Security insights, written by offensive-security engineers.
What regulators actually require, how attackers actually break things, and what a real engagement should look like.
Penetration Testing for Nigerian Fintechs: What CBN and NDPR Actually Require
CBN's framework demands an independent annual pentest and board-visible remediation, while NDPR covers customer data. Here's how deep a real test needs to go and how to vet a pentest company.
Read articleISO 27001 Penetration Testing: What the Standard Actually Requires
ISO 27001:2022 never says "penetration testing," yet auditors expect one anyway. Here's what Annex A controls A.8.8 and A.8.29 actually require, and what evidence survives a Stage 2 audit.
Read articleERPNext Privilege Escalation: How a Low-Privilege Account Can Take Over the Whole System
A low-privilege ERPNext account was enough to become the Administrator — via server-side template injection. Here's the full chain, how Frappe fixed it, and what to do if you run ERPNext.
Read articleContinuous coverage. Expert-led pentests.
Move from once-a-year snapshots to a live security posture. Book a scoping call and we'll quote your first engagement within 48 hours.