Cytix Value Propositions Flashcards

1
Q

How do we define Cytix

Specifically the product

As stated on our website

A

A continuous testing platform for application security teams

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Cytix promise to do for customers?

As stated on our website

A

Threat model live development tickets & prioritise your security testing plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name two security benefits of automatically threat modelling live development tickets

A

1) Increasing visibility on development changes they didn’t know were happening; typically minor changes pass the need to be security checked, which allows vulnerabilities to slip through the net

2) Giving confidence that the right tests and actions are happening for every change, to ensure coverage of all relevant vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

We can integrate into any development ticketing system… How many can you name?

There are 8 listed in the answer

Try to name at least thee top 3

A

Jira
Azure DevOps (ADO)
Linear
Notion
ServiceNow
ManageEngine
Trello
Monday

In order of popularity

Jira is used by over 50% of our customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Unlike most competitors, we offer a hybrid of what two forms of security testing?

A

Manual penetration testing and automated DAST scanning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The main benefit of offering the hybrid is that it means we can identify which type of vulnerability more reliably?

A

Business logic flaws

“Identity and access management issues” and “complex injection flaws” ar

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long does it take for us to threat model a development ticket?

A

An average of 13 - 30 seconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

From identifying a change to completing all testing, how long does it typically take us?

Including threat modelling the ticket and delivering the testing

A

2-3 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a micro-pentest?

Think of the “Three As”

A

Testing A particular area of An Application for A specific set of vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How long does a micro-pentest take to complete?

Including only the actual time spent testing

A

Between 15 minutes and 2 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the main limitations of traditional (baseline) penetration testing?

A

It is slow and laborious, and therefore expensive

Most businesses are only able to perform the testing once per year

This leads to vulnerabilities going undetected for a long time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SAST and DAST are unable to identify roughly ____ % of recognised classes of security vulnerability

This is supported by research done with Lancaster University

A

25%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why might poor quality output from automated tooling create friction inside a business?

A

It frustrates development teams who are expected to remediate false positives and findings based on limited information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who do we see as our biggest competitors?

A

We operate in quite a unique space where we don’t really have major competitors, however our customers are often comparing us to their existing penetration testing and scanning suppliers

There are companies like SnyAck and CovertSwarm also trying to solve the continuous testing challenge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cytix is capable of finding security vulnerabilities in Cloud Infrastructure

True or False?

A

False

We are exclusively focused on application security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How can companies better understand the value Cytix provides?

A

We offer a low-burden proof of concept

As well as our change analysis tool on our website