At some point, organizations seem to have confused hacking
certifications with the ability to breach systems at the level of state actors. An unfortunate side effect has been to equate penetration tests
with actual breaches.
They aren’t the same.
You'll likely not guess this from the balance of conference topics and social media posts skewed towards red teaming but red teams are just another capability within a cyber security
program.
Really, they are.