Building a penetration testing program is challenging. It’s more than just testing your public facing website and making sure you don’t have SSH exposed to the world. In this presentation I’ll present 7 lessons learned from building a penetration testing program at a fortune 500 company. Everything from prioritizing what to test, how to build a winning team, how to pass that audit, and having the tools you need to do your job. Along the way we’ll explore some powerful penetration testing techniques to get you started if you’re new to the hacking scene or improve your game if you’re one of the OGs.