Insights

Field notes from real engagements.

Notes on what we find, how we test, and what it means for the people who have to fix it.

IDOR is not dead, it just moved to your API
Object-level authorisation remains the most common critical we find. Why it survives code review, and the three checks that catch most cases.
Building a red team from scratch
What to hire first, what to buy, and the two years of groundwork nobody puts in the business case.
Compliance is not the same as secure
Passing an audit and resisting an attacker are different objectives. Where they overlap, and where treating them as one gets expensive.
Reading a pentest report as a board member
Which numbers matter, which are theatre, and the four questions to ask your security lead after a report lands.
Threat modelling without a two-day workshop
A lightweight version your engineers will actually run each quarter, and the three artefacts worth keeping.
Why awareness training keeps failing
Annual click-through modules do not change behaviour. What measurably does, based on 6,000 people trained.
Mailing list

New writing and open cohort dates.

Roughly monthly. Field notes, course announcements, and nothing else: no drip campaign.

Unsubscribe in one click. We never share or resell your address.