2024 State of Pentesting (6th Annual Installment) at Cloud Native Now 2024
Join Caroline Wong and Anne Nielsen for a fireside chat about the 2024 State of Pentesting report, which provides data and insights from more than 4000 manual pentests performed in 2023. This year’s report includes common security vulnerabilities identified in artificial intelligence tools. In addition to the historical pentest data, we also surveyed ~1000 information security professionals in the USA and UK. We’ll discuss key themes and takeaways.
Transcript
Hi, my name is Caroline Wong, and my colleague Anne and I are so thrilled to be here with you today at techstrong. Today we're gonna be talking about this state of pen testing 2024 Cobalt's sixth annual installment of this report. Thank you.
Alright, so state of pen testing. We're so excited to get into this with you all today. Uh, but first, before we, we start covering the report, uh, I just wanna take a minute to introduce ourselves.
Uh, I'm Ann Nielsen. I lead product marketing at Cobalt. I have about 15 years of experience working in various roles at various cybersecurity companies.
Uh, can't get me away from the, from the cybersecurity stuff. I love it. Caroline, why don't you introduce yourself Similarly, can't get me away from that cybersecurity stuff.
Uh, been in cybersecurity since 2005, began by leading security teams at eBay and at Zynga, currently the Chief Strategy Officer at Cobalt. I also host a podcast called Humans of InfoSec, and I teach courses about cybersecurity on LinkedIn learning. Awesome, thank You.
All right, so today we're gonna be talking about the data pen testing report. Uh, we have some key takeaways that we're gonna be getting to at the end, but first we're gonna go through some of the insights that we've seen on AI security, uh, some of the, the kind of data points that we saw around budgets, around effects on security teams. Uh, and then we're gonna wrap up, like I said, with the key takeaways and tips.
But, um, before we jump into that, I wanted to take a minute to give a frame on the cyber, uh, on the state of pen testing report and sort of our methodology. We have done over 4,000 pen tests in 2023. And so this report is really analyzing those pen tests and seeing, you know, what sort of trends are we seeing in the market.
But this is just pure data, right? We don't have any context around that data. Uh, you know, why is this happening?
We just have the data that it's happening. Uh, and so in order to augment and kind of add to that why, uh, we did a online survey with about 900 cybersecurity professionals in the UK or in the US to kind of get a, a broad range, uh, and asked some more context based questions to get an understanding and, and get that context, uh, for the data that is coming out of our, of our pen testing. So that is what we're gonna be jumping into now, uh, but wanted to give you that framework.
This is our sixth annual report. We do, uh, analyze this data every year, and so it's, it's nice to be able to kind of compare year for year over year, how things are changing. Now, with that, I'm gonna hand it off to Caroline to talk a little bit about ai, because this was a big trend in our data this year.
We saw quite a spike in AI pen tests, uh, and that led to, to some interesting insights. Caroline, take it away. So certainly AI is everyone's new favorite or least favorite topic.
I think that I've not been able to attend any sort of technology related conference event or, or made up for at least the past 12 months where AI is not a main topic of conversation. And today, we're delighted to share with you some of the data, both from the survey as well as from Cobalt pentest data. Um, of course, AI in computing has actually been around for decades, but it's only recently that it's really become so easily accessible by so many people at a large scale.
Um, I just wanna start out with a few definitions for key terms. So AI being short for artificial intelligence, a branch of computer science focused on creating machines with the ability to replicate human cognitive functions and the application of this field to software, uh, Anne and I both having focused on software security, um, for quite a long time, uh, recently in our careers. Now, generative ai, gen AI for short is a field of AI that's really focused on creating algorithms typically, typically called models.
And these are capable of generating new content or output following the dataset that trained it. So in this case, we as consumers, we're seeing all sorts of applications of available for us that allow us to do this kind of thing for images, for audio, for video, um, et cetera. Um, so you can see that based on this survey that we did for Cobalt State of pen testing, 75% of respondents to the survey say their team has adopted new AI tools in the past 12 months.
And yet, 57% of those respondents are saying that the demand for AI is outpacing the securities team's ability to keep up. Today, AI is undeniably a part of working at any and every company that uses software and the internet. Every organization is just trying to identify and refine the specific use cases that are going to suit their business needs.
We at Cobalt have been performing pen tests on AI and LMS for our customers, and I'd like to kind of share a few different levels of maturity that we've observed. So the first level of maturity at an enterprise organization is chatbot utilization. Um, this is when employees begin to use chatbots such as chat, GB gbt for assistance in performing daily tasks.
Uh, we are actually performing pen tests on these types of chatbots. Um, a note that this particular level of maturity, it might happen with or without formal approve approval from management. Um, I remember, uh, Ann and I talking about this topic, uh, before, and Ann saying, you know, this whole AI thing, it reminds me of BYOD, uh, when it was coming out.
Bring your own device. And the thing about AI is, regardless of whether it's allowed or not, people are going to use it. Similarly, you know, when we were going through bring your own device, we similarly, regardless of what the policy is, people are gonna do it.
Um, so there is an advantage to just getting ahead of it. Um, from a security perspective, you know, some of the data that these chat bots are using is sensitive, sometimes the data is confidential. Um, and, and certainly this is one of the bigger risks to any and every enterprise, which is employees using public chat bots and potentially disclosing any sort of sensitive or confidential information.
The second level of maturity that we've observed has to do with developing an AI policy. So when businesses actually do choose to take an official stance on the use of ai, the third level of maturity we're seeing is when organizations use ai. And that AI is what's called context aware.
You can think of this as an AI system going and doing a Google search by itself to take into consideration authoritative sources. The fourth level of maturity is tool enabled ai, where AI is not only grabbing context from external sources, but it also has access to external tools. And the fifth maturity level of AI is where AI is handling an entire series of tasks or a full blown process completely on its own.
That being said, there are relatively very few organizations that are currently at this highest level of maturity, but I think this is gonna increase significantly over the next three to five years. Next slide please. So at Cobalt, we're thinking about security testing.
We've had a focus on software security testing for years now, and we're actually approaching nearly 15,000 manual pen tests conducted across all time. And so one of the things that's really obvious that we wanna make sure that folks understand is that common web app vulnerabilities such as injection apply just as much to chat bots and other AI software applications as they do to any other web applications. Des, despite its very exciting and practical applications, AI is actually inherently limited and prone to these types of mistakes.
And so here, and in the report, we actually share three of the most common vulnerabilities that COBAL pen testers have been finding in AI systems. And so as we go into this, I just wanna zoom out for a moment and say, you know, folks are familiar with this computer science and software engineering output of garbage in and garbage out. And so when we look at these three most common vulnerabilities that cobalt core pen testers are finding in AI systems, when we're looking at injection and denial of service and, and prompt leaking, you know, these actually have to do with violating the confidentiality of information within an AI system.
And actually these three, you know, they each touch on the full CIA triad. So we've got prompt injection messing with the actual data that's in the AI LLM, we've got denial of service, which certainly is an impact to availability, making an AI software system unavailable for the intended users. And then prompt leaking, of course, has to do with confidentiality if an attacker can trick an AI chat bot into sharing information that it's not actually supposed to.
Um, next slide please. Uh, one of the things that we're actually seeing over the past couple of months or so, there's been a shift from folks thinking, gosh, AI is the latest and greatest thing. It's gonna solve all of our problems.
I actually think we're entering a place where folks are bringing more and more of their concerns to the table. And these concerns are really what's driving technical manual security pen testing of these AI systems. Our customers are concerned about liability, they're concerned about reputational risk, they're concerned about potential financial impact.
And I've heard folks refer to this phase that we're currently in as the trough of disillusionment, similar to, um, a phase of the Gartner hype cycle. And so now is really a time for us to inspect and scrutinize the ways in which our organizations are using ai and certainly to apply technical security testing as we have been doing for web applications for a long time now. Next slide please.
So our industry has a draft oasp top 10 for large language model applications. Um, right now that's a bit of a work in progress, and we're very proud that some of the members of our Cobalt core Pentest community are involved in this working group. Um, certainly the AI pen tests that we've conducted over the past several months are showing us that some of these items on the oasp top 10 are indeed being found in real life, and now is the time for us to scrutinize and test these systems.
Um, the last thing that I wanna say with regards to Cobalt's AI vision is that we are actually thinking about this in terms of a few different ways at Cobalt when it comes to pen testing. One of them, of course, is to enhance report writing, because I'll tell you what, the real opportunity from my perspective when it comes to AI for any of us and business processes is to think about what parts of my job do I love that I want to keep doing, and what parts of my job do I find to be kind of grueling and kind of boring? And for pen pentesters, hackers love to hack hackers, don't love to check for typos and grammar mistakes.
And so that's one of the ways in which we're leveraging AI today. Um, certainly when it comes to the test process of performing a manual pen test, uh, we are also leveraging AI to go in that direction, especially as we look toward the future, um, as well as, uh, using it in various parts of our platform just to make things easier and simpler. Um, and so that is our section on ai.
Next, I'm going to pass to Anne to talk about additional key insights from the state of pen testing 2024, having to do with budgets and security teams. Awesome. Thank you, Caroline.
Yeah, we, we had these, these interesting trends with ai, but uh, we have a sort of routine analysis that we do when we look at all of our pen test data. And there were some additional surprises that sort of popped out at us. Um, you know, after digging in on the AI front, we also started to notice some other things.
And so I wanted to go through that as, as some of the key insights that we, we saw from this year's dataset. So one of the, the overall sort of macro trends that we're seeing in the market is the attack surface is increasing. I don't think that that's a surprise to anyone.
Uh, companies are shifting from, uh, you know, their traditional network to cloud and DevOps and adopting more DevOps practices. Um, and yeah, that's been happening for 10 years. That's not, you know, brand new.
Uh, but what this does is this is sort of erasing the line between network and compute, where we're seeing the traditional boundaries by which security sort of, uh, was able to, you know, put up that that fencing, um, are now evaporating. And again, this is not, not new, not a, a total surprise, but it is something that is, uh, making se it harder for security teams to do their job. Uh, it, again, another trend that has been continuing for the past few years is the embrace of open source code, leveraging open source, uh, to get further faster.
Uh, rather than writing something from scratch, just go grab an existing library, existing framework, an existing package, and just pull that into your, into your code so that you don't have to just, uh, come up with that on your own. And something that is relatively new is the use of AI generated code. We've all seen the copilots that are out there, uh, and many developers are quick to adopt this sort of like helper, uh, that comes in and, and adds some lines of codes so that they can do their jobs faster.
However, you, that is not increasing the security of, of those, uh, those lines of code, unfortunately. And what we've seen is that just taken altogether, um, the software that is being produced as part of this growing attack surface is not more secure, unfortunately, it is less secure. We're seeing a 21% increase in the number of findings, and this is on a pen test engagement.
So these are findings that are then exposed, uh, are true vulnerabilities rather than, you know, theoretical weaknesses in the code. Uh, these are ones that are our pen testers are able to uncover. So that is, that is concerning.
Um, and then, okay, you know, at least we're finding these findings. How are we doing it fixing these findings? Well, also, you know, sad news there as well.
As we look at the meantime to repair, um, I added that little, uh, line that you see there, um, that we're seeing this, uh, go up. This is steadily increasing in the amount of time it takes to fix findings. Now this is across all severity types.
Um, but as I looked at remediation, as we looked at remediation across all severities and then across high and critical findings, um, you know, thinking, hey, maybe we're actually fixing our high and critical findings and sort of leaving the medium, the low informational findings, um, as something that's a later problem, that would be a reasonable approach to take. Uh, but unfortunately we're seeing that, um, even though, uh, even as the time to fix is increasing, um, we're also seeing the remediation times, uh, for, uh, the remediation itself for high and critical findings is not, not a good picture either. We are seeing that there's an increase in the remediation need for high and critical findings where they're not getting fixed as much as we would like to see.
Uh, and that is, you know, true across all severities as well. So it's, it's not, uh, a great picture that we're seeing here in terms of the findings themselves. And so that led us to, um, you know, that context, uh, asking security practitioners.
What is going on here as part of our survey and the conclusion that we've sort of drawn is that, um, and again, I don't think this is a surprise to anyone on the, on the call, but, um, you know, we're, we're seeing some organizational dynamic challenges where security teams are being asked to do more with less. We're seeing a growing attack surface, yet a constraint on the budget and on the, the team size, um, which is causing, uh, the teams to have to struggle to try and secure the, these boundaries. So what we saw is that, you know, 31% of our pro respondents have faced layoffs, or 29% expect to face layoffs.
So security teams are essentially either staying flat with where they are or they're being reduced. Uh, and then when we look at budgets, it's the same sort of story. Budgets are either staying flat or they're being reduced.
And what are the teams doing as they're trying to, to address this issue? How are they, uh, trying to approach this issue? Well, many of them are saying, well, they're deprioritizing new technologies.
They're deprioritizing hiring, they're looking at outsourcing more. Where can they get, um, help with their security programs that are outside of their organization so they can put that budget to work and protect, um, the team that they have, but augment, uh, that team and, and use that to protect the company. So, uh, that is where we're seeing this increase in pen test year over year.
Um, we're seeing that as companies are looking to do more with less, as the companies are trying to do this belt heightening or not hiring at a minimum, then they're leaning on known, uh, good controls, uh, that they know produce effective results. And so that's where pen testing is coming into play. And so we've actually seen that as sort of a macro trend across, across the market where, uh, companies are looking for more, uh, exposure validation to say, instead of helping me find a bunch of theoretical things that could maybe cause a problem to my organization, I need to focus on the things that I know are true positives that I know are truly going to impact my organization.
And so this is the difference between talking about this is theoretical risk versus I need budget for true risk where I can tell you exactly what the impact will be. If this vulnerability is not addressed, I can, I have the, the full attack path here for how somebody could get into the system, what crown jewels they would be able to access, how they would go about doing that. And that's why I need the security budget.
And so what we're seeing as cobalt is that this is a sort of pivot towards more offensive security approaches rather than continuing to invest in defensive strategies. Doing both, just to be clear, like we're not saying like doing only one or the other, but truly using offensive security to help validate and verify that those defensive controls are truly effective. So doing this as an investment strategy to have on the one side, building up your defensive controls, and then on the other side, using that malicious attacker mindset, malicious actor mindset to verify the effectiveness of those controls and produce those findings that are truly actionable for the organization because they are verified vulnerabilities that can be exploited, uh, and focusing on those and fixing those rather than focusing on the things that are more theoretical in nature.
So this is how Cobalt, uh, has been viewing the, the challenges that organizations are facing. And many companies are coming to us, um, because of our depth of knowledge with pen testing. Uh, we, we pen test, uh, we're mostly known for web and API pen testing, but we pentest network, we pentest, uh, devices.
That is an area that we've seen a lot of growth in recently. We also do social engineering, physical pen testing, uh, but many companies are coming to us and they're saying, Hey, we know you for pen testing, but can you help us? Can you bring your security expertise to bear in these other areas?
And so Cobalt has started, uh, growing in other areas like red teaming, uh, but also in digital risk assessments to understand what is out there that could compromise an organization, uh, growing in source code reviews, uh, or secure code reviews to help an organization earlier in the software development process, secure that software. Um, and growing into threat modeling as well, again, on that same sort of, um, angle of helping an organization early in the software development process. So that's, that's where Cobalt has really, uh, spent our time.
And what, uh, the state of pen testing report really helps us see is that this is an area that, uh, many organizations are struggling with. So I'll hand it back to Caroline to get into our key takeaways and tips for, for the audience. Thank you, Anne.
So we're just wrapping up and wanna leave you with a few of these items. Thing number one, folks are using ai, they're also focused on AI security and testing their AI systems thing. Number two, folks are finding that they don't necessarily have the specialized technical security skills all in-house, uh, and they're looking to third parties to partner with in order to get that work done really effectively and really efficiently.
Um, and thirdly, uh, folks are really shifting from a defensive to a more offensive security approach, as Anne was saying, in order to focus on items that are really truly exploitable, uh, and kind of not waste limited time on purely theoretical items. Uh, next slide. So a brief call to action.
We really encourage each and every organization to have a stance and a policy on ai. We really wanna make sure that you're communicating to all of your staff members that sensitive information should not be going into public lms. Um, number three, you know, we're really finding that some of the most common attack types that are effective on AI systems are similar to the ones that we're seeing in a normal software development lifecycle.
And so just the way that you secure your regular SDLC folks should be thinking about securing their use of ai. Similarly, finally, the best way to validate that your defensive controls are working is to leverage offensive security controls. So sometimes I think about this in terms of the attacker mindset.
You know, for folks that are building software, we tend to think about using the things that we build in the ways that are intended to be used, but we don't often consider the misuse and abuse cases. And so we can find ourselves biased towards overemphasizing the good ways in which software can be used while disregarding the bad ways. Um, and maybe the best way to identify where and how an organization or a piece of software is going to be susceptible to attack is by taking on the perspective of a malicious person, which is the attacker's mindset.
Uh, final slide. So with that, uh, Anna and I just wanna leave you with, um, the thoughts that we've really only scratched the surface of insights from this year's state of pen testing 2024. We encourage you to download and check out the full report whenever you get a chance.
io, click on resources and you'll find it right there. Thank you so much for taking the time to be with us today. Thank you all.
Really appreciate it. Have a great day.