@SheHacksPurple Ahhh, okay. For IT infrastructure you need to do it from time to time in environments like insurance, finance (regulation). Never seen that for web application security. Most companies do a delegation to a pen tester and then they think they're done. After a while you get feedback but that is not the same to be under stress to fix a security issue asap... would be a nice course