The NHS Data Security and Protection Toolkit now expects independent, evidenced penetration testing rather than a self-declared tick box. Here’s who it applies to and what a compliant report needs.
Blog & Articles
-
-
Blog & Articles
Breach and Attack Simulation vs Penetration Testing: Don’t Believe the “Continuous Pen Test” Pitch
BAS vendors call it continuous penetration testing. It isn’t. Here’s what breach and attack simulation vs penetration testing actually measures, and why you still need both.
-
SOC 2 never uses the words “penetration test” but most auditors expect one anyway. Here is what CC4.1 actually requires, how often to test, and what a Type II audit …
-
The Cyber Security and Resilience Bill never says the words penetration test, yet regulators will expect one. Here is the gap between the law and what it actually means for …
-
Blog & Articles
Your DSPT Says ‘Standards Met’ on Penetration Testing. Does the Evidence Back That Up?
A vulnerability scan is not a penetration test, and NHS England’s own DSPT guidance says so. Here’s where submissions actually fall short, and how to fix it before an auditor …
-
Blog & Articles
Penetration Testing vs Security Audit: What UK Compliance Frameworks Actually Require
ISO 27001, PCI DSS and cyber insurers each treat audits and penetration tests differently. Here is what each one checks, what the frameworks require, and which to book first.
-
A strong password does not stop credential stuffing, because the attacker already has a valid one from another breach. Here is what actually works instead.
-
How to budget for a vulnerability assessment: what sets the price, a simple pricing table, and a checklist to run through before accepting any quote.
-
An unpatched Magento vulnerability is being exploited to backdoor stores with no login needed. Here’s how to check for compromise and cut your risk before a patch exists.
-
Black box penetration testing is often assumed to be the toughest, most realistic option. Here is why that assumption is frequently wrong, and how to choose properly.