Threat research
What 1,728 Exploited Vulnerabilities Say About Patch Priorities
Our analysis of CISA's Known Exploited Vulnerabilities catalog: the vendors, flaw types and devices attackers use, and what it means for patching.
· 8 min read
// Network Pentest
External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.
Your external attack surface is whatever the internet can reach: firewalls, VPNs, mail servers, forgotten staging servers and cloud hosts someone spun up two years ago. Internal networks are what an attacker reaches after one phished laptop.
A network penetration test maps both, identifies exploitable weaknesses, and demonstrates, safely and within agreed rules, how far an attacker could get.
Read the full testing methodology.
// Process
A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.
Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.
A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.
Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.
// FAQ
No denial-of-service testing is performed unless explicitly agreed. Testing windows, rate limits and emergency contacts are agreed in the rules of engagement before anything starts.
You run a small, pre-configured virtual machine or device inside your network that we connect to over an encrypted tunnel. It’s removed at the end of the test.
Most major cloud providers no longer require pre-approval for testing your own resources, but some hosting companies do. We check this during scoping.
// Further reading
Threat research
Our analysis of CISA's Known Exploited Vulnerabilities catalog: the vendors, flaw types and devices attackers use, and what it means for patching.
· 8 min read
Penetration testing
A section-by-section guide to pentest reports (executive summary, scope, severity ratings, findings and retests) and how to turn one into a fix plan.
· 5 min read
Penetration testing
What penetration tests cost in 2026 by test type, how quotes are built from days and day rates, what drives the price, and how to spot a scan sold as a pentest.
· 5 min read
// Also available
An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.
Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.
A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.