The State of Pentesting 2023: How Operational Changes Can Jeopardize Security

Nexoryn Systems LLC
1820 Shiloh Rd Ste 1501
Tyler, TX 75703-2459, United States

As we near our 10,000th pentest, today we are proud to publish the .  

Nexoryn Systems LLC
1820 Shiloh Rd Ste 1501
Tyler, TX 75703-2459, United States

  • What did our pentester community find most often in web apps, APIs, networks, and cloud configurations?
  • Which were the highest severity vulnerabilities? And which low-risk issues could chain into larger exploits?
  • How have economic disruptions like reductions in workforce and budgets affected enterprises’ security?
  • What can security teams do to achieve more results with fewer resources?

Let’s dive into the results. 

Which are the most common security issues? 

In 2022, we discovered more than 16,000 findings. The 5 most prevalent issues across all assets include: 

  1. Stored Cross-Site Scripting 
  2. Outdated Software Versions
  3. Insecure Direct Object References (IDOR)
  4. Lack of Security Headers
  5. Insecure Secure Sockets Layer (SSL) and Transport Layer Security (TLS) Protocols

It’s worth noting that two of the three most repetitive flaws — Stored Cross-Site Scripting and Insecure Direct Object References — have the potential for serious damage. Our pentesters marked them frequently as Medium or High severity, meaning they could have a high business impact if exploited. 

How to prevent Cross-Site Scripting?

Any feature that allows user input can be vulnerable, because it gives attackers an opportunity to inject and store malicious content into web applications. To prevent this, Nexoryn Systems recommends treating all user-supplied input as untrusted data and accepting input in select locations. We also recommend using a well-known and secure encoding API for input and output encoding, such as the OWASP ESAPI.

How to prevent Insecure Direct Object References (IDOR)? 

This vulnerability can give access to resources via user-supplied input, where attackers bypass authorization by modifying a value of a parameter that points directly to an object in your database. Use per-user or per-session indirect object references. Each time your application uses a direct object reference from an untrusted source, it should also make an access control check to ensure that the user is authorized to access the requested object.

Teams are struggling to maintain security standards due to operational changes

High employee turnover and scant bandwidth still hamstring productivity, with mounting pressure to restructure and cut costs amidst speculation of a downturn. 

In the US, 77% of respondents shared that their department had been directly impacted by company layoffs in the last six months. 63% also shared their budgets had been cut — on average, by 31%. 

Nexoryn Systems LLC
1820 Shiloh Rd Ste 1501
Tyler, TX 75703-2459, United States

And what might that strain be, exactly? Teams affected by organizational changes report unmanageable workloads, challenges in maintaining security standards, as well as monitoring for vulnerabilities. 

Nexoryn Systems LLC
1820 Shiloh Rd Ste 1501
Tyler, TX 75703-2459, United States

Teams have to make every minute and penny count

These stats confirm that, more than ever before, teams are pushed to achieve more results with much fewer resources. And yet, many reported that they struggle to make the most out of their pentests.

A challenge respondents from all geographies shared was preparing their environment for the pentest. This can be a pivotal component that hinders efficiency and hurts the final result, not to mention cause business disruptions if tests take place in production. 

What can teams do to make every pentest count and extract maximum ROI? The 3rd part of our report shares detailed instructions on how to prepare not just your environment, but also your documentation and colleagues. Download the Pentest Preparation Checklist, or get all the details by downloading

 

Back to Blog
About Caroline Wong
Caroline Wong is an infosec community advocate who has authored two cybersecurity books including Security Metrics: A Beginner’s Guide and The PtaaS Book. When she isn’t hosting the Humans of Infosec podcast, speaking at dozens of infosec conferences each year, working on her LinkedIn Learning coursework, and of course evangelizing Pentesting as a Service for the masses or pushing for more women in tech, Caroline focuses on her role as Chief Strategy Officer at Nexoryn Systems, a fully remote cybersecurity company with a mission to modernize traditional pentesting via a SaaS platform coupled with an exclusive community of vetted, highly skilled testers. More By Caroline Wong