Earlier quoted context omitted.
Agreed. Caveat: do you need to do pen testing every release? I'm guessing, not. YMMV. If you're a defense contractor (as some other commenters mentioned), your priorities are probably quite different.
I head infosec for a “Series A - C” B2B company and a fairly standard request from a potential customer is to see not only our own penetration test reports but third party penetration test results, as well. As a result, we run automated pen tests on weekends and before major releases. We also work with an application security firm every 6-12 months. For what it’s worth, we don’t do anything nearly as intense as defen…
Glad to hear security is taking the front seat some places. Anecdotes like this help me expand my world view. <3