Demo Series 12 minJun 24, 2024

A Closer Look at Traditional Pentesting vs. Comprehensive PTaaS

Rather than waiting weeks or months to get a test started, standard PTaaS consolidates security testing capabilities on a remote platform so organizations can start tests faster. At Synack, we take it even further. This Cut to the Chase demo dives into the differences between…

Wade Lance Global Field CISO, Synack
Justine Salisbury Sr. Product Marketing Manager, Synack

Overview

Rather than waiting weeks or months to get a test started, standard PTaaS consolidates security testing capabilities on a remote platform so organizations can start tests faster. At Synack, we take it even further. This Cut to the Chase demo dives into the differences between traditional pentesting, standard PTaaS and Synack’s PTaaS while showcasing what makes the Synack PtaaS Platform stand out. Learn how customers can launch tests on-demand, customize reports and view remediation and vulnerability root cause analysis, all on one platform.

Full transcript

Read transcript

Hello, and welcome to Cut to the Chase. My name is Wade Lance. I'm the field CISO here at SYNNAC, and we're very excited to bring you the next installment of Cut to the Chase, where we talk about issues and processes that people are experiencing in cybersecurity today. Today's topic is going to be around penetration test as a service, PTAS, and Synapse version of PTAS versus traditional pen test. So if you've been curious about what PTAS is all about and

Synnac's take on that, we're gonna fill you in today. I'm joined today by Justine Desmond, who is a product marketing manager here at Synnac. Say hi, Justine. Hi, Wade. Well, it's now Justine Salisbury because I'm recently married, but thank you for the introduction. Absolutely. And I'm so glad you're here. So let's do a quick conversation and then we'll turn it over for a quick demo of some of the topics that we've talked about. So for folks that have heard about penetration test as a service,

for most organizations, it pretty much falls into a couple of categories. It's a platform delivered capability where organizations rather than sending a couple of people with a couple of laptops on-site for a couple of weeks to do a penetration test and then hand you a PDF of findings and what the processes were and then CSVs of, you know, listings of vulnerabilities and outcomes. PTAS tries to consolidate all this on a

platform delivered capability so that in most cases, the researchers are remote. And what it allows organizations to do mostly is to start tests much faster than they normally would, kind of optimize the process for assessment design and creation. And then also channel the vulnerabilities out to the correct people. Most of them have an RBAC engine so that the different application teams,

when a vulnerability is discovered in their environment, they get notification through the system. So that's kind of a basic difference between penetration test as a service versus traditional pen test. At SYNNAC, we do it a little differently. And our thoughts on this have been, we like the acceleration in PTAS. We like some of the automation, but you have to be careful about just automating an old school methodology and just doing

mediocre pen tests faster. So what we do at SYNNAC is we use our platform to provide access to fifteen hundred of the best security researchers in the world so that you're actually getting researchers who are skills aligned to this tech stack that they're analyzing. This allows for tier one researchers to go very deep into the environment and find the kind of vulnerabilities that are human exploitable complex environments,

it's a real game changer. The other part about the process is that it gives us a way to not just channel the vulnerabilities out to the various team members, say application teams, infrastructure teams, cloud migration teams, but it also allows us to do remediation retest. We say this all the time here at SYNACT. Penetration testing is not about finding vulnerabilities. It's about demonstrating that you don't have vulnerabilities.

So when we find vulnerabilities, we wanna work with our customers to manage the remediation of those by doing the retest of that. So we identify the vulnerability, application teams, infrastructure teams, they remediate that or patch the vulnerability and then we drive a retest to it. And this is all automated through the platform, which is a huge value for organizations who are trying to manage their risk traditionally around internet facing mission critical,

change rate environments where this kind of testing is super valuable. And then I guess the last thing I would say about Synapse version of PTAS is that one of the things that we are able to do on the platform, we've been doing platform delivered security testing for over a decade now, and we appreciate the rest of the market waking up to the value of platform delivered pen test. But when part of what we do is to look across the tests that we're doing and the remediation processes and help

organizations understand what trajectories are they on? What are the trending that we're seeing? Where are they getting better? Where are they struggling? And this allows security organizations to get a level above the individual pen tests and look across the organization and understand their risk. And it really becomes a business enabler at that point, helping security organizations focus their spend on the most important things that are gonna have the biggest impact and allow the business to take advantage of opportunities in the space.

So that's enough out of me. Let's jump over to Justine and she's gonna show you a couple of these concepts in the Sync platform. Thanks so much, Wade. So this is the Sync platform that I'm showing right now. This is the homepage where we have our exploitable vulnerabilities, suspected vulnerabilities, remediation status, and other key metrics. But what we're gonna start with today is our assessment creation wizard. So how do you start,

using self-service to create your own assessments in the Synact portal? So as you can see here, it's just a quick click of the button. You select your assessment type. So we have web application testing, host or network testing, and API testing. And then there's a number of steps here from general information to scope, to test plan, to different authentication that you need to provide, scheduling, scan controls, rules of engagement, additional information, known vulnerabilities,

so we're not duplicating and finding what you already know about, any files that need uploading, and then review and confirmation. So this is a great way to just create assessments within minutes, and launch them immediately, which is very different from traditional pen testing, which requires, days or weeks or sometimes even months, advanced notice to start. And I think one of the things that our customers consistently give us good feedback about this capability is that rather

than doing email, word documents back and forth and different people, there's a unified place for their teams and the Synact teams to work together to create assessments. And it's just a much faster process with fewer mistakes. That's right. And then we have our vulnerabilities tab. So these are any and all vulnerabilities that are reported through those assessments. So those all appear here. And so we have our exploitable vulnerabilities, which are any vulnerabilities that have gone through our

triage process and we've found to be exploitable. And then we have suspected vulnerabilities. And suspected vulnerabilities are any vulnerabilities that are found by our scanner, Smart Scan. And then as you can see here, those are also triaged. So those are triaged by the SRT. So here, there's sixteen folds, some triage in process. And then, based on that triage, they'll be found not exploitable or exploitable. And then if they are found to be exploitable by the SRT,

they go they appear here in the exploitable vulnerabilities tab. And so in terms of, how to remediate these vulnerabilities, you can actually change the status on the right, and request a patch verification automatically to the researcher that initially submitted that vulnerability. So that's a great way, to just efficiently make that retest request right from the portal, and see whether you've successfully remediated that vulnerability. And then here you can see the status of different

vulnerabilities across your whole attack surface. So this is what Wade mentioned, more of getting to the root cause, trying to see the bigger picture of what's happening. So you can see your total number of exploitable vulnerabilities here. You can also see it by CVSS score. You can see the total number of suspected vulnerabilities that have been found and, their status as well, high, medium, low, critical, And then you can see the remediation status. So you can see how many of these bones you've remediated.

You can also see the remediation time frame by CVSS score as well. So it's critical, high, medium, low. You can see how efficiently your team is remediating those vulnerabilities. And you can see the number of times that they've successfully remediated those bones on the first attempt. So that's patch efficacy. You can also see the types of bones that are reoccurring over time. So here we have cross site scripting that appears to be appearing about twenty percent of the time.

So that could be something to look into. Your developers might need some more training on how to prevent that particular type of vulnerability. So this is an area where customers get really excited because, you know, without using platform delivered security testing, it's very hard to get understanding of which teams are struggling to manage important vulnerabilities in critical infrastructure. And so when we can communicate back to them, hey, it's taking a very long time to fix these really important vulnerabilities in mission critical infrastructure,

then teams know where to focus their efforts. And it allows security teams to inform senior management in metrics, hey, we're doing a great job. The time that vulnerabilities stay active in our environment now is very short and we've got metrics to demonstrate that we're focused on the right things becomes very popular in board meetings and in leadership meetings to show that the priority is in the right place. Awesome. And just lastly, I wanted to show our reports tab. So this is our reports tab.

You can generate a report about any of this data. So an executive summary report or a custom report. You can decide the frequency. You can decide who to send it to, maybe the senior leadership on your team. You can decide which severity. So maybe you only want the critical or high vulnerabilities to be sent over and prioritized, and you can also see vulnerability status. And you can measure your progress over time with our ARS

score so you can understand how you're improving. You can see here an industry comparison. You can see the scores stayed pretty close to eighty, but you can see any fluctuation in the ARS score and then use that to track how you're doing as a company compared to others in your industry or previous assessments. And that about wraps it up. Thank you so much for your time,

and hope you enjoyed our talk today on PTAS versus traditional pen testing and what SYNNAC has to offer. Thanks, Justine.

Speakers

Wade Lance

Synack

Global Field CISO

Justine Salisbury

Synack

Sr. Product Marketing Manager

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.