Written by People Who Test for a Living.
Methodology, reporting, scoping, pricing and the awkward questions buyers ask consultancies. Practical pieces that take a position, aimed at the person doing the work.
Penetration Testing for a SaaS Startup: When to Start and What to Buy
The first test is usually bought because a customer asked. Here is when it is genuinely worth doing sooner, what to spend on it, and what enterprise buyers will ask for next.
PCI DSS Penetration Testing Requirements, in Plain Terms
PCI is the one standard that genuinely prescribes testing, and it is specific about scope, frequency and segmentation. What requirement 11.4 asks for and where assessors find gaps.
How Long a Penetration Test Takes, and Why Estimates Vary So Much
From first call to final report, with the parts nobody counts. What drives the testing days, how long reporting really takes, and where the calendar time goes that is not testing at all.
Internal or External Penetration Testing: What Each One Actually Tells You
They answer different questions and most organisations buy only one. What an external test proves, what it cannot, and why the internal one is usually the uncomfortable one.
Black Box, Grey Box or White Box: Which Test to Ask For
The three names describe how much the tester is told, and the choice changes what you get per day more than almost anything else in the scope.
What Happens After a Penetration Test
The report is the halfway point. How to triage what came back, what to fix first, what a retest proves, and what to tell the customer who asked for the test in the first place.
How to Prepare for a Penetration Test
Most overruns are caused before the first request is sent. The five things to have ready, the two decisions to make in advance, and what to tell your own team.
Choosing a Penetration Testing Provider: The Questions That Separate Them
Certifications and logos tell you less than eight specific questions do. What to ask, what a good answer sounds like, and the two answers that should end the conversation.
What a Penetration Test Report Should Contain
Section by section, what belongs in a report, what it is for, and the six things reports leave out that make them harder to act on than they need to be.