Straightforward writing on the things we get asked about most, with no filler and no sales pitch.
Penetration testing gets talked about a lot, but the actual process is often misunderstood. Here is what really happens from start to finish.
Read articleThe two get used as if they mean the same thing. They share techniques, but they answer different questions.
Read articlePreparation goes more smoothly when you treat SOC 2 as a project with a clear scope rather than a last-minute scramble.
Read articleMost businesses do not think about a security audit until something has already gone wrong. Here is how to tell if it is time before that happens.
Read articleThe worst time to decide who is in charge of a security incident is during one.
Read articleAPIs carry most of the sensitive data in modern applications and are tested less thoroughly than the interfaces built on top of them.
Read articleMost web application breaches trace back to a small set of well-known issues. Here is what to watch for.
Read articleSmart contracts hold real value, are public and usually cannot be patched once deployed. Review has to be part of development.
Read articleFirewalls and monitoring tools matter, but most breaches still start with a person clicking something they should not have.
Read articleA security policy sitting in a shared drive does not protect anyone. Security has to be something people actually do.
Read article