4 ms·
This seems like a poor approach if you are really serious about the security of your data. Proper pen testing encompasses more than a single app you may be deve
by level3 11y ago
This seems like a poor approach if you are really serious about the security of your data. Proper pen testing encompasses more than a single app you may be developing.
1) A developer can only help secure your code base, not your entire infrastructure and company-wide security practices.
2) A single security-minded developer does not suddenly make the rest of your developers more security-minded (not to mention your non-developers).
3) Even the most security-minded developers may lack knowledge of specific security threats. They are primarily focused on development, not keeping up on every new vulnerability or attack technique.
I agree that cost may be an issue, but pretending that security needs can be solved by finding the right developers is pretty short-sighted.
- brianwawok 11y agoI think it is a more likely path to success then hiring a pen tester and hoping he finds all your bugs! Fortune 500 companies spend millions on pen testing and miss stuff. How much can you afford to spend for a startup, and what will your ROI be? I have nothing against pen testing. But it should be like your 7th line of defense. Not sure most startups have the other 6 figured out....