I've been using a continuous penetration testing service for the last couple years against our public websites and the ROI looks pretty poor.
The "crowdsource your pen testing" model appears to incentivize freelancers that move quickly and find common issues that are repeated across many different sites/customers. For us, I haven't seen much evidence of them having success finding flaws that are complex or unique to our environment. That might be because we are awesome, but I suspect "shallow" testing might be an issue.
Seeing you've got hundreds of researchers signed up to test your site each year sounds great... until you start doing the math and realize each person is only spending an average of about 90 minutes, most likely repeating the work of their peers looking for quick hits.
Has anyone else purchased a continuous testing service, decided it wasn't worth it, and returned to dedicated testing engagements to either save money or receive more thorough testing?
Any offensive folk out there working these gigs & care to provide insight from the other side of the fence?
All feedback / guidance appreciated.
#redteam #PTaaS #pentest #pentesting #blueteam