nearly all the agencies we examined had recently paid contractors between $9 000 to $75 000 to
conduct penetration tests on their infrastructure. Some agencies were doing these tests up to four
times a year. In the absence of a broader assessment of vulnerabilities, penetration tests alone are of
limited value, as our testing demonstrated. Further, they are giving agencies a false sense of security
about their exposure to cyber threats.