A cyber security risk assessment ranks your threats by likelihood and impact so security spending goes where it matters most. Here is what it covers, who needs one, and how …
Blog & Articles
-
-
A jargon-free walk-through of what happens when you commission a penetration test, from agreeing the scope to fixing what’s found.
-
PCI DSS penetration testing requirements are more than one annual test. Where the checkbox approach falls short on internal, external, segmentation and remediation obligations, and how to fix it.
-
The headline cost of a data breach UK figure is real, but it describes a different kind of business than most readers run. Here’s the number that actually matters, and …
-
A Russian state-backed campaign against Zimbra webmail went straight for 2FA backup codes, not passwords. Here is why that part of MFA gets ignored, and what to do about it.
-
A practical breakdown of DORA’s two testing tiers, the annual baseline programme and threat-led penetration testing (TLPT), with a checklist for preparing either way.
-
A practitioner’s view on setting third party penetration testing requirements: what to ask suppliers and vendors for, how to tier them by risk, and where GDPR, ISO 27001 and PCI …
-
What a software supply chain attack actually looks like, why the numbers are rising fast, and a priority-ordered checklist UK businesses can act on this quarter.
-
DfE standards do not require it and Cyber Essentials does not test it. Here is what a penetration test for a school covers, and why the compliance gap matters.
-
An insider threat comes from someone who already has legitimate access to your systems. Here’s what the main types are, what they cost, and how to reduce your risk.