A practitioner’s view of what to prepare for a penetration test: scope, access, cloud provider rules and who needs to know before testing begins.
Blog & Articles
-
-
A CVE identifies a vulnerability, nothing more. Here is why treating the number itself as a severity signal leads to the wrong patch order, and what should drive it instead.
-
A practical checklist for writing a vulnerability disclosure policy: what to include, what UK product security law now requires, and how it differs from a bug bounty programme or a …
-
PCI DSS treats network segmentation as a control you must prove, not assume. Here is what segmentation testing covers, how often you need it, and what auditors expect to see.
-
Vendors sell badges, but no accredited penetration testing certificate exists. What a proper report and attestation letter contain, and why the distinction matters at audit time.
-
Cyber Essentials is a self-signed questionnaire. Cyber Essentials Plus is what happens when someone actually checks it. An honest look at what each proves, what CE+ tests, and who really …
-
CBEST and STAR-FS grab the headlines, but most FCA-regulated firms need a different answer. Here is what operational resilience testing actually requires if you’re not a systemically important bank.
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Why framing in-house vs outsourced penetration testing as an either-or choice misses the point, and the hybrid model most UK businesses should actually run.
-
A practical guide to choosing between SAST, DAST and penetration testing, based on what you actually run, what you need to prove, and where to spend your first pound of …