- Home
- Insights
Practical notes from the work
No thought-leadership, no predictions. Just the problems we get asked about most often, written up so you can act on them without hiring anyone.
What a web application penetration test actually covers
Most scoping documents list the same six bullet points. Here is what those bullets really mean, and which one is usually where the serious findings are hiding.
Read the articleAndroid and iOS fail differently
Treating mobile as one platform means missing the interesting parts. The two ecosystems have genuinely different failure modes, and the test plan should reflect that.
Read the articleWhere network penetration tests still find real problems
External testing tells you how hard you are to enter. Internal testing tells you what happens next — and that is where the damage usually is.
Read the articlePrompt injection: the attack surface nobody scoped
Language models have no reliable distinction between data and instructions. That single property undermines a lot of assumptions your existing security controls are built on.
Read the articleDetection is a tuning problem, not a tool problem
A platform that fires four hundred alerts a week gets muted within a month. Alert quality, not coverage, is what decides whether detection actually works.
Read the articleRed teaming vs penetration testing: what is the difference?
One asks "what is broken?". The other asks "can a motivated adversary reach a specific goal?". The distinction changes how you scope, measure and get value from the work.
Read the articleWant this applied to your environment?
Reading about it is a good start. A 30-minute review will tell you which of these actually applies to you.