Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Thousands of Gaza children face imminent deaths under the siege of Israel: United Nations | Israeli-Palestinian conflict news

Hazy Hawk Exploites DNS Records hijack CDC to hijack CDC, the corporate domain for malware delivery

Coventry Building Society Arena is partner with Planet

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Key insights from the 2025 Pentest Report
Identity

Key insights from the 2025 Pentest Report

userBy userMay 20, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 20, 2025Hacker NewsPenetration tests/risk management

In the newly released 2025 Pentest Report, Pentera investigated 500 CISOs in Global Enterprise to understand the strategies, tactics and tools it uses to address thousands of security alerts, persistent violations, and growing cyber risks. The findings reveal a complex picture of progress, challenges, and changing ways of thinking about how businesses approach security testing.

More tools, more data, more protection… No guarantee

Over the past year, 45% of businesses have expanded their security technology stack, and organizations now manage an average of 75 different security solutions.

However, despite these layers of security tools, 67% of US companies have experienced violations in the past 24 months. The growing number of tools deployed has some impact on the organization’s day-to-day operations and overall cyber attitude.

It seems clear, but the findings tell a clear story. More security tools will improve your security attitude. However, there are no silver bullets. Among organizations with less than 50 security tools, 93% reported violations. As stack size increases, that percentage drops steadily, dropping to 61% of people using more than 100 tools.

Alert fatigue is real

The backstage of a large security stack is that CISOs and their teams must compete with a larger influx of information. Enterprises, which manages over 75 security solutions, face an average of 2,000 alerts per week. Compared to organizations with smaller stacks, they are twice the volume, and those with more than 100 tools receive over 3000 (three times the alerts).

This places a greater emphasis on effective prioritization. Otherwise, critical threats could be buried in the sea of ​​alerts. In this environment with high alert volumes and short time to triage, organizations benefit most when they can test frequently exploitable gaps, so they know which issues are really important before threat actors first find them.

Acquiring software-based pen tests

Trust in software-based security testing is growing rapidly. Just five or ten years ago, many companies never allowed automated tools to run pentests in their environments for fear of causing a shutdown, but emotions are changing.

As CISOS continues to recognize the benefits of software in scaling adversarial testing and maintains a ever-changing IT environment and pace, software-based pen testing is becoming the norm. Today, more than half of companies use these tools to support in-house testing driven by the need for reliable and scalable continuous verification strategies. Today, 50% of CISOS cite software-based pen testing solutions as the main way to uncover exploitable gaps.

Insurance providers become unexpected influencers

Beyond internal management and boards, an incredible new power is shaping security strategies, namely cyber insurance providers. 59% of CISOs admitted that they implemented at least one cybersecurity solution that they had not previously considered as a result of cyber insurers. It is a clear indication that insurers are proactively prescribing ways to reduce it, not just pricing risks, and reshaping the security priorities of companies in the process.

Low confidence in government support

Government agencies such as CISA (USA) and ENISA (EU) play a key role in threat visibility and coordination, but government trust in cybersecurity support is surprisingly low.

Only 14% of CISOs who believe the government is adequately supporting private sector cyber agendas, while 64% feel that government efforts are not recognized but insufficient. 22% believe they can’t rely on the government at all for cybersecurity help.

To benchmark your organization’s pentest practices, budgets and priorities for other global companies, register for a webinar on May 27, 2025 where senior security analysts discuss key findings. Or get the full state of the 2025 Pentest Report and see all your insights!

Note: This article was written and contributed by Jay Martane, a field stool at Pentera.

Did you find this article interesting? This article is a donation from one of our precious partners. Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEU reaches initial deals to lift sanctions in Syria: Report | Political News
Next Article BINGX AI Evolution begins: a $300 million vision for building the future of AI-powered cryptography
user
  • Website

Related Posts

Hazy Hawk Exploites DNS Records hijack CDC to hijack CDC, the corporate domain for malware delivery

May 20, 2025

Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections

May 20, 2025

Sidewinder hit South Asia with old office flaws and custom malware

May 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Thousands of Gaza children face imminent deaths under the siege of Israel: United Nations | Israeli-Palestinian conflict news

Hazy Hawk Exploites DNS Records hijack CDC to hijack CDC, the corporate domain for malware delivery

Coventry Building Society Arena is partner with Planet

TrustCloud raises $15 million, led by ServiceNow Ventures & Cisco, reinvents enterprise GRC with AI-driven risk automation

Trending Posts

Thousands of Gaza children face imminent deaths under the siege of Israel: United Nations | Israeli-Palestinian conflict news

May 20, 2025

Iran’s Khamenei slumps ‘nonsense’ US nuclear demands | Nuclear Weapons News

May 20, 2025

EU reaches initial deals to lift sanctions in Syria: Report | Political News

May 20, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TrustCloud raises $15 million, led by ServiceNow Ventures & Cisco, reinvents enterprise GRC with AI-driven risk automation

Elon Musk promises to lead Tesla for the next five years amid challenges and optimism

CATL, the world’s largest EV battery manufacturer, will surge 16% with its biggest IPO of 2025, Hong Kong debut of $4.6 billion

BINGX AI Evolution begins: a $300 million vision for building the future of AI-powered cryptography

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.