636-555-3226 wrote: » Good pentesters for ANYTHING are hard to find. Most pentesters generically tackle the network side of things. Web app specialists aren't as numerous. If you really want to get in on a good niche that is just starting out but will make you a millionaire in a few years when it explodes, get in to ICS/SCADA. That's a very small niche with only half a dozen **good** people across the US worth paying for. Make yourself one of those elite and you're set for life.
Ertaz wrote: » I have to laugh at this a little, because its such a painful realization. ICS/SCADA security in every manufacturing org I've ever been in is %99 at the network layer. No host controls allowed, no device hardening. A moderately well versed pentester could do some permanent damage to ICS systems at older manufacturers. Some of those systems are 30+ years old and are running everything from HP-UX, NT4, unpatched out of support appliances. At newer, "profitable", manufacturers or utilities I can see the strong need for advanced knowledge in the pentesting arena. The cia triad in manufacturing be like:c-i-A
Kalabaster wrote: » I disagree. The "A" should be much bigger.
636-555-3226 wrote: » True, true, but pentesting ICS/SCADA isn't just about finding win 3.1 & linux from the mid-90s. It's about understanding how the systems integrate as a cohesive whole. Coming in and pointing out my win 3.1 system needs upgraded doesn't even require a pentest, but being able to understand that my city's water/sewer system are reliant on win3.1 and we don't have the $20M to upgrade requires more than just a pentest FAIL stamp. no smart company in the world pays for just a pentest - they pay for someone to 1) find the holes, 2) prove the holes are exploitable, and 3) provide useful takeaways for action items that can be accomplished. simply giving me a red critical 10/10 rating for end of support systems and telling me i need to upgrade (which accomplishes 1 & 2, above) doesn't work. you need to tell me how to keep the water flowing in a safe manner. how many network pentesters do you know who understand how a water treatment system works that provides water for 2M people? RE: ICS - that's the guy who is going to be making the big bucks, not the guy with an OSCP who can run nessus and veil.