A practical checklist for writing a vulnerability disclosure policy: what to include, what UK product security law now requires, and how it differs from a bug bounty programme or a …
penetration testing
-
-
Vendors sell badges, but no accredited penetration testing certificate exists. What a proper report and attestation letter contain, and why the distinction matters at audit time.
-
SonicWall’s second exploited SMA zero-day chain this year is a reminder that perimeter VPN appliances need testing and hardening, not just a patch cycle.
-
CBEST and STAR-FS grab the headlines, but most FCA-regulated firms need a different answer. Here is what operational resilience testing actually requires if you’re not a systemically important bank.
-
The 2025 OWASP Top 10 is a solid, data-driven baseline for web application risk. Here’s what changed since 2021, and why it should be a floor, not a ceiling.
-
Why framing in-house vs outsourced penetration testing as an either-or choice misses the point, and the hybrid model most UK businesses should actually run.
-
A practical guide to choosing between SAST, DAST and penetration testing, based on what you actually run, what you need to prove, and where to spend your first pound of …
-
Most penetration test disputes trace back to a thin scope of work. Here is what a proper one pins down, why vague scoping backfires, and how it differs from your …
-
Continuous threat exposure management (CTEM) is a genuinely useful framework buried under heavy marketing. Here’s what it actually requires, and where a dashboard alone falls short.
-
Threat modelling is how you work out where a system could be attacked before it’s built or tested. Here’s how it works, the main methodologies, and how it relates to …