By Dave Woodhouse May 03, 2021
Maximising penetration test value for clients: Why threat modelling, proving exploitability and demonstrating impact matters.
Threat modelling and proving exploitability of issues in the context of the threat model is key to gaining maximum value from a penetration test and ensuring that issue criticality levels are not misclassified. This post details how and why correctly applying a threat model can significantly alter the criticality rating of an issue even though the technical risk hasn’t changed and how demonstrating exploitability in the threat model context can help inform where resourcing for mitigations could be applied for best effect.