CBEST and STAR-FS grab the headlines, but most FCA-regulated firms need a different answer. Here is what operational resilience testing actually requires if you’re not a systemically important bank.
Blog & Articles
-
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Why framing in-house vs outsourced penetration testing as an either-or choice misses the point, and the hybrid model most UK businesses should actually run.
-
A practical guide to choosing between SAST, DAST and penetration testing, based on what you actually run, what you need to prove, and where to spend your first pound of …
-
Most penetration test disputes trace back to a thin scope of work. Here is what a proper one pins down, why vague scoping backfires, and how it differs from your …
-
Continuous threat exposure management (CTEM) is a genuinely useful framework buried under heavy marketing. Here’s what it actually requires, and where a dashboard alone falls short.
-
Threat modelling is how you work out where a system could be attacked before it’s built or tested. Here’s how it works, the main methodologies, and how it relates to …
-
A practical walkthrough of external attack surface management: how discovery actually works, how it feeds into vulnerability scanning and penetration testing, and how to do it without enterprise tooling.
-
Most security budgets still assume the job is keeping attackers out. Lateral movement is why that assumption fails, and what actually stops a breach from spreading.
-
Privilege escalation rarely needs a clever exploit. Most real cases trace back to one boring, forgotten access right that nobody ever took back.