A Year of Penetration Testing and the Lessons Learned
A Year of Penetration Testing and the Lessons Learned
Wednesday, April 29, 2026 | 9:45AM–10:30AM PT | California Promenade, Second Floor
Session Type:
Poster
Delivery Format:
Poster Session
Penetration testing is a highly effective method for identifying real vulnerabilities within IT and OT environments. By using the same tactics, techniques, and procedures (TTPs) as malicious actors, penetration testers provide institutions with a realistic assessment of their security posture. The REN ISAC offers penetration testing services tailored to research and higher education institutions, conducted by cybersecurity professionals with several years of experience in higher education who understand the unique challenges of academia. Over the years, our engagements have revealed not only recurring technical findings, but also important lessons learned throughout the engagement life cycle, beginning with the pre-engagement questionnaire and pre-engagement meeting. The questionnaire often uncovers gaps in asset knowledge and scoping clarity. During the pre-engagement meeting, communication alignment and expectation-setting significantly shape testing outcomes. This session reviews collective trends observed across these engagements, from initial planning through final reporting, and shares practical recommendations for strengthening both security controls and the overall penetration testing process. Attendees will gain a clearer understanding of vulnerabilities impacting their institutions and insights into optimizing future assessments from start to finish.
Presenters
Kyle Enlow
Peer Assessment Program Manager, Indiana University