<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://cyber-security.com.cy/feed.xml" rel="self" type="application/atom+xml" /><link href="https://cyber-security.com.cy/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-06-05T18:00:15+00:00</updated><id>https://cyber-security.com.cy/feed.xml</id><title type="html">We find it first.</title><subtitle>Independent cyber security consultancy based in Cyprus. Penetration testing, API security reviews, Security Awareness trainings, Attack Surface Mapping, and more.</subtitle><author><name>Petros Soutzis</name><email>psoutzis@cyber-security.com.cy</email></author><entry><title type="html">Why Most Penetration Tests Don’t Actually Reduce Risk</title><link href="https://cyber-security.com.cy/blog/why-pentests-fail-to-reduce-risk/" rel="alternate" type="text/html" title="Why Most Penetration Tests Don’t Actually Reduce Risk" /><published>2026-05-20T00:00:00+00:00</published><updated>2026-05-20T00:00:00+00:00</updated><id>https://cyber-security.com.cy/blog/why-pentests-fail-to-reduce-risk</id><content type="html" xml:base="https://cyber-security.com.cy/blog/why-pentests-fail-to-reduce-risk/"><![CDATA[<p>Every year, plenty of organisations buy a penetration test, receive a thick PDF
full of findings, file it for the auditors, and change almost nothing about
their actual security posture. The test happened. The risk didn’t move.</p>

<p>If you’re spending real money on offensive security, it’s worth understanding
why that gap exists — and how to close it.</p>

<h2 id="a-report-is-not-an-outcome">A report is not an outcome</h2>

<p>The deliverable everyone fixates on is the report. But a report is just a
snapshot of what one tester found in a fixed window of time. The outcome you
actually want is <em>fewer exploitable paths into your environment</em>. Those are not
the same thing, and conflating them is where most engagements quietly fail.</p>

<p>A few patterns I see repeatedly:</p>

<ul>
  <li><strong>Findings with no owner.</strong> A vulnerability that isn’t assigned to a specific
team with a specific deadline will still be open at the next test.</li>
  <li><strong>CVSS as the only lens.</strong> A “medium” that chains into account takeover on a
payments flow matters more than a “high” on an internal box nobody can reach.
Business context beats raw scores.</li>
  <li><strong>No retest.</strong> If remediation is never verified, you’re trusting that a fix
worked — which is exactly the assumption a test is supposed to remove.</li>
</ul>

<h2 id="what-a-good-engagement-looks-like">What a good engagement looks like</h2>

<p>The mechanics of the test matter less than what surrounds it. The engagements
that move risk tend to share a few traits:</p>

<ol>
  <li><strong>Clear, attacker-style goals</strong> agreed up front — “can we reach customer
funds?” beats “scan everything.”</li>
  <li><strong>Findings prioritised by real impact</strong>, with attack chains spelled out so
engineers understand <em>why</em> something matters, not just that it scored high.</li>
  <li><strong>A working session with the people who’ll fix it</strong>, not a report thrown over
the wall.</li>
  <li><strong>A retest</strong> to confirm the fixes hold.</li>
</ol>

<blockquote>
  <p>The point of an offensive engagement isn’t to prove you can be hacked. It’s to
give your defenders a prioritised, verified list of things that will make the
next attacker’s job harder.</p>
</blockquote>

<h2 id="the-takeaway">The takeaway</h2>

<p>Before you book your next test, ask the provider one question: <em>what happens
after the report?</em> If the answer is “we send it and invoice you,” you’re buying
a document. If the answer involves prioritisation, a working session and a
retest, you’re buying risk reduction.</p>

<p>That difference is the whole game.</p>

<hr />

<p><em>Want a test that actually changes your risk?
<a href="/#contact">Get in touch</a>.</em></p>]]></content><author><name>Petros Soutzis</name><email>psoutzis@cyber-security.com.cy</email></author><category term="pentesting" /><category term="risk" /><category term="fintech" /><summary type="html"><![CDATA[A penetration test that ends with a PDF and a handshake rarely changes your risk. Here's what separates an assessment that matters from one that just ticks a box.]]></summary></entry></feed>