In this customer spotlight, Rusty Wolf, Director of IT Infrastructure & Security at Custom Truck One Source, sits down with Evolve Security to share what's kept the partnership strong, why continuous testing matters, and the value of human-in-the-loop validation.

Rusty Wolf, Director of IT Infrastructure & Security, Custom Truck One Source

Custom Truck One Source (NYSE: CTOS), the first true single-source provider of specialized truck and heavy equipment solutions, has partnered with Evolve Security since 2019 to advance its proactive penetration testing, security assessment, and incident response programs.

In this customer spotlight, Rusty Wolf, Director of IT Infrastructure & Security at Custom Truck One Source, sits down with Evolve Security to share what's kept the partnership strong, why continuous testing matters, and the value of human-in-the-loop validation.

Transcript

Rusty Wolfe:

I'm Rusty Wolfe, Director of IT Infrastructure and Security at Custom Truck One Source, headquartered here in Kansas City, Missouri. We specialize in utility rental, sales, and service for your typical bucket trucks, utility vehicles, and service vehicles you might see on the road working on power lines or internet services, and even trailers in our case.

For us, one of the biggest things emerging today is AI — whether that's AI, LLMs, machine learning, you name it. That just increases the need to have penetration testing, and to do it at least annually. If you can do it continuously, that would be great as well. It's really starting to challenge us, especially as we continue to look at the threats coming from attackers who are utilizing AI to put us on our defenses.

We had used Evolve Security before for our penetration testing and saw a lot of great benefits, especially with the Darwin portal. It was the first of its kind I'd had experience with — other penetration testers were using Excel files or exporting to a PDF. We saw the wealth of knowledge that comes back through it, and it gives us the confidence of knowing we're doing the right steps throughout the year when we're implementing or reconfiguring solutions.

When it comes to our pen testing, we're required by our private equity company to do an annual penetration test. It allows us to have that compliance and to showcase — not only to our PE firm, but to our auditors at EY, our executive management, and our investors — that we're taking the proper steps from a security and infrastructure perspective to keep the company safe.

We had a relationship with Evolve Security a couple of years ago and really enjoyed the engagement — we actually did some CISO services with them as well. Then, just due to the standard norm of switching between different penetration testers over the years, we wanted to change it up one year. It didn't go so well, so we came running back to Evolve Security and said, "Hey, Mark and team, how can we partner with you again and have you do our penetration testing?" It's been a wonderful relationship over the years, and hopefully it will continue.