A checklist-style guide to what a penetration testing rules of engagement document should contain, who needs to sign it, and what happens when it’s skipped.
Rebecca Sutton
Rebecca Sutton
Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
-
-
Zero trust security stops one stolen password from reaching everything else. Here is what it takes in practice, a realistic starting checklist, and the mistakes businesses make along the way.
-
CVE-2026-58048 is being downplayed as low risk because it needs an existing account. On shared hosting, that’s exactly the wrong conclusion to draw.
-
The NHS Data Security and Protection Toolkit now expects independent, evidenced penetration testing rather than a self-declared tick box. Here’s who it applies to and what a compliant report needs.
-
Blog & Articles
Breach and Attack Simulation vs Penetration Testing: Don’t Believe the “Continuous Pen Test” Pitch
BAS vendors call it continuous penetration testing. It isn’t. Here’s what breach and attack simulation vs penetration testing actually measures, and why you still need both.
-
SOC 2 never uses the words “penetration test” but most auditors expect one anyway. Here is what CC4.1 actually requires, how often to test, and what a Type II audit …
-
A maximum-severity Metabase SQL injection vulnerability was exploited in the wild before a fix existed, and Framework and Tally have both confirmed data loss.
-
The Cyber Security and Resilience Bill never says the words penetration test, yet regulators will expect one. Here is the gap between the law and what it actually means for …
-
Blog & Articles
Your DSPT Says ‘Standards Met’ on Penetration Testing. Does the Evidence Back That Up?
A vulnerability scan is not a penetration test, and NHS England’s own DSPT guidance says so. Here’s where submissions actually fall short, and how to fix it before an auditor …
-
New passkey attacks bypass phishing-resistant MFA on Windows and Chrome. Here is what IT teams should patch and review right now.