September 4, 2026
When 98 Users Are Happy, Who Is Watching the Other Two?
The role of a security tester has never been easy!

By Anand Gururaj
2 min read
The challenge is not just about keeping pace with an ever changing digital landscape and the growing threat of AI. The real challenge lies in the tenacity of a security tester to convince the business team, technical team, and management of why a particular security issue could be detrimental to the organization.
Imagine you have 100 visitors to your website. Ninety-eight of them come to do business. They are not interested in breaking into your application or gaining illicit benefits from your product or service.
Those 98 users are primarily taken care of by the QA, business, and other teams who need to "think like a regular user" and ensure that the application behaves as expected. In other words, they are focused on meeting user requirements.
The role of a security tester, however, is largely focused on the other two users out of 100, the ones who don't come to do their own business, but someone else's business!
They don't come to "meet their requirements." They essentially come with someone else's objectives.
The objective may differ depending on the type of attacker. It could be a casual attacker, an organized criminal group, a state-sponsored actor, or someone else. That is a different topic altogether, which I will discuss separately.
Now, the biggest challenge for a security tester is not merely identifying the potential intent or actions of those malicious users. The real challenge is convincing everyone (the business team, technical team, and management) that those two users matter, when everyone is naturally more focused on the other 98.
This does not mean that the others don't care about security. They understand its importance. They know that a single data breach can potentially bring an entire business to its knees.
It is more about the mindset, the "thinking fast and thinking slow" phenomenon, that can sometimes obscure the possibility of something bad or unforeseen happening and disrupting the business.
This is where a security tester needs a mature mindset, patience, and, most importantly, the ability to communicate in the right language.
Security professionals often talk about things that might cause business losses. They are not always the ones bringing positive news! They recommend security controls and tools that may cost the company money rather than directly generate revenue.
And therein lies the challenge.
Like everything else, it is not always the technology that poses the biggest challenge. It is the mindset, the understanding of human psychology, and the ability to translate technical risk into business language that matter the most.
Security testers must be good listeners. They must anticipate rejection of their ideas and recommendations. After all, companies do not generate revenue from those "two" users we talked about earlier. Their focus is naturally on the 98 users who bring business.
The security tester's job is to make the organization understand why those two users matter, before they become the reason the other 98 stop coming.
Ultimately, security testing is not just about finding vulnerabilities. It is about finding the right way to make people care about them.
A good security tester doesn't merely identify a risk. They must know how to translate that risk into a language that everyone can understand, appreciate, and act upon.