13 Sep 10 Hot Penetration Testing Companies To Watch In 2020
Ethical hacking is a skillset and a mindset
– Steve Morgan, Editor-in-Chief
Sausalito, Calif. – Sep. 13, 2020
Why? “Because you don’t know if the defenses you’ve put in place are actually working,” adds Sehgal, an expert pen tester with more than 16 years of network security experience.
Penetration testing, also known as pentesting or ethical hacking, is the authorized simulation of cyberattacks on IoT devices, networks, software programs, users, and web applications, in order to evaluate the security of a system.
No matter how secure you might think a network is, you really don’t know until it’s been hacked. So you might as well call in the pentesting troops before the cybercriminals get to it.
Cybercrime TV: 30,000 Foot View of the Pentesting Market
Interview with Seemant Sehgal, founder & CEO at BreachLock
Who’s a pentester?
“Hacking is not really a skillset, it’s a mindset,” says Sehgal. He offers up Kevin Mitnick, often referred to as the world’s most famous hacker, as a historical example given the practice of ethical intrusion dates to phreakers in the 1970s.
While today’s pentester may have earned a technical certification such as the CEH (certified ethical hacker), they must also possess a knack for cat and mouse play and advanced social engineering skills.
“Cybersecurity can be a very crowded market,” notes Sehgal, and that definitely goes for pentesting. He explains three types of companies: technology centric or automated vulnerability scanning; bug bounty or crowdsourced services; boutique firms selling man hours.
Hot Pentesting Companies
Who’s who in the penetration testing space? Here’s 10 hot companies the editors at Cybercrime Magazine are watching in 2020, and you should too.
- BreachLock, New York, N.Y. Penetration Testing as a Service powered by certified hackers and artificial intelligence. comprehensive, continuous pentesting and vulnerability scanning with actionable results for your public cloud, applications, or networks.
- Bugcrowd, San Francisco, Calif. Crowdsourced security offers a new solution for retaining, matching, and deploying pen test talent to fill the gaps created by an increasingly resource-constrained market. Rapid provisioning, and high quality, immediately actionable insights for compliance-based pentesting.
- CrowdStrike, Sunnyvale, Calif. Penetration Testing Services simulate real-world attacks on different components of your IT environment to test the detection and response capabilities of your people, processes and technology and identify where vulnerabilities exist in your environment.
- HackerOne, San Francisco, Calif. Redefine the way you respond to vendor security assessments and compliance needs with hacker-powered security. A creative, community-led approach to pentests to give you more coverage, instant results, and seamless remediation workflows all in one platform.
- ImmuniWeb, Geneva, Switzerland. On-Demand delivers scalable, rapid and DevSecOps-enabled web application penetration testing with tailored remediation guidelines and zero false-positives SLA. It leverages award-winning AI technology to augment, intensify and accelerate web app pen testing.
- Mitnick Security, Las Vegas, Nev. Improve your security posture with the ultimate in security services, penetration testing. Alongside a team of whitehat hackers, Kevin Mitnick will work with you to plan a customized attack, execute the hack, and provide prioritized recommendations for moving forward.
- Offensive Security, New York, N.Y. Labs designed to allow security and IT professionals to learn hacking techniques, sharpen their security and pentesting skills, and get a sense of the experience of being enrolled in OffSec’s sought-after certification programs.
- ScienceSoft, McKinney, Texas. Complete penetration testing services designed to pinpoint system vulnerabilities, as well as flaws in application, service and OS, loopholes in configurations, and potentially dangerous non-compliance with security policies.
- SecureLayer7, Maharashtra, India. A holistic approach to perform penetration tests that not only discover security vulnerabilities, but also find business logic vulnerabilities along with security checklists based on industry standards, including OWASP Top Ten, PCI Compliance, and NIST 800-53.
- Synack, Redwood City, Calif. Test the smart way with the right combination of human and artificial intelligence. The Synack Crowdsourced Security Testing Platform provides the industry’s most comprehensive, continuous penetration test with actionable results.
Cybercrime Magazine will be expanding our coverage of penetration testing and this list in 2021.
– Steve Morgan is founder and Editor-in-Chief at Cybersecurity Ventures.
Sponsored by BreachLock
Affordable, Smarter and Scalable Cyber Security Testing
BreachLock™ offers a SaaS platform that enables our clients to request and receive a comprehensive penetration test with a few clicks.
Our unique approach makes use of manual as well as automated vulnerability discovery methods aligned with industry best practices.
We execute in-depth manual penetration testing and provide you with both offline and online reports. We retest your fixes and certify you for executing a Penetration Test. This is followed up with monthly automated scanning delivered via the BreachLock platform. Throughout this process, you have access to the platform and our security experts who will help you find, fix, and prevent the next cyber breach.
BreachLock has offices in The Netherlands, London, New York City, and Wilmington, Del.