In a small business that relies entirely on SaaS services, where the team only has to manage an internet gateway, switches, Wi-Fi access points, printers, and user laptops, is penetration testing still relevant? Given that the security for the services is usually covered by SLAs and contracts provided by the SaaS vendors, do pen testing companies even have the capability to assess anything beyond servers or traditional infrastructure? If penetration testing is necessary, what should it ideally focus on?
4 Answers
It’s important to remember that part of pen testing is about testing the users too. If your users can easily give out their passwords or not follow security protocols, then SaaS alone won't keep you safe. It's definitely worth it to do some testing on that front, especially since you might find unaddressed issues with your SaaS setup.
Honestly, in a pure SaaS setup, it often feels like pen testing is just a way to spend money to feel secure. I mean, you might spend a lot on it just to say you've done it. But that's not the whole picture! While it might seem unnecessary, it can still highlight risks, especially if your team isn't properly trained on security protocols. Just having SaaS doesn't mean you're completely safe.
Totally agree! The big problem we found in our pen tests was user behavior. Users can easily undermine your security by sharing passwords or letting unverified people into the office. Education and awareness are key. Pen testing can help expose how vulnerable your users are and spot other potential misconfigurations in your SaaS applications, like weak passwords or lack of MFA.
Definitely! Even in a SaaS environment, there's still a lot to consider. You can get phishing attacks on your users that might fly under the radar of basic penetration tests. Plus, switches and routers can be targeted, and user desktops can get compromised if someone downloads malicious software. So, it's not just about testing the servers. There's real value in understanding the vulnerabilities in your user base and network devices.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures