A Closer Look at Traditional Pentesting vs. Comprehensive PTaaS
Rather than waiting weeks or months to get a test started, standard PTaaS consolidates security testing capabilities on a remote platform so organizations can start tests faster. At Synack, we take it even further. This Cut to the Chase demo dives into the differences between…
Overview
Rather than waiting weeks or months to get a test started, standard PTaaS consolidates security testing capabilities on a remote platform so organizations can start tests faster. At Synack, we take it even further. This Cut to the Chase demo dives into the differences between traditional pentesting, standard PTaaS and Synack’s PTaaS while showcasing what makes the Synack PtaaS Platform stand out. Learn how customers can launch tests on-demand, customize reports and view remediation and vulnerability root cause analysis, all on one platform.
Full transcript
Read transcript
Hello, and welcome to Cut to the Chase. My name is Wade Lance. I'm the field CISO here at SYNNAC, and we're very excited to bring you the next installment of Cut to the Chase, where we talk about issues and processes that people are experiencing in cybersecurity today. Today's topic is going to be around penetration test as a service, PTAS, and Synapse version of PTAS versus traditional pen test. So if you've been curious about what PTAS is all about and
Synnac's take on that, we're gonna fill you in today. I'm joined today by Justine Desmond, who is a product marketing manager here at Synnac. Say hi, Justine. Hi, Wade. Well, it's now Justine Salisbury because I'm recently married, but thank you for the introduction. Absolutely. And I'm so glad you're here. So let's do a quick conversation and then we'll turn it over for a quick demo of some of the topics that we've talked about. So for folks that have heard about penetration test as a service,
for most organizations, it pretty much falls into a couple of categories. It's a platform delivered capability where organizations rather than sending a couple of people with a couple of laptops on-site for a couple of weeks to do a penetration test and then hand you a PDF of findings and what the processes were and then CSVs of, you know, listings of vulnerabilities and outcomes. PTAS tries to consolidate all this on a
platform delivered capability so that in most cases, the researchers are remote. And what it allows organizations to do mostly is to start tests much faster than they normally would, kind of optimize the process for assessment design and creation. And then also channel the vulnerabilities out to the correct people. Most of them have an RBAC engine so that the different application teams,
when a vulnerability is discovered in their environment, they get notification through the system. So that's kind of a basic difference between penetration test as a service versus traditional pen test. At SYNNAC, we do it a little differently. And our thoughts on this have been, we like the acceleration in PTAS. We like some of the automation, but you have to be careful about just automating an old school methodology and just doing
mediocre pen tests faster. So what we do at SYNNAC is we use our platform to provide access to fifteen hundred of the best security researchers in the world so that you're actually getting researchers who are skills aligned to this tech stack that they're analyzing. This allows for tier one researchers to go very deep into the environment and find the kind of vulnerabilities that are human exploitable complex environments,
it's a real game changer. The other part about the process is that it gives us a way to not just channel the vulnerabilities out to the various team members, say application teams, infrastructure teams, cloud migration teams, but it also allows us to do remediation retest. We say this all the time here at SYNACT. Penetration testing is not about finding vulnerabilities. It's about demonstrating that you don't have vulnerabilities.
So when we find vulnerabilities, we wanna work with our customers to manage the remediation of those by doing the retest of that. So we identify the vulnerability, application teams, infrastructure teams, they remediate that or patch the vulnerability and then we drive a retest to it. And this is all automated through the platform, which is a huge value for organizations who are trying to manage their risk traditionally around internet facing mission critical,
change rate environments where this kind of testing is super valuable. And then I guess the last thing I would say about Synapse version of PTAS is that one of the things that we are able to do on the platform, we've been doing platform delivered security testing for over a decade now, and we appreciate the rest of the market waking up to the value of platform delivered pen test. But when part of what we do is to look across the tests that we're doing and the remediation processes and help
organizations understand what trajectories are they on? What are the trending that we're seeing? Where are they getting better? Where are they struggling? And this allows security organizations to get a level above the individual pen tests and look across the organization and understand their risk. And it really becomes a business enabler at that point, helping security organizations focus their spend on the most important things that are gonna have the biggest impact and allow the business to take advantage of opportunities in the space.
So that's enough out of me. Let's jump over to Justine and she's gonna show you a couple of these concepts in the Sync platform. Thanks so much, Wade. So this is the Sync platform that I'm showing right now. This is the homepage where we have our exploitable vulnerabilities, suspected vulnerabilities, remediation status, and other key metrics. But what we're gonna start with today is our assessment creation wizard. So how do you start,
using self-service to create your own assessments in the Synact portal? So as you can see here, it's just a quick click of the button. You select your assessment type. So we have web application testing, host or network testing, and API testing. And then there's a number of steps here from general information to scope, to test plan, to different authentication that you need to provide, scheduling, scan controls, rules of engagement, additional information, known vulnerabilities,
so we're not duplicating and finding what you already know about, any files that need uploading, and then review and confirmation. So this is a great way to just create assessments within minutes, and launch them immediately, which is very different from traditional pen testing, which requires, days or weeks or sometimes even months, advanced notice to start. And I think one of the things that our customers consistently give us good feedback about this capability is that rather
than doing email, word documents back and forth and different people, there's a unified place for their teams and the Synact teams to work together to create assessments. And it's just a much faster process with fewer mistakes. That's right. And then we have our vulnerabilities tab. So these are any and all vulnerabilities that are reported through those assessments. So those all appear here. And so we have our exploitable vulnerabilities, which are any vulnerabilities that have gone through our
triage process and we've found to be exploitable. And then we have suspected vulnerabilities. And suspected vulnerabilities are any vulnerabilities that are found by our scanner, Smart Scan. And then as you can see here, those are also triaged. So those are triaged by the SRT. So here, there's sixteen folds, some triage in process. And then, based on that triage, they'll be found not exploitable or exploitable. And then if they are found to be exploitable by the SRT,
they go they appear here in the exploitable vulnerabilities tab. And so in terms of, how to remediate these vulnerabilities, you can actually change the status on the right, and request a patch verification automatically to the researcher that initially submitted that vulnerability. So that's a great way, to just efficiently make that retest request right from the portal, and see whether you've successfully remediated that vulnerability. And then here you can see the status of different
vulnerabilities across your whole attack surface. So this is what Wade mentioned, more of getting to the root cause, trying to see the bigger picture of what's happening. So you can see your total number of exploitable vulnerabilities here. You can also see it by CVSS score. You can see the total number of suspected vulnerabilities that have been found and, their status as well, high, medium, low, critical, And then you can see the remediation status. So you can see how many of these bones you've remediated.
You can also see the remediation time frame by CVSS score as well. So it's critical, high, medium, low. You can see how efficiently your team is remediating those vulnerabilities. And you can see the number of times that they've successfully remediated those bones on the first attempt. So that's patch efficacy. You can also see the types of bones that are reoccurring over time. So here we have cross site scripting that appears to be appearing about twenty percent of the time.
So that could be something to look into. Your developers might need some more training on how to prevent that particular type of vulnerability. So this is an area where customers get really excited because, you know, without using platform delivered security testing, it's very hard to get understanding of which teams are struggling to manage important vulnerabilities in critical infrastructure. And so when we can communicate back to them, hey, it's taking a very long time to fix these really important vulnerabilities in mission critical infrastructure,
then teams know where to focus their efforts. And it allows security teams to inform senior management in metrics, hey, we're doing a great job. The time that vulnerabilities stay active in our environment now is very short and we've got metrics to demonstrate that we're focused on the right things becomes very popular in board meetings and in leadership meetings to show that the priority is in the right place. Awesome. And just lastly, I wanted to show our reports tab. So this is our reports tab.
You can generate a report about any of this data. So an executive summary report or a custom report. You can decide the frequency. You can decide who to send it to, maybe the senior leadership on your team. You can decide which severity. So maybe you only want the critical or high vulnerabilities to be sent over and prioritized, and you can also see vulnerability status. And you can measure your progress over time with our ARS
score so you can understand how you're improving. You can see here an industry comparison. You can see the scores stayed pretty close to eighty, but you can see any fluctuation in the ARS score and then use that to track how you're doing as a company compared to others in your industry or previous assessments. And that about wraps it up. Thank you so much for your time,
and hope you enjoyed our talk today on PTAS versus traditional pen testing and what SYNNAC has to offer. Thanks, Justine.
No lines match that search.
Speakers
Synack
Global Field CISO
Synack
Sr. Product Marketing Manager
Watch next
1 min Feb 3, 2025 Synack & Microsoft Sentinel Synack, the premier Pentesting as a Service (PTaaS) platform, provides a direct integration to Microsoft Sentinel, a solution for intelligent security analytics, event management, threat detection,… 1 min watch
Demo Series 10 min Jan 24, 2025 Synack OSINT Testing: Take Action on Your Risk According to research, roughly 80-95% of cybersecurity breaches originate from Open Source Intelligence (OSINT). OSINT is often the first step malicious hackers take before planning their… Tim Nordvedt Synack 10 min watch
Demo Series 6 min Nov 19, 2024 Integrate ASM and Pentesting with PANW Cortex Xpanse and Synack In today’s evolving attack surface, offensive security testing and attack surface management (ASM) can no longer afford to be a siloed effort. To keep up with… Simon Harper Synack 6 min watch Next step
Run the test instead of evaluating the idea.
Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.


