1. Home
  2. Insights
Insights

Practical notes from the work

No thought-leadership, no predictions. Just the problems we get asked about most often, written up so you can act on them without hiring anyone.

Web 6 min read

What a web application penetration test actually covers

Most scoping documents list the same six bullet points. Here is what those bullets really mean, and which one is usually where the serious findings are hiding.

Read the article
Mobile 6 min read

Android and iOS fail differently

Treating mobile as one platform means missing the interesting parts. The two ecosystems have genuinely different failure modes, and the test plan should reflect that.

Read the article
Network 6 min read

Where network penetration tests still find real problems

External testing tells you how hard you are to enter. Internal testing tells you what happens next — and that is where the damage usually is.

Read the article
AI security 7 min read

Prompt injection: the attack surface nobody scoped

Language models have no reliable distinction between data and instructions. That single property undermines a lot of assumptions your existing security controls are built on.

Read the article
Threat detection 6 min read

Detection is a tuning problem, not a tool problem

A platform that fires four hundred alerts a week gets muted within a month. Alert quality, not coverage, is what decides whether detection actually works.

Read the article
Red teaming 6 min read

Red teaming vs penetration testing: what is the difference?

One asks "what is broken?". The other asks "can a motivated adversary reach a specific goal?". The distinction changes how you scope, measure and get value from the work.

Read the article

Want this applied to your environment?

Reading about it is a good start. A 30-minute review will tell you which of these actually applies to you.

Book a security review