Penetration Tests: useful, pointless, harmful, required, ineffective? – Phillip Wylie – ESW #398
Penetration tests are probably the most common and recognized cybersecurity consulting services. Nearly every business above a certain size has had at least one pentest by an external firm.
Here's the thing, though - the average ransomware attack looks an awful lot like the bog standard pentest we've all been purchasing or delivering for years. Yet thousands of orgs every year fall victim to these attacks. What's going on here? Why are we so bad at stopping the very thing we've been training against for so long?
This Interview with Phillip Wylie will provide some insight into this! Spoiler: a lot of the issues we had 10, even 15 years ago remain today.
Segment resources:
- Phillip's talk, Optimal Offensive Security Programs from Dia de los Hackers last fall
Announcements
Identiverse 2025 is returning to Las Vegas, June 3-6. Hear from 250+ expert speakers and connect with 3,000+ identity security professionals across four days of keynotes, breakout sessions, and deep dives into the latest identity security trends. Plus, take part in hands-on workshops and explore the brand-new Non-Human Identity Pavilion. Register now and save 25% with code IDV25-SecurityWeekly at https://www.securityweekly.com/IDV2025
Guest
Phillip Wylie is an offensive security professional with over 21 years of cybersecurity experience. He is also a former Dallas College Adjunct Instructor where he taught pentesting and web application pentesting. Phillip has diverse experience in multiple cybersecurity disciplines, including network security, application security, and pentesting. As an offensive security professional with over a decade of experience, he has conducted pentests of networks, Wi-Fi networks, and applications.
Phillip’s contributions to the cybersecurity industry extend beyond his work as a pentester. He is the concept creator and co-author of The Pentester Blueprint: Starting a Career as an Ethical Hacker, a highly regarded book inspired by a lecture he presented to his class at Dallas College, which later became a conference talk. Phillip previously hosts The Phillip Wylie Show and The Hacker Factory Podcast. Lastly, he is a frequent speaker, keynote speaker, international speaker, and workshop instructor.