What does a good pentesting tender look like?

Over the past few weeks, there has been a great deal of attention on the MIAUW framework. We recently published a blog about this. Previously, we also wrote a...Read more...

Blogs

  • How your site can be hacked through HTTP/1.1 and how to prevent it

    Security vulnerabilities can originate from many different sources. It can be an oversight or mistake from a developer, a flaw inherited from the architecture design, or an outdated third-party package to name a few. These are well-known vulnerability classes that can be mitigated through code review, automated...Read more...

  • COAST: A Shared Language for Tool Autonomy in Cybersecurity

    When rules of engagement say "automated tools are permitted," what does that actually authorise? When a vendor markets a product as "autonomous threat detection," what does that mean in practice? When a regulator asks whether a security operation was conducted with appropriate human oversight, what standard are they...Read more...

  • The CISO's guide to Threat-Led Penetration Testing - Blog 4: What a TLPT reveals that nothing else does

    After three blogs on frameworks, preparation, and pitfalls, the question a CISO reasonably asks is: what do I actually get out of this?
    Not in compliance terms. Not in framework deliverables. In genuine security insight.
    The answer is different for every organization. But in our experience running TIBER and TLPT...
    Read more...

  • The CISO's guide to Threat-Led Penetration Testing - Blog 3: Where TLPT trajectories go wrong, and how to avoid it

    A TLPT does not fail because the Red Team was not skilled enough. Poor Red Team quality is a real risk, and the strict qualification requirements in TIBER-EU exist for exactly that reason. But in our experience, the more common causes of failure are organizational: the organization was not ready, the wrong provider...Read more...

  • Human‑ vs. AI‑driven testing: when to use each option

    We are going to say something unusual for a security company: “Your next penetration test might not need us”. If an assessment scope fits the narrow circumstances in which AI‑powered tools operate, current tools deliver fast and affordable vulnerability discovery. We track them closely, we respect what they do, and in...Read more...

Questions or feedback?