Risk Response Strategies

As a pentester, it would be a mistake to assume that all vulnerabilities will be fixed on the client's side. From a purely economic point of view, a fix is not worthwhile if it causes higher costs than a criminal exploitation. Our finding could also be a business requirement for the target system or application, which management has explicitly decided on. For example, social network operators often choose not to automatically terminate a user session after the user has been inactive for a long period of time, even though this issue is listed as a vulnerability in penetration testing standards such as the OWASP Testing Guide. In terms of the usability of social networks, such a decision is also understandable, since the average usage time would presumably be reduced if users have to authenticate themselves again each time. However, from an IT security perspective, a missing session timeout is associated with risks. One threat scenario, among others, would be that third parties could perform actions on behalf of an absent application user. Basically, the following strategies are available to our client to respond to risks:

  • Risk mitigation: Countermeasures are taken for the risk.
  • Risk transfer: The risk is shifted, e.g., by software outsourcing or taking out insurance.
  • Risk acceptance: The risk is consciously accepted by the management.
  • Risk avoidance: Functions are omitted that could have a negative impact on a company's operations.

Since we cannot be sure that all vulnerabilities will be addressed on the client's side, it is even more important that we clearly communicate the potential for damage. Regardless of our view, the client should carry out its own risk assessment, as we do not know all the background information from the company.

Section Navigation

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

binsec GmbH is a highly specialized penetration testing provider and the operative pentesting core of the binsec group. Since 2013, the company has focused exclusively on high-end, human-led penetration tests (pentests) and advanced red team simulations. Rejecting automated scans, our team of permanently employed, certified senior pentest experts delivers manual deep-dive assessments of critical digital systems: from web applications and APIs to mobile apps, complex network infrastructures, and cloud environments. As a dedicated assessment partner for highly regulated sectors such as Payment, Banking, and Healthcare, binsec GmbH provides clear risk evaluations and actionable reports to effectively secure business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808