Are all security consultants useless?

Posted by ArticleGlad9497@reddit | sysadmin | View on Reddit | 150 comments

I can't be the only SysAdmin getting increasingly more and more fed up with having to deal with security consultants who don't have a clue what they're doing can I? It probably doesn't help that their standard pay seems to be much higher and yet their ability to apply knowledge sensibly is completely lacking. I have to deal with several NHS trusts and so granted they're probably bottom of the barrel security consultants be even so, it's infuriating. Last week one of them wrote to us as they'd pentested the service we host for them and found several security headers were missing. I knew they were there so that was odd and also there should have been a number of other low scoring vulnerabilities that were missing. First off I speak to the other admin, we've had no request to turn off or bypass their WAF so that would have hidden pretty much all the vulnerabilities but even more impressive I realised he had run the pentest using an external tool. As part of his initial security requirements for our product we blocked connectivity to the portal from everywhere other than 3 public IP addresses. So essentially he has pentested absolutely nothing... I pointed this out to him and his response was that he will mark it as a false positive... And that we've passed the pentest....WTF! As the SysAdmin I'm happy to get it off my plate but as a member of the UK public a part of me feels the need to raise this ineptitude within the trust because god knows what else this guy has signed off without having a clue what he is doing... Please restore my faith and let me know there are some good ones somewhere....