{"id":108652,"date":"2023-02-10T10:00:33","date_gmt":"2023-02-10T10:00:33","guid":{"rendered":"https:\/\/kasperskycontenthub.com\/securelist\/?p=108652"},"modified":"2023-03-27T16:33:53","modified_gmt":"2023-03-27T16:33:53","slug":"how-the-analyst-can-enhance-pentest","status":"publish","type":"post","link":"https:\/\/securelist.com\/how-the-analyst-can-enhance-pentest\/108652\/","title":{"rendered":"Good, Perfect, Best: how the analyst can enhance penetration testing results"},"content":{"rendered":"

Penetration testing is something that many (of those who know what a pentest is) see as a search for weak spots and well-known vulnerabilities in clients’ infrastructure, and a bunch of copied-and-pasted recommendations on how to deal with the security holes thus discovered. In truth, it is not so simple, especially if you want a reliable test and useful results. While pentesters search for vulnerabilities and put a lot of effort into finding and demonstrating possible attack vectors, there is one more team member whose role remains unclear: the cybersecurity analyst. This professional takes a helicopter view of the target system to properly assess existing security holes and to offer the client a comprehensive picture of the penetration testing results combined with an action plan on how to mitigate the risks. In addition to that, the cybersecurity analyst formulates a plan in the business language that helps the management team, including the C-level, to understand what they are about to spend money on.<\/p>\n

Drawing on Kaspersky’s expertise with dozens of security assessment<\/a> projects, we want to reveal the details of the analyst’s role on these projects: who they are, what they do, why projects carried out together by pentesters and an analyst<\/strong> are much more useful for clients.<\/p>\n

Who is an analyst?<\/h2>\n

\"\"<\/a>In general, an analyst is a professional who works on datasets. For example, we all know about financial analysts who evaluate the efficiency of financial management. There are more than one type of analyst in the field of information security:<\/p>\n