Pro-tip: do not contractually require your vendor to have an external penetration test done daily unless you are prepared to cover the hundreds of thousands of dollars it would cost. Do other vendors sign contracts without reading them?

Sep 19, 2020 · 2:16 AM UTC

1
1
Replying to @bilcorry
Cron nmap might be sufficient for their definition of pen test. Worth asking if they’re seeking continuous monitoring or something else.
1
1
Oh, I’m sure they meant scanning, but it wasn’t what they wrote :)
1