Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.
Scriptkiddie level people should just be honest that they are doing checklist audits to see if administrators are doing their job.
But unfortunately we are on the hype train where everyone needs to be "cybersec/offensive/pentester/ethical hacker". In the end, cannot really blame them entirely because otherwise CEO and CFO types are not going to hire them and they won't earn money.
Most pentesters / offensive security professionals have to operate with their hands tied behind their backs. Management generally has no interest in a real report of what happens if someone actually tried to break in. Generally speaking pentests are often so limited in scope and what is allowed to be engaged that you might have a group of people perfectly capable of robbing you unable to show you how because the company doesn’t want to know the truth.
Especially pre-Wannacry, since then things have improved somewhat, when top management woke up to the thought that these things do in fact actually happen.
You haven't seen good pentesters then, I suppose. I personally know a lot better than the level you described and I'm not near as experienced as some of the people I know. Question is whether or not whoever holds the purse is willing to pay for the higher quality work.
Dirt cheap programmers from low-economy countries aren't always the best either, just saying.
Yes good point. The ones I know come across as "box tickers". They're from a very high profile IT company but that doesn't say much. I assumed they were all like that but I admit that was an assumption.