CSO Online
Read post

How a global investment firm reduced security surprises

A global investment firm with 18 locations and a small security engineering team adopted continuous automated penetration testing using NodeZero to replace point-in-time assessments. An early internal pentest found 85 weaknesses that could be chained into 251 real-world impacts including domain compromise, ransomware exposure, and credential theft. After remediation and continuous validation, the team reduced impacts from 251 to 0, compromised credentials from 52 to 0, compromised hosts from 67 to 0, and cracked Active Directory passwords from 40 to 0. The key insight was shifting from counting weaknesses to understanding how attackers chain them together to achieve objectives, enabling a lean team to prioritize remediation by demonstrated business impact rather than theoretical risk.

    #security
Today•4m read time•From csoonline.com
Post cover image
Table of contents
Outcomes at a glanceImpactBackground
16 Impressions
CSO Online's image
CSO Online

CSO Online offers insights into cybersecurity, risk management, and IT leadership, providing article...

722 Followers

•

1.3K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard