CHECK penetration testing is the NCSC’s accreditation for testers working on UK government and CNI systems. Here’s why it exists, who must use it, and how it stacks up against …
penetration testing
-
-
A buyer’s guide to assumed breach penetration testing: how it works, how it differs from a standard test or red team, and how to tell if your organisation is ready …
-
A quick way to work out whether your organisation needs ICS or SCADA penetration testing, who a genuine OT specialist looks like, and how to scope a safe first engagement.
-
A checklist-style guide to what a penetration testing rules of engagement document should contain, who needs to sign it, and what happens when it’s skipped.
-
Zero trust security stops one stolen password from reaching everything else. Here is what it takes in practice, a realistic starting checklist, and the mistakes businesses make along the way.
-
The NHS Data Security and Protection Toolkit now expects independent, evidenced penetration testing rather than a self-declared tick box. Here’s who it applies to and what a compliant report needs.
-
Blog & Articles
Breach and Attack Simulation vs Penetration Testing: Don’t Believe the “Continuous Pen Test” Pitch
BAS vendors call it continuous penetration testing. It isn’t. Here’s what breach and attack simulation vs penetration testing actually measures, and why you still need both.
-
SOC 2 never uses the words “penetration test” but most auditors expect one anyway. Here is what CC4.1 actually requires, how often to test, and what a Type II audit …
-
The Cyber Security and Resilience Bill never says the words penetration test, yet regulators will expect one. Here is the gap between the law and what it actually means for …
-
Blog & Articles
Your DSPT Says ‘Standards Met’ on Penetration Testing. Does the Evidence Back That Up?
A vulnerability scan is not a penetration test, and NHS England’s own DSPT guidance says so. Here’s where submissions actually fall short, and how to fix it before an auditor …