Ransomware isn’t getting more sophisticated, it’s getting more industrialised. Here’s how the criminal supply chain behind it works, and why the same basic gaps keep letting it in.
penetration testing
-
-
A practical guide to running a business impact assessment: NIST’s three-step process, setting real recovery targets, and turning the results into action.
-
An insider threat comes from anyone with legitimate access to your systems, whether they mean harm or not. Here’s how to spot one and reduce your risk.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
Blog & Articles
Is Penetration Testing Legal in the UK? Why Authorisation Is the Only Thing That Makes It So
Strip away the tooling and the reputation, and a penetration test technically matches the definition of a crime under the Computer Misuse Act. Here is why authorisation is the only …
-
Two chained Microsoft SharePoint flaws, patched in July and August, let an attacker take over an on-premises server without any credentials at all.
-
A practical checklist for scoping SC cleared penetration testing: when the CHECK scheme makes it mandatory, why CREST accreditation isn’t the same thing, and what to ask suppliers before you …
-
A buyer’s guide to penetration testing methodology: what a proper process includes, red flags in a weak one, and the questions to ask before you commission a test.
-
The OWASP Top 10 was rebuilt for 2025. Here is what moved, what is new, and the questions worth asking before your next web application penetration test.
-
The Certighost AD CS privilege escalation bug will get patched. The Windows default that made it possible, an unreviewed machine account quota, will not fix itself.