
Sign up to save your podcasts
Or


Welcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by Jamie Kerem with CISO and founder, Trevor Horwitz.
“A vulnerability without exploitation is just a hypothesis.”
In this episode, Penetration Testing: What’s Really Cooking Behind the Scenes, Jamie and Trevor break down penetration testing from the inside out, moving beyond checkbox compliance and into the realities of adversarial security validation.
The conversation walks through the full lifecycle of a penetration test, from scoping and reconnaissance to exploitation, lateral movement, post-exploitation, remediation, and continuous testing. Along the way, they unpack how attackers actually think, move through environments, chain vulnerabilities together, and exploit the gaps between security controls.
They also explore:
* Vulnerability scanning vs penetration testing
* Black box, gray box, and white box testing
* Cloud, API, network, and application security testing
* Phishing, MFA fatigue, and human-layer attacks
* Business logic abuse and identity-based attack paths
* AI-assisted remediation and continuous security validation
* Why modern organizations are shifting from annual testing to continuous testing integrated into CI/CD and DevSecOps workflows
Take the conversation further:
* TrustNetInc.com
* https://www.linkedin.com/company/trustnet-inc
* https://www.linkedin.com/in/trevorhorwitz/
* https://www.linkedin.com/in/jamie-kerem
By TrustNetWelcome back to The Cyber Kitchen where cybersecurity gets sliced, diced, and served up with just enough spice to keep things interesting. Hosted by Jamie Kerem with CISO and founder, Trevor Horwitz.
“A vulnerability without exploitation is just a hypothesis.”
In this episode, Penetration Testing: What’s Really Cooking Behind the Scenes, Jamie and Trevor break down penetration testing from the inside out, moving beyond checkbox compliance and into the realities of adversarial security validation.
The conversation walks through the full lifecycle of a penetration test, from scoping and reconnaissance to exploitation, lateral movement, post-exploitation, remediation, and continuous testing. Along the way, they unpack how attackers actually think, move through environments, chain vulnerabilities together, and exploit the gaps between security controls.
They also explore:
* Vulnerability scanning vs penetration testing
* Black box, gray box, and white box testing
* Cloud, API, network, and application security testing
* Phishing, MFA fatigue, and human-layer attacks
* Business logic abuse and identity-based attack paths
* AI-assisted remediation and continuous security validation
* Why modern organizations are shifting from annual testing to continuous testing integrated into CI/CD and DevSecOps workflows
Take the conversation further:
* TrustNetInc.com
* https://www.linkedin.com/company/trustnet-inc
* https://www.linkedin.com/in/trevorhorwitz/
* https://www.linkedin.com/in/jamie-kerem