's affecting them?
In 2023. We asked folks about the impact of layoffs. In 2022, we ask folks about the impact of the great resignation and you can see this cyclical nature.
Yeah, you know one year. I've been closer leaving for tons of money great opportunities and then the next year, you know folks are finding that the roles are being eliminated. So I think that I think that makes sense.
I also think that We have a little bit of room to improve in terms of cyber security talent management on both sites. I think we have an opportunity to improve in terms of the way that we hire and we also have an opportunity to improve in terms of how candidates represent themselves. I think that right now that's a little messy and it can be really difficult on both ends.
But at the end of the day, I actually firmly believe that there's a bunch of jobs and there's a bunch of people now the matching is challenging but Sure, this field there's just gonna be more software. It's not getting more secure in any sort of matching rate at the rate at which rowing and exploding cyber security is gonna evolve and it's gonna continue to need people working in this field and solving these problems that we haven't been able to solve for decades and I don't know that we'll ever be able to solve them but we're better. Yeah, I mean look to me the poster child for this Caroline is AI.
If there's one silver Shining Light in the tech world right now, it's AI. There's money being thrown on it. Like it's a gold rush everyone.
You can't walk more than three feet without tripping over a generator of AI. You know question or topic. Yeah.
And and what's the one thing that is scaring the crap out of people about AI security that's exactly right. That's exactly right with every next new exciting expensive shiny object comes security challenges. And on that point.
I actually think that one of the areas that's often overlooked when it comes to Ai and cybersecurity is Who's paying attention to the protection of data that's going into the AI? Well, you just saw the Samsung. I think if it was an I apologize but 99% sure was Samsung they were doing something with AI to help with their analysis or whatever and they uploaded their information into chat GPT all of it.
And it then became part of public, you know. People are just putting stuff in there. Right?
It's week. He's not thinking about it. We forget where the data goes that we put places and some people, you know are putting sensitive proprietary mentioned private data There was a big.
at the US government level very very confidential documents have been leaked and I don't have any sort of insight into how that happened, you know, but one might imagine that someone just like Popped it into something somewhere. I mean, you know people are just putting data in. You know with not recognize, you know, so 100 years ago in law school Caroline.
I had my con law professor and he said that when it comes to human rights when it comes to the balancing of Rights even like the abortion issue. He said technology always races ahead of the Law's ability. To to regulate it to normalize it to balance it right and so he always felt that like Roe v.
Wade was a middle ground to when we we'd have technology of artificial wombs and you wouldn't have an abortion. You would do an artificial rumors or something. Whatever, but it's the same thing in security technology races out ahead.
And then there's a lag until the security. Catches up to it. And I think that's kind of where we are with AI in these early days of this, you know generative AI stuff is Securities lagging because we're so busy kind of exploring the frontier.
We don't you know, and whether you believe this letter with Elon Musk and these folks that I don't believe progress stops for nomad or security. Right. It's just going to keep going but we do have to we'll have to catch up.
Absolutely. And it's AI. It's the metaverse.
It's another self driving Vehicles. You know, it's expanding in all these. Directions and some of them are a little more successful than others right AI maybe is doing a little better than folks thought the metaverse was going to do but these all remain relatively unexplored Realms as far as normal and practice security and I think the law a little bit like security one of the things that I think is in common actually in these two very very different fields.
Is there both incident based right law gets written based on basically an incident two people with a post, you know, two parties with opposing opinions a judgment is made, you know in security incidents happen. And then action gets taken decisions get made and so the stuff just hasn't happened yet or it hasn't we haven't had the internet. Right, we're early and that's so exciting.
But it's also you know, no scary look scary. I'm not really inherently risky. Yeah, it is.
So has AI kind of found this way into the pen testing report this year at all it you know this year, you know, one of the things that we've been kind of brainstorming about is with this Trove of data, you know how might we actually feed ML and AI models going into the future, but that's not the direction. We're currently taking. It'll be interesting.
It would be cold. Well, maybe it won't be so they'd be cool to upload all this into a generator of AI. What do you see what it it kicks out with you, but he we just had this conversation.
Maybe not a good idea this year Caroline. We're about out of time. I want to thank you for coming on as always.
It's great seeing you. I will see you in about two weeks or so and I say, yes, we will can't wait for people who want to go download the report. io slash blog call you slash blog.
You'll find everything right there. All right. It's so good seeing you Carolyn Wong Carolyn want one of my one of my Idols almost insecurity.
I feel like I've known her since she was this little but it's so great to see you. I'll see you soon. Thank you so much.
io slash blog Go download the Cobalt state of pen testing report 2023. We're gonna take a break on text strong. We'll be right back.