Plain-English security writing
No fear-mongering, no acronym soup. The questions Australian teams ask before they buy a test, written down so you can brief a vendor, including us.
How to scope a web application penetration test
What to put in the rules of engagement, which roles to include, and how to avoid buying a test that misses the actual risk.
Read post >APRA CPS 234 and security testing: what actually satisfies the standard
How APRA-regulated entities should brief a pentest so the report maps to information-security control testing, not a generic scan.
Read post >Essential Eight and penetration testing: how they fit together
The ACSC maturity model is a control program. A pentest is how you find out whether those controls survive a motivated attacker.
Read post >ISO 27001 penetration testing in Australia
Where independent testing sits in Annex A, what auditors actually look for in a report, and how often to retest.
Read post >How much does a penetration test cost in Australia?
Typical price ranges for Australian pentests, what drives the cost up or down, and how to compare quotes properly.
Read post >Penetration testing vs vulnerability scanning: what's the difference?
Both find security problems, but they answer different questions. When a scan is enough, and when you need a human attacker.
Read post >What is penetration testing? A plain-English guide
What actually happens during a pentest, what you get at the end, and how to tell a real one from a rebadged scan.
Read post >