What to demand from an ecommerce penetration test, why PCI compliance alone is not enough, and the questions that separate a real test from a relabelled one.
penetration testing
-
-
Red team, blue team and purple team explained as a practical decision, not just a definition: what each one assumes you already have, and what to commission next.
-
Six direct questions that separate a penetration testing company that will genuinely test your systems from one selling a repackaged vulnerability scan.
-
A practical action plan for UK businesses that have spotted NIS2 in an EU customer contract: what Article 21 expects from testing, how often, and what evidence to keep ready.
-
A practitioner’s view of what to prepare for a penetration test: scope, access, cloud provider rules and who needs to know before testing begins.
-
TerminalFix’s exotic technical detail hides a simpler truth: a fake CAPTCHA still works, and what decides the outcome is whether anyone notices what happens after the click.
-
A practical checklist for writing a vulnerability disclosure policy: what to include, what UK product security law now requires, and how it differs from a bug bounty programme or a …
-
Vendors sell badges, but no accredited penetration testing certificate exists. What a proper report and attestation letter contain, and why the distinction matters at audit time.
-
SonicWall’s second exploited SMA zero-day chain this year is a reminder that perimeter VPN appliances need testing and hardening, not just a patch cycle.
-
CBEST and STAR-FS grab the headlines, but most FCA-regulated firms need a different answer. Here is what operational resilience testing actually requires if you’re not a systemically important bank.