Penetration testing services are now widely supplied and utilised by a variety of organisations. The quality of service can vary dramatically, but the industry harbours a number of dark secrets that are rarely discussed. Mike Kemp outlines how the industry came to be, where it's going and why we are still doing it wrong. Everything is broken, but we can fix it (possibly). The talk was held at Plymouth University on 19 June 2012. [(CC) BY-NC-SA 2.0 UK]