The Trust Services Criteria never mention a pentest by name, yet auditors expect one for every SOC 2 report. Here is what actually drives that expectation.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
UK insurers increasingly ask for evidence of penetration testing before they will quote or pay out on cyber cover. Here is what they actually require and how to get ready …
-
CVE-2026-94127 is a patching emergency, but the real lesson is what happens when perimeter appliances quietly become identity providers nobody tested.
-
MFA blocks the vast majority of account takeovers, but attackers now have working playbooks against weaker forms of it. Here is how MFA works, how it gets bypassed, and a …
-
Fixing what a pen test found is only half the job. Here’s how to prioritise remediation, and why retesting is what actually proves the fix worked.
-
Phishing simulation testing shows exactly who clicks and who reports, but NCSC and UK GDPR both set limits on how to run it fairly. Here is how the process works.
-
A buyer’s checklist for vetting a mobile app penetration testing quote, covering what should be in scope, what questions to ask, and what a useful report looks like.
-
From scoping to retesting, here’s where the time actually goes in a penetration test and why the total is longer than the days you’re quoted.
-
Third party plugin risk, not clever malware, is why a critical WooCommerce flaw patched in February is still being exploited in September.
-
A web application firewall filters attack traffic in real time, but the vulnerability behind a blocked request is still there tomorrow. What it stops, why it can be bypassed, and …