Resources

Practical security buying guides.

Guides for teams using penetration testing to support compliance, product assurance and security decision-making.

ISO 27001

ISO 27001 pentest evidence

How penetration testing supports ISO 27001 evidence, risk treatment and audit readiness, with practical guidance for SaaS and technology teams.

Read page
SOC 2

SOC 2 pentest requirements

Practical SOC 2 penetration testing guidance for SaaS teams that need security evidence, remediation tracking and audit-ready reporting.

Read page
Checklist

API pentest checklist

A practical API penetration testing checklist covering REST, GraphQL, authentication, object authorisation, rate limits and data exposure.

Read page
Buying guide

Subscription vs one-off pentest

Compare penetration testing subscriptions and one-off pentests for SaaS, compliance and fast-changing product teams.

Read page
Pricing guide

UK pentest costs

A practical guide to UK penetration testing costs, what changes the price, and when a subscription is better than separate one-off tests.

Read page
PCI DSS

PCI DSS pentest requirements

Practical PCI DSS penetration testing guidance for teams that need internal, external and segmentation testing evidence.

Read page
Infrastructure

External penetration testing

What external penetration testing covers, how to scope internet-facing assets, and what a useful external pentest report should prove.

Read page
Infrastructure

Internal penetration testing

A practical guide to internal penetration testing, assumed-breach starts, Active Directory, lateral movement and reporting.

Read page
Active Directory

Active Directory pentesting

Active Directory penetration testing guidance covering privilege paths, ADCS, Kerberoasting, delegation, lateral movement and remediation evidence.

Read page
Cloud

AWS security review

What an AWS security review should cover across IAM, public exposure, storage, logging, networking, workloads and secrets.

Read page
API security

GraphQL API pentesting

GraphQL API penetration testing guidance covering introspection, object authorisation, batching, query depth, resolver behaviour and data exposure.

Read page