Blog

Written by People Who Test for a Living.

Methodology, reporting, scoping, pricing and the awkward questions buyers ask consultancies. Practical pieces that take a position, aimed at the person doing the work.

Business

Penetration Testing for a SaaS Startup: When to Start and What to Buy

The first test is usually bought because a customer asked. Here is when it is genuinely worth doing sooner, what to spend on it, and what enterprise buyers will ask for next.

Pental19 Aug 20264
Security

PCI DSS Penetration Testing Requirements, in Plain Terms

PCI is the one standard that genuinely prescribes testing, and it is specific about scope, frequency and segmentation. What requirement 11.4 asks for and where assessors find gaps.

Pental19 Aug 20264
Business

How Long a Penetration Test Takes, and Why Estimates Vary So Much

From first call to final report, with the parts nobody counts. What drives the testing days, how long reporting really takes, and where the calendar time goes that is not testing at all.

Pental19 Aug 20264
Security

Internal or External Penetration Testing: What Each One Actually Tells You

They answer different questions and most organisations buy only one. What an external test proves, what it cannot, and why the internal one is usually the uncomfortable one.

Pental19 Aug 20264
Methodology

Black Box, Grey Box or White Box: Which Test to Ask For

The three names describe how much the tester is told, and the choice changes what you get per day more than almost anything else in the scope.

Pental19 Aug 20264
Methodology

What Happens After a Penetration Test

The report is the halfway point. How to triage what came back, what to fix first, what a retest proves, and what to tell the customer who asked for the test in the first place.

Pental19 Aug 20264
Methodology

How to Prepare for a Penetration Test

Most overruns are caused before the first request is sent. The five things to have ready, the two decisions to make in advance, and what to tell your own team.

Pental19 Aug 20264
Business

Choosing a Penetration Testing Provider: The Questions That Separate Them

Certifications and logos tell you less than eight specific questions do. What to ask, what a good answer sounds like, and the two answers that should end the conversation.

Pental19 Aug 20264
Reporting

What a Penetration Test Report Should Contain

Section by section, what belongs in a report, what it is for, and the six things reports leave out that make them harder to act on than they need to be.

Pental19 Aug 20265

Written by the People Building the Platform.

Everything here comes out of real engagements. If you would rather see the product than read about the trade, the trial is seven days with no card.