Event Hack Red Con 2024 starts on Oct 25, 2024, 10:00:00 AM (America/Kentucky/Louisville)
Reframing the “Success” of an Offensive Test: Taking a Risk-Based Approach
60min Talk - Business
Location: Trophy Room - 10/25/24, 1:00 PM - 10/25/24, 2:00 PM (America/Kentucky/Louisville) (1 hour)
Reframing the “Success” of an Offensive Test: Taking a Risk-Based Approach
Celina Stewart
Head of Risk Management
Celina Stewart
Head of Risk Management

Celina Stewart is an expert in cyber risk management at Neuvik, a cybersecurity services company. In her current role, she leads Neuvik’s Integrated Risk Management service line, translating technical findings from Red Team Assessments to cogent, tactical strategies to buy-down business risk. Celina specializes in designing and optimizing cybersecurity programs, taking a risk-based approach to program strategy, organization and operating model design, and alignment of technical controls to reduce business risk. Prior to joining Neuvik, Celina worked for McKinsey & Company, where she was a founding member of the cybersecurity practice. In this role, she served Fortune 500+ clients to develop cybersecurity strategy, to optimize cyber program performance, and to integrate cybersecurity with enterprise risk management. Her research has been published in McKinsey on Risk and other publications.


At its simplest, the goal of offensive testing – and penetration tests in particular – is to identify vulnerabilities within an environment and provide remediation guidance. However, many organizations view offensive testing as a performance review, aiming to get a ‘top score’ with only a few findings.

This talk challenges that mindset, as it often distorts the true risk present in an organization – leading to a false sense of security when a “top score” is achieved. Instead, this talk reframes what a “successful” offensive test looks like. By taking a risk-based approach, offensive testing can prioritize systems tied to critical business risks – in turn ensuring that all findings truly buy-down risk.

Attendees will receive tactical guidance on how to extract the most value from their offensive testing to truly address the most pressing risks in their environment. Key topics include how to scope for impact by using a risk-based approach to prioritize systems for offensive testing and how to communicate findings in a Board-friendly manner to truly buy-down risk within the environment.