3 ms·
A lot of their "cybersecurity" revenue does indeed stem from advisory and risk assessment oriented work. They still have technical teams of varying quality that
by bitexploder 9y ago
A lot of their "cybersecurity" revenue does indeed stem from advisory and risk assessment oriented work. They still have technical teams of varying quality that perform "penetration testing", though. Often the follow up and methodology for any risk assessment is to leave an executive with strategic recommendations. Many of these recommendations are the actual technical work. No way a Big 4 sends technical, even heavily technical, work to some other firm. They just say, "yes, we do that".
It is the same with any assessment or consulting. We always try to leave recommendations, strategic and tactical, which advise them on next steps. Often, those next steps involve us helping them with more assessment work, directed at the most security sensitive areas to maximize usage of often limited security budgets. What will get them hacked next, basically.
Smaller firms with more technical staff definitely shy away from risk assessment and compliance work because it is, honestly, repetitive and boring. But, it also drives a tremendous amount of hard technical work into any firm because if you can't sell someone a pen test or technical assessment after doing advisory work you aren't very good at things.
Sorry if that sounds cynical or like "everyone needs more of our services and pen testing", but that is the model. It is also why boutiques exist. We don't just give brain dead "yep, you need pentesting, and it is going to be expensive" recommendations. We tailor it and focus on what the customer actually wants/needs. Whereas, a big4 tends to rotate consultants and lose knowledge unless it is staff aug. The relationship and understanding engineer teams really matters when you want to do the most interesting assessment work AND provide value to the customer and not just "sell them pen tests" :)