Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:43
Security testing is often framed as vulnerability hunting. But that’s not where most of the time goes.
In this clip, James Wickett breaks down how the majority of a security engagement — as much as 60–70% — is spent on application discovery and understanding system architecture. Only a small fraction is dedicated to actually exercising vulnerabilities. Report writing consumes even less.
The implication is operational inefficiency. When security teams spend most of their time just mapping authentication flows, authorization frameworks, and service relationships, vulnerability testing becomes secondary. That discovery tax limits scale.
By reducing manual discovery, some teams are compressing 40–80 hour engagements into four to six hours. The real acceleration isn’t in testing faster — it’s in understanding faster.
If your security program feels slow, the bottleneck may not be vulnerability analysis at all.
How much of your team’s time is spent finding issues versus figuring out how the system works?
Subscribe to our podcasts: https://securityweekly.com/subscribe
#AppSec #SecurityTesting #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
SOCIAL SHARE CARD GENERATOR