Resources from
the field.
Practical writing for pentest companies and their clients: how to scope, fix and prove.
What a good pentest scope looks like
Too narrow and you miss the real attack paths. Too broad and testers spread thin. Here is how to get it right.
Read article →Pentest or continuous project?
A pentest answers a point-in-time question. A continuous project keeps scanning on a cadence. Most clients need both.
Read →Reading a CVSS score without the panic
A 9.8 is not always your top priority. How to combine CVSS with exploitability and business context.
Read →Segmentation testing under PCI DSS v4.0
What requirements 11.4.5 and 11.4.6 ask for, and the evidence your QSA expects to see.
Read →Why every finding needs a retest
A ticket marked done is not a fixed vulnerability. Only a retest can prove it.
Read →Red team or pentest: which do you need?
A pentest finds as many weaknesses as possible. A red team tests whether you can stop a real attack.
Read →A platform for pentest companies and their clients. The pentest company runs its engagements in the Team Console, and its clients follow findings, disputes, retests and reports in the Client Portal.
Penetration tests, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements. Vulnerability assessments and PCI ASV scanning run as continuous projects, in cycles.
Pentest findings are scored with CVSS 3.1. A tester can override the calculated severity with a written justification.
Yes. Results import from Nessus, Nexpose, Burp, Acunetix and CSV, and scans can be launched in Nessus, Nexpose and Burp Pro.
When a fix is ready, the client requests a retest in the Client Portal and the pentest company records the result. In continuous projects, verification scans flag findings that look fixed, for an analyst to confirm.
Only what has been published to them: findings with their evidence and SLA due dates, cycle and scan status, and reports. Evidence marked internal stays with the pentest company.
From the engagement record, on HTML or Word templates set up for your company, and delivered as password-protected PDFs.
Multi-factor authentication on every account, single sign-on with Microsoft Entra ID for staff, role-based permissions and an append-only audit log.
Security testing, in plain words.
23 terms- ASV
- Approved Scanning Vendor: a company approved by the PCI SSC to run external vulnerability scans for PCI DSS.
- Attack surface
- Every system, service and entry point an attacker could try to reach.
- Attestation of Scan Compliance
- The PCI ASV document that confirms a quarter's external scans passed.
- CDE
- Cardholder data environment: the people, processes and systems that store, process or transmit card data.
- CISA KEV
- The US CISA catalogue of vulnerabilities known to be exploited in the wild.
- Continuous project
- Recurring vulnerability assessment or PCI ASV work, run as cycles on a set cadence.
- CVSS
- Common Vulnerability Scoring System: a standard 0 to 10 score for technical severity. Version 4.0 is the latest; 3.1 is still the most widely used.
- EPSS
- Exploit Prediction Scoring System: the estimated probability a vulnerability will be exploited in the next 30 days.
- Exploit chain
- Several weaknesses combined so that, together, they achieve more than any one alone.
- False positive
- A reported vulnerability that turns out not to be real. Removing these is part of triage.
- Lateral movement
- Moving from one compromised system to others inside a network.
- MITRE ATT&CK
- A public knowledge base of real attacker tactics and techniques.
- OWASP
- Open Worldwide Application Security Project: publishes the Top 10, WSTG and ASVS standards.
- Penetration test
- A scoped, manual test where testers try to find and exploit weaknesses before attackers do.
- Purple teaming
- Attackers and defenders working together to replay attacks and improve detection.
- QSA
- Qualified Security Assessor: an auditor approved to assess PCI DSS compliance.
- Red teaming
- An objective-led simulation of a real adversary that tests people, process and detection.
- Retest
- Repeating the original attack against a fix to prove the vulnerability is closed.
- Rules of engagement
- The agreed scope, windows, exclusions and contacts for a test.
- Segmentation testing
- Testing that proves sensitive networks are isolated from the rest of the environment.
- Threat-led testing
- Testing designed around the specific threat actors likely to target an organisation.
- Verification scan
- A rescan that checks whether findings from an earlier scan have been fixed.
- Vulnerability assessment
- Scanning-led discovery of known weaknesses, triaged and prioritised by a tester.