636-555-3226 wrote: » FWIW, as it pertains to outsourced infosec, including MSSPs, I'm not a fan. For the cost of all that I've seen you might as well just buy FTEs and put them to use. I know many a professional pentester who was doing a test for someone and ended up on the MSSP's network, sometimes gaining domain admin on that MSSP network....
tpatt100 wrote: » I understand why companies outsource and it makes sense for many companies. From a regulation and compliance viewpoint it becomes a big headache trying to figure out how to stay compliant when a company outsources parts if not all of their IT.