UK insurers increasingly ask for evidence of penetration testing before they will quote or pay out on cyber cover. Here is what they actually require and how to get ready …
Blog & Articles
-
-
MFA blocks the vast majority of account takeovers, but attackers now have working playbooks against weaker forms of it. Here is how MFA works, how it gets bypassed, and a …
-
Fixing what a pen test found is only half the job. Here’s how to prioritise remediation, and why retesting is what actually proves the fix worked.
-
Phishing simulation testing shows exactly who clicks and who reports, but NCSC and UK GDPR both set limits on how to run it fairly. Here is how the process works.
-
A buyer’s checklist for vetting a mobile app penetration testing quote, covering what should be in scope, what questions to ask, and what a useful report looks like.
-
From scoping to retesting, here’s where the time actually goes in a penetration test and why the total is longer than the days you’re quoted.
-
A web application firewall filters attack traffic in real time, but the vulnerability behind a blocked request is still there tomorrow. What it stops, why it can be bypassed, and …
-
Penetration testing as a service and traditional pen testing solve different problems. A practical comparison to help UK businesses pick the right one.
-
Blog & Articles
Black Box vs White Box Penetration Testing: Which Question Are You Trying to Answer?
Black box, white box and grey box penetration testing each answer a different question. Here is how to match the approach to what you actually need to know.
-
Google’s Gemini reached three live companies during a security test using a guessed password and leaked credentials. Here’s what to check in your own environment.