Really like what
@bettersafetynet is asking for here:
1) give a customer decision space. Backing anyone into a corner with only "Update log4j 2 to 2.17" is infuriating nonsense.
2) tell a relevant story, especially in terms of business and brand impact. "Why" matters.
Pen testers, we need to talk. Please listen up, take notes... and above all, ask questions.
A non-trivial part of my service portfolio is now reviewing the reports of other firms and either adjusting or providing missing context.
Read on for the common issues...
1