What is our primary use case?
Pentera is used for continuous automation penetration testing across our internal network, external network, and also with our clients.
Pentera is utilized as part of a wider team workflow, with team members using it for penetration testing, discovering anomalies, weaknesses in environments, and identifying issues through Active Directory.
What is most valuable?
The best features of Pentera for our team include automation attack path discovery that chains multiple vulnerabilities into realistic exploitation scenarios and evidence-based remediation, which are features our team heavily relies on.
Pentera has significantly affected our organization by dropping our mean time to remediate critical vulnerabilities because the remediation team can clearly evidence the exploit instead of debating CVSS scores, and our security posture has improved. We have saved approximately 45% of the hours we used to spend on manual penetration testing.
What needs improvement?
The biggest friction point with Pentera is the need for more granular control or the ability to exclude specific sensitive systems, as well as the necessity for the cloud environment to mature. While Pentera excels in on-premises and hybrid setups, its
AWS and
Azure attack path simulation is not as deep compared to others.
If I could change one thing in Pentera to improve my workflow the most, it would be the platform UI because some security team members are not penetration testing specialists, making it difficult for them to navigate. I would make it easier with more guided workflows.
For how long have I used the solution?
I have been familiar with Pentera for around three years.
Which solution did I use previously and why did I switch?
Before landing on Pentera, we were conducting penetration testing manually.
How was the initial setup?
When we first implemented Pentera, it took approximately six to eight weeks for a proof of concept to get everything up and running in our environment. Our team needed to research, learn from PDFs, talk to some people, and take training before deploying it.
What was our ROI?
Pentera has significantly affected our organization by dropping our mean time to remediate critical vulnerabilities because the remediation team can clearly evidence the exploit instead of debating CVSS scores, and our security posture has improved. We have saved approximately 45% of the hours we used to spend on manual penetration testing.
Which other solutions did I evaluate?
While evaluating options, we checked multiple vendors and found that Pentera was top-notch. The rating and overall quality were good, which is why we chose it.
What other advice do I have?
My advice for someone considering Pentera who has a workflow similar to mine is to run the proof of concept in your real environment rather than an isolated lab, as the findings from a realistic network segment will strengthen the business case. Engage your legal and compliance team early to establish authority and testing scope, and always integrate penetration findings with your vulnerability management workflows from day one. I would rate this product nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other