{"id":318,"date":"2021-05-05T00:22:00","date_gmt":"2021-05-05T00:22:00","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=318"},"modified":"2025-05-13T11:50:03","modified_gmt":"2025-05-13T18:50:03","slug":"does-pen-testing-still-make-sense-in-an-era-of-digital-transformation","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/","title":{"rendered":"Research Results: The Challenges With Pen Testing for Cybersecurity"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"664\" height=\"861\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\" alt=\"\" class=\"wp-image-319\" style=\"width:263px;height:auto\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png 664w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1-395x512.png 395w\" sizes=\"auto, (max-width: 664px) 100vw, 664px\" \/><\/figure><\/div>\n\n\n<p>Penetration testing is one of the most well-known tools security teams use to defend against attackers and keep their organizations secure. But it\u2019s also a technology from another century: penetration testing has its origins in the late 1960\u2019s.&nbsp;<br><br><a href=\"\/blog\/digital-transformation-demands-a-digital-risk-protection-strategy\/\">Does pen testing still make sense in an era of digital transformation<\/a>, where even the largest, most traditional companies are reinventing themselves to be digital-first businesses? The very same world where attackers take the path of least resistance to breach business data and applications, using weaknesses in overlooked and internet-exposed assets?<\/p>\n\n\n\n<p>We wanted to understand the answer to those questions, so we worked with Dark Reading to survey over 100 large organizations about their penetration testing practices and perceptions, to see what they truly think about pen testing effectiveness for the modern IT ecosystem. Short answer: respondents at these organizations think that pen tests have huge blind spots, are done too infrequently, and are too expensive to be very effective as a security solution \u2013 despite the fact that they rely on them for exactly that.<\/p>\n\n\n\n<p>We uncovered those insights (and more) by commissioning Dark Reading to survey security and IT professionals involved closely with penetration testing: from CISOs and CIOs to IT and security directors to security architects and pen test leads.&nbsp;<\/p>\n\n\n\n<p>Here are some highlights of what we uncovered:<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why do organizations pen test?<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>70% to measure the organization\u2019s security posture<\/li>\n\n\n\n<li>69% for breach prevention<\/li>\n\n\n\n<li>65% to ensure compliance with regulatory mandates<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The biggest concerns with penetration testing?&nbsp;<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>60% say they get only limited test coverage and have too many blind spots<\/li>\n\n\n\n<li>47% report that their penetration tests only help them detect known threats, not new or unknown ones<\/li>\n\n\n\n<li>44% described the cost-per-asset tested as being too high<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How much do organizations spend on pen testing annually?&nbsp;<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>12\/% spend more than $1 million<\/li>\n\n\n\n<li>8% spend $500,001 to $1 million<\/li>\n\n\n\n<li>10% spend 250,001 to $500,000<\/li>\n<\/ul>\n\n\n\n<p><strong>That\u2019s 30% of large organizations spending a quarter of a million dollars or more a year on penetration testing.<\/strong><\/p>\n\n\n\n<p>It\u2019s probably not that surprising to anyone in the security industry that there are so\u00a0<a href=\"\/blog\/pen-test-alternatives\/\">many concerns with penetration testing as a solution for securing organizations<\/a>. It\u2019s a bit more surprising that with all those shortcomings and with such a large price tag, organizations continue to count on them to ensure they are secure. Based on the results of the research, it seems clear that\u00a0<a href=\"\/solutions\/autopt.php\">penetration tests<\/a>\u00a0are simply not cut out for today\u2019s new and emergent threat landscape or digital transformation.<\/p>\n\n\n\n<p>Abandoning penetration testing may simply not be a viable approach for many organizations. But, every organization can get a great deal more value from their penetration testing investments by shifting a significant portion to an&nbsp;<a href=\"\/external-attack-surface-management\/\">external attack surface management (EASM)<\/a>&nbsp;solution. EASM platforms like the CyCognito platform provide a comprehensive, continuous, more cost-effective approach that will discover and help them secure their entire internet-exposed attack surface.&nbsp;<\/p>\n\n\n\n<p>Read the full report for additional findings and further detail on how the challenges with the cost, coverage, and cadence of penetration tests hinder their effectiveness in measuring security posture and preventing breaches.&nbsp;&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Does pen testing still make sense in an era of digital transformation where companies are reinventing themselves to be digital-first businesses?<\/p>\n","protected":false},"author":22,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,18,34],"class_list":["post-318","post","type-post","status-publish","format-standard","hentry","category-research","tag-attack-surface-management","tag-easm","tag-pen-testing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"Does pen testing still make sense in an era of digital transformation where companies are reinventing themselves to be digital-first businesses?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-05T00:22:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-13T18:50:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"664\" \/>\n\t<meta property=\"og:image:height\" content=\"861\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Raphael Reich\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Raphael Reich\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\"},\"author\":{\"name\":\"Raphael Reich\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/5fc71e29aa32c6153db0b1cbcfd395a7\"},\"headline\":\"Research Results: The Challenges With Pen Testing for Cybersecurity\",\"datePublished\":\"2021-05-05T00:22:00+00:00\",\"dateModified\":\"2025-05-13T18:50:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\"},\"wordCount\":522,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\",\"keywords\":[\"Attack Surface Management\",\"EASM\",\"Pen Testing\"],\"articleSection\":[\"Research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\",\"name\":\"Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\",\"datePublished\":\"2021-05-05T00:22:00+00:00\",\"dateModified\":\"2025-05-13T18:50:03+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png\",\"width\":664,\"height\":861},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Research Results: The Challenges With Pen Testing for Cybersecurity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/5fc71e29aa32c6153db0b1cbcfd395a7\",\"name\":\"Raphael Reich\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a187c2484d7ae7c4068cf1f26c507972?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a187c2484d7ae7c4068cf1f26c507972?s=96&d=mm&r=g\",\"caption\":\"Raphael Reich\"},\"description\":\"Was Vice President of Marketing at CyCognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/raphael-reich\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/","og_locale":"en_US","og_type":"article","og_title":"Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog","og_description":"Does pen testing still make sense in an era of digital transformation where companies are reinventing themselves to be digital-first businesses?","og_url":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/","og_site_name":"CyCognito Blog","article_published_time":"2021-05-05T00:22:00+00:00","article_modified_time":"2025-05-13T18:50:03+00:00","og_image":[{"width":664,"height":861,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png","type":"image\/png"}],"author":"Raphael Reich","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Raphael Reich","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/"},"author":{"name":"Raphael Reich","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/5fc71e29aa32c6153db0b1cbcfd395a7"},"headline":"Research Results: The Challenges With Pen Testing for Cybersecurity","datePublished":"2021-05-05T00:22:00+00:00","dateModified":"2025-05-13T18:50:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/"},"wordCount":522,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png","keywords":["Attack Surface Management","EASM","Pen Testing"],"articleSection":["Research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/","url":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/","name":"Research Results: The Challenges With Pen Testing for Cybersecurity | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png","datePublished":"2021-05-05T00:22:00+00:00","dateModified":"2025-05-13T18:50:03+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/COVER-pen-testing-1.png","width":664,"height":861},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/does-pen-testing-still-make-sense-in-an-era-of-digital-transformation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Research Results: The Challenges With Pen Testing for Cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/5fc71e29aa32c6153db0b1cbcfd395a7","name":"Raphael Reich","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a187c2484d7ae7c4068cf1f26c507972?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a187c2484d7ae7c4068cf1f26c507972?s=96&d=mm&r=g","caption":"Raphael Reich"},"description":"Was Vice President of Marketing at CyCognito","url":"https:\/\/www.cycognito.com\/blog\/author\/raphael-reich\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/318","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=318"}],"version-history":[{"count":4,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/318\/revisions"}],"predecessor-version":[{"id":1526,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/318\/revisions\/1526"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}