Insights
Field notes from real engagements.
Notes on what we find, how we test, and what it means for the people who have to fix it.
What most external pentests miss
Four categories of finding that automated platforms structurally cannot reach, with anonymised examples from engagements where each one led to full compromise.
IDOR is not dead, it just moved to your API
Object-level authorisation remains the most common critical we find. Why it survives code review, and the three checks that catch most cases.
Building a red team from scratch
What to hire first, what to buy, and the two years of groundwork nobody puts in the business case.
Compliance is not the same as secure
Passing an audit and resisting an attacker are different objectives. Where they overlap, and where treating them as one gets expensive.
Reading a pentest report as a board member
Which numbers matter, which are theatre, and the four questions to ask your security lead after a report lands.
Threat modelling without a two-day workshop
A lightweight version your engineers will actually run each quarter, and the three artefacts worth keeping.
Why awareness training keeps failing
Annual click-through modules do not change behaviour. What measurably does, based on 6,000 people trained.
Mailing list
New writing and open cohort dates.
Roughly monthly. Field notes, course announcements, and nothing else: no drip campaign.
Subscribed.
You'll hear from us when there is something worth reading.