A jargon-free walk-through of what happens when you commission a penetration test, from agreeing the scope to fixing what’s found.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
PCI DSS penetration testing requirements are more than one annual test. Where the checkbox approach falls short on internal, external, segmentation and remediation obligations, and how to fix it.
-
A critical Cisco email gateway vulnerability shows why perimeter security appliances need the same scrutiny and testing as the applications they protect.
-
The headline cost of a data breach UK figure is real, but it describes a different kind of business than most readers run. Here’s the number that actually matters, and …
-
A Russian state-backed campaign against Zimbra webmail went straight for 2FA backup codes, not passwords. Here is why that part of MFA gets ignored, and what to do about it.
-
A practical breakdown of DORA’s two testing tiers, the annual baseline programme and threat-led penetration testing (TLPT), with a checklist for preparing either way.
-
A practitioner’s view on setting third party penetration testing requirements: what to ask suppliers and vendors for, how to tier them by risk, and where GDPR, ISO 27001 and PCI …
-
What a software supply chain attack actually looks like, why the numbers are rising fast, and a priority-ordered checklist UK businesses can act on this quarter.
-
WordPress’s automated plugin review caught a real backdoor before it shipped. That is a genuine win, but it does nothing about the vulnerable plugins already on your site.
-
DfE standards do not require it and Cyber Essentials does not test it. Here is what a penetration test for a school covers, and why the compliance gap matters.