Which is to say, at least in the app pentesting market, I'm a little skeptical of the premise.
Which is to say, at least in the app pentesting market, I'm a little skeptical of the premise.
Many go to them, they see awesome resumes. They also see very large costs. The the customer finds he doesn't get the A-team, but the F-Team, due to 'unprecedented demand'.
This is about making the process transparent.
The software pentesters with gold-plated resumes do high-value targets (because there are more high-value targets than there are pentesters to service them). Google is not going to source Google Mail pentesters on DICE. Adobe doesn't source pentesters for Reader on DICE. Microsoft doesn't source pentesters for SCHANNEL.DLL on DICE. Apple doesn't source pentesters for the iPhone bootloader on DICE. That's where the A-Team ends up.
What transparency are you adding here?
If the argument behind this was, "we're going to drive down the price of pentesting", that would be a coherent pitch, although I'd still want to hear how you expect this service will do that; again, the market is supply-constrained.
There are many boutique companies that are excellent, but don't have a fair share at the market.
Companies that are 'all things to all men' tend to have quality issues over time... like the big security giants of the last decade. Eventually people get tired of it and look for specialists. That's where this will help.
I'm not talking about "big security giants" like IBM and Deloitte. I'm talking about boutique application security firms that do little other than test software. They're already specialized.
This is, for what it's worth, my field; I co-founded Matasano and helped run it until we sold to NCC.