Most enterprise security programs have an uncomfortable truth sitting on their risk registers. They test a small fraction of ...