Most UK businesses pen test once a year. But annual testing is a minimum, not a strategy. This guide explains when your penetration test frequency needs to increase and what …
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
An external penetration test simulates an outside attacker probing your perimeter. An internal test simulates what happens once someone is already inside. Both answer different questions, and your organisation probably …
-
Two members of Scattered Spider have pleaded guilty over the 2024 TfL breach. The techniques they used are low-tech and still active. Here is what organisations can do to make …
-
Three ShapedPlugin Pro plugins served malware via official updates for three weeks. Updating the plugin is not enough — here is what site owners need to do.
-
Cyber Essentials does not require a penetration test, and CE+ uses vulnerability scanning rather than adversarial testing. A side-by-side guide to what each certification covers, what it misses, and when …
-
The Squidbleed vulnerability in Squid Proxy leaks HTTP credentials from heap memory in every default installation. Here is how to check whether you are affected and what to do while …
-
The Gravity SMTP vulnerability (CVE-2026-4020) is being exploited at mass scale. But the real issue is structural: email plugins holding API keys create a risk that one permission bug can …
-
A vulnerability assessment scans your IT systems for known security weaknesses, rates each one by severity, and produces a prioritised fix list. This guide explains how the process works, what …
-
The Gentlemen ransomware gang ships an EDR killer framework to every affiliate, targeting 48 security products before encryption begins. Here are three practical checks every IT team should make this …
-
The FortiBleed Fortinet VPN breach compromised 74,000 firewalls, many running current firmware. The real failures were exposed management interfaces, legacy password hashing, and no MFA. Here is the harder lesson.