Resources
Practical security buying guides.
Guides for teams using penetration testing to support compliance, product assurance and security decision-making.
ISO 27001 pentest evidence
How penetration testing supports ISO 27001 evidence, risk treatment and audit readiness, with practical guidance for SaaS and technology teams.
Read page →SOC 2SOC 2 pentest requirements
Practical SOC 2 penetration testing guidance for SaaS teams that need security evidence, remediation tracking and audit-ready reporting.
Read page →ChecklistAPI pentest checklist
A practical API penetration testing checklist covering REST, GraphQL, authentication, object authorisation, rate limits and data exposure.
Read page →Buying guideSubscription vs one-off pentest
Compare penetration testing subscriptions and one-off pentests for SaaS, compliance and fast-changing product teams.
Read page →Pricing guideUK pentest costs
A practical guide to UK penetration testing costs, what changes the price, and when a subscription is better than separate one-off tests.
Read page →PCI DSSPCI DSS pentest requirements
Practical PCI DSS penetration testing guidance for teams that need internal, external and segmentation testing evidence.
Read page →InfrastructureExternal penetration testing
What external penetration testing covers, how to scope internet-facing assets, and what a useful external pentest report should prove.
Read page →InfrastructureInternal penetration testing
A practical guide to internal penetration testing, assumed-breach starts, Active Directory, lateral movement and reporting.
Read page →Active DirectoryActive Directory pentesting
Active Directory penetration testing guidance covering privilege paths, ADCS, Kerberoasting, delegation, lateral movement and remediation evidence.
Read page →CloudAWS security review
What an AWS security review should cover across IAM, public exposure, storage, logging, networking, workloads and secrets.
Read page →API securityGraphQL API pentesting
GraphQL API penetration testing guidance covering introspection, object authorisation, batching, query depth, resolver behaviour and data exposure.
Read page →