[{"data":1,"prerenderedAt":1657},["ShallowReactive",2],{"news-\u002Fblog\u002Fapi-security-common-failures":3,"news-related-posts":88},{"id":4,"title":5,"authors":6,"body":12,"date":74,"description":75,"draft":76,"extension":77,"image":78,"meta":79,"navigation":80,"path":81,"seo":82,"stem":83,"tags":84,"__hash__":87},"news\u002F3.blog\u002F2025\u002Fapi-security-common-failures.md","The API Security Failures We Keep Finding",[7],{"name":8,"to":9,"avatar":10},"Max Snow","https:\u002F\u002Fpensure.ai",{"src":11},"\u002Fimages\u002Fteam\u002Fmax-snow.jpg",{"type":13,"value":14,"toc":66},"minimark",[15,19,24,41,45,52,56,59,63],[16,17,18],"p",{},"APIs are where modern applications actually live — and where most of the interesting findings come from. Across engagements, the same patterns recur with remarkable consistency.",[20,21,23],"h2",{"id":22},"broken-object-level-authorization","Broken Object Level Authorization",[16,25,26,27,31,32,35,36,40],{},"The single most common API vulnerability. An endpoint like ",[28,29,30],"code",{},"GET \u002Fapi\u002Finvoices\u002F1042"," checks that you're logged in, but not that invoice ",[28,33,34],{},"1042"," belongs to ",[37,38,39],"em",{},"you",". Sequential IDs make it trivially exploitable; UUIDs merely make it less discoverable, not less broken.",[20,42,44],{"id":43},"excessive-data-exposure","Excessive Data Exposure",[16,46,47,48,51],{},"The endpoint returns the full database object and trusts the client to display only what's needed. Internal flags, other users' email addresses, and soft-deleted records all end up one ",[28,49,50],{},"curl"," away.",[20,53,55],{"id":54},"unprotected-non-production-environments","Unprotected Non-Production Environments",[16,57,58],{},"Staging APIs with production data, debug endpoints left enabled, or v1 routes kept alive \"temporarily\" after v2 shipped. Attack surface you've forgotten about is attack surface you're not defending.",[20,60,62],{"id":61},"what-to-do","What To Do",[16,64,65],{},"Enforce authorization at the object level in one place, return explicit response schemas rather than raw models, and inventory every deployed environment. Then test continuously — API surface changes with every release.",{"title":67,"searchDepth":68,"depth":68,"links":69},"",2,[70,71,72,73],{"id":22,"depth":68,"text":23},{"id":43,"depth":68,"text":44},{"id":54,"depth":68,"text":55},{"id":61,"depth":68,"text":62},"2025-06-17T00:00:00.000Z","APIs now carry the majority of application traffic, and the same handful of vulnerability patterns appear in engagement after engagement. Here are the most common ones and how to avoid them.",false,"md",null,{},true,"\u002Fblog\u002Fapi-security-common-failures",{"title":5,"description":75},"3.blog\u002F2025\u002Fapi-security-common-failures",[85,86],"API Security","Web Security","yiIFoEjtVQWTwECouT7NuUG05nqKA8XC-OYU2U54t4c",[89,156,197,263,334,388,634,713,786,856,929,1169,1253,1363,1521],{"id":90,"title":91,"authors":92,"body":95,"date":146,"description":147,"draft":76,"extension":77,"image":78,"meta":148,"navigation":80,"path":149,"seo":150,"stem":151,"tags":152,"__hash__":155},"news\u002F3.blog\u002F2025\u002Fai-in-offensive-security.md","What AI Actually Changes in Offensive Security",[93],{"name":8,"to":9,"avatar":94},{"src":11},{"type":13,"value":96,"toc":141},[97,100,104,127,131,134,138],[16,98,99],{},"Every security vendor now claims to be \"AI-powered\". It's worth being precise about what AI genuinely changes in offensive security today — and what it doesn't.",[20,101,103],{"id":102},"where-ai-delivers-now","Where AI Delivers Now",[105,106,107,115,121],"ul",{},[108,109,110,114],"li",{},[111,112,113],"strong",{},"Reconnaissance at scale."," Enumerating attack surface, correlating exposed assets, and prioritising targets is pattern-matching work that AI handles faster and more thoroughly than manual effort.",[108,116,117,120],{},[111,118,119],{},"Breadth of coverage."," AI-driven testing can exercise every endpoint and parameter on every release, a cadence no human team can sustain.",[108,122,123,126],{},[111,124,125],{},"Triage and deduplication."," Clustering raw findings, filtering false positives, and drafting remediation guidance dramatically reduces reporting overhead.",[20,128,130],{"id":129},"where-humans-still-win","Where Humans Still Win",[16,132,133],{},"Business logic abuse, novel exploit chains, and judgement calls about real-world impact remain human strengths. An AI can find the missing authorization check; a human recognises that combining it with the export feature exposes your entire customer list.",[20,135,137],{"id":136},"the-model-that-works","The Model That Works",[16,139,140],{},"For complex, regulated or high-risk environments, the effective pattern combines AI-powered breadth with expert testers directing depth. That is the Core Plus model: a specialist penetration tester actively investigates complex attack paths and applies expert human judgement.",{"title":67,"searchDepth":68,"depth":68,"links":142},[143,144,145],{"id":102,"depth":68,"text":103},{"id":129,"depth":68,"text":130},{"id":136,"depth":68,"text":137},"2025-11-12T00:00:00.000Z","Beyond the hype, AI is reshaping specific parts of the penetration testing workflow — reconnaissance, coverage, and triage — while leaving others firmly human. A grounded look at the current state.",{},"\u002Fblog\u002Fai-in-offensive-security",{"title":91,"description":147},"3.blog\u002F2025\u002Fai-in-offensive-security",[153,154],"AI","Penetration Testing","3L-2PcjI9Uf9-wPt-4aRhpXmcuPqE9yQuXOaE9ebsHQ",{"id":4,"title":5,"authors":157,"body":160,"date":74,"description":75,"draft":76,"extension":77,"image":78,"meta":194,"navigation":80,"path":81,"seo":195,"stem":83,"tags":196,"__hash__":87},[158],{"name":8,"to":9,"avatar":159},{"src":11},{"type":13,"value":161,"toc":188},[162,164,166,174,176,180,182,184,186],[16,163,18],{},[20,165,23],{"id":22},[16,167,26,168,31,170,35,172,40],{},[28,169,30],{},[28,171,34],{},[37,173,39],{},[20,175,44],{"id":43},[16,177,47,178,51],{},[28,179,50],{},[20,181,55],{"id":54},[16,183,58],{},[20,185,62],{"id":61},[16,187,65],{},{"title":67,"searchDepth":68,"depth":68,"links":189},[190,191,192,193],{"id":22,"depth":68,"text":23},{"id":43,"depth":68,"text":44},{"id":54,"depth":68,"text":55},{"id":61,"depth":68,"text":62},{},{"title":5,"description":75},[85,86],{"id":198,"title":199,"authors":200,"body":203,"date":254,"description":255,"draft":76,"extension":77,"image":78,"meta":256,"navigation":80,"path":257,"seo":258,"stem":259,"tags":260,"__hash__":262},"news\u002F3.blog\u002F2025\u002Fcontinuous-pentesting-vs-annual-audits.md","Continuous Penetration Testing vs the Annual Audit",[201],{"name":8,"to":9,"avatar":202},{"src":11},{"type":13,"value":204,"toc":249},[205,208,212,215,219,239,243,246],[16,206,207],{},"Most organisations still run penetration tests on an annual cycle, usually driven by compliance deadlines. But modern teams ship code daily. A report that was accurate in January says very little about the application you're running in June.",[20,209,211],{"id":210},"the-problem-with-point-in-time-testing","The Problem with Point-in-Time Testing",[16,213,214],{},"A traditional engagement captures a snapshot. Every deploy after the report lands can introduce new attack surface: a new endpoint, a changed permission model, a third-party dependency bump. None of it is tested until the next annual cycle.",[20,216,218],{"id":217},"what-continuous-testing-changes","What Continuous Testing Changes",[105,220,221,227,233],{},[108,222,223,226],{},[111,224,225],{},"Coverage tracks your release cadence."," New surface is assessed as it ships, not months later.",[108,228,229,232],{},[111,230,231],{},"Findings arrive as a stream, not a batch."," Small, regular remediation work beats a 40-page report that lands on one sprint.",[108,234,235,238],{},[111,236,237],{},"Trends become visible."," You can see whether your security posture is improving quarter over quarter.",[20,240,242],{"id":241},"the-hybrid-reality","The Hybrid Reality",[16,244,245],{},"Continuous testing doesn't eliminate the need for deep, human-led engagements — it changes what they're for. Automated and AI-assisted testing handles regression coverage and breadth; expert testers focus on depth, chained attacks, and business logic.",[16,247,248],{},"The annual audit becomes one milestone in an ongoing programme rather than the entire programme.",{"title":67,"searchDepth":68,"depth":68,"links":250},[251,252,253],{"id":210,"depth":68,"text":211},{"id":217,"depth":68,"text":218},{"id":241,"depth":68,"text":242},"2025-04-08T00:00:00.000Z","Annual penetration tests leave months-long blind spots between engagements. Continuous testing closes that gap — here's how the two models compare in practice.",{},"\u002Fblog\u002Fcontinuous-pentesting-vs-annual-audits",{"title":199,"description":255},"3.blog\u002F2025\u002Fcontinuous-pentesting-vs-annual-audits",[154,261],"Strategy","j4ksFsUZ8tnC-cLh9VQbXBOSyvZOAXMPTQAM4nPHdCo",{"id":264,"title":265,"authors":266,"body":269,"date":325,"description":326,"draft":76,"extension":77,"image":78,"meta":327,"navigation":80,"path":328,"seo":329,"stem":330,"tags":331,"__hash__":333},"news\u002F3.blog\u002F2025\u002Fowasp-top-10-primer.md","A Practical Primer on the OWASP Top 10",[267],{"name":8,"to":9,"avatar":268},{"src":11},{"type":13,"value":270,"toc":320},[271,274,278,281,285,310,314,317],[16,272,273],{},"The OWASP Top 10 is often the first framework teams reach for when thinking about application security. Used well, it's an excellent foundation. Used poorly, it becomes a compliance checkbox that gives a false sense of coverage.",[20,275,277],{"id":276},"what-the-top-10-actually-is","What the Top 10 Actually Is",[16,279,280],{},"The Top 10 is an awareness document, not a testing standard. It ranks the most common categories of web application risk — injection, broken access control, cryptographic failures, and so on — based on real-world incident and vulnerability data.",[20,282,284],{"id":283},"using-it-effectively","Using It Effectively",[286,287,288,294,300],"ol",{},[108,289,290,293],{},[111,291,292],{},"Map categories to your stack."," Broken access control looks very different in a multi-tenant SaaS product than in an internal admin tool.",[108,295,296,299],{},[111,297,298],{},"Prioritise by exposure."," Internet-facing authentication flows deserve more scrutiny than internal reporting endpoints.",[108,301,302,305,306,309],{},[111,303,304],{},"Go beyond the list."," Business logic flaws — the vulnerabilities unique to ",[37,307,308],{},"your"," application — rarely fit neatly into a Top 10 category, and they're where skilled testers earn their keep.",[20,311,313],{"id":312},"where-automated-testing-fits","Where Automated Testing Fits",[16,315,316],{},"Automated scanning covers the repetitive, well-understood portions of the Top 10 quickly and continuously. Human expertise is best spent on access control logic, chained exploits, and context-dependent issues that tools can't reason about.",[16,318,319],{},"A mature programme combines both: continuous automated coverage as the floor, with expert-led testing raising the ceiling.",{"title":67,"searchDepth":68,"depth":68,"links":321},[322,323,324],{"id":276,"depth":68,"text":277},{"id":283,"depth":68,"text":284},{"id":312,"depth":68,"text":313},"2025-02-20T00:00:00.000Z","The OWASP Top 10 remains the most widely used baseline for web application security. Here's how to use it as a starting point for your testing programme rather than a checkbox exercise.",{},"\u002Fblog\u002Fowasp-top-10-primer",{"title":265,"description":326},"3.blog\u002F2025\u002Fowasp-top-10-primer",[86,332],"Fundamentals","ymxGzn2idOCTv18lNd-o-bwZpBq5j8CdVFT-_6RoUtY",{"id":335,"title":336,"authors":337,"body":340,"date":379,"description":380,"draft":76,"extension":77,"image":78,"meta":381,"navigation":80,"path":382,"seo":383,"stem":384,"tags":385,"__hash__":387},"news\u002F3.blog\u002F2025\u002Freading-a-pentest-report.md","How to Actually Read a Penetration Test Report",[338],{"name":8,"to":9,"avatar":339},{"src":11},{"type":13,"value":341,"toc":373},[342,345,349,352,356,359,363,366,370],[16,343,344],{},"A penetration test report that sits unread in a shared drive delivers exactly zero security value. The report is the start of the work, not the end of it.",[20,346,348],{"id":347},"start-with-context-not-severity","Start with Context, Not Severity",[16,350,351],{},"CVSS scores are a useful baseline, but they don't know your business. A \"medium\" finding on your payment flow may matter far more than a \"high\" on an internal tool behind a VPN. Re-rank findings against your actual exposure and data sensitivity.",[20,353,355],{"id":354},"look-for-chains","Look for Chains",[16,357,358],{},"The most dangerous outcomes are rarely single findings. Read the attack narrative sections carefully: an information disclosure plus a weak session control plus a permissive CORS policy can add up to full account takeover, even if each finding alone looks modest.",[20,360,362],{"id":361},"fix-classes-not-instances","Fix Classes, Not Instances",[16,364,365],{},"If the report lists five instances of missing authorization checks, the real finding is that your framework doesn't enforce authorization by default. Fix the pattern and you fix the next ten instances before they're written.",[20,367,369],{"id":368},"close-the-loop","Close the Loop",[16,371,372],{},"Schedule retesting for every finding you remediate. A fix that hasn't been verified is a hypothesis, not a fix.",{"title":67,"searchDepth":68,"depth":68,"links":374},[375,376,377,378],{"id":347,"depth":68,"text":348},{"id":354,"depth":68,"text":355},{"id":361,"depth":68,"text":362},{"id":368,"depth":68,"text":369},"2025-09-02T00:00:00.000Z","A penetration test report is only valuable if it drives remediation. Here's how to triage findings, challenge severity ratings, and turn a report into an actionable plan.",{},"\u002Fblog\u002Freading-a-pentest-report",{"title":336,"description":380},"3.blog\u002F2025\u002Freading-a-pentest-report",[154,386],"Remediation","NYZBt7DgwlV1XGFyW0E8D_sJY_lfeHnqCT26NfmD678",{"id":389,"title":390,"authors":391,"body":394,"date":625,"description":626,"draft":76,"extension":77,"image":78,"meta":627,"navigation":80,"path":628,"seo":629,"stem":630,"tags":631,"__hash__":633},"news\u002F3.blog\u002F2025\u002Funderstanding-zero-day-vulnerabilities.md","Understanding Zero-Day Vulnerabilities in Modern Security Systems",[392],{"name":8,"to":9,"avatar":393},{"src":11},{"type":13,"value":395,"toc":591},[396,399,402,406,409,414,434,436,440,447,450,457,460,467,470,472,476,482,485,491,494,500,503,505,509,512,518,521,527,530,536,539,546,549,551,555,575,577,581,584,586],[16,397,398],{},"In the rapidly evolving landscape of cybersecurity, one of the most critical threats that organizations face is zero-day vulnerabilities. These vulnerabilities, named for the fact that developers have zero days to fix them before they are exploited, represent a unique challenge to modern security systems. In this blog, we'll delve into what zero-day vulnerabilities are, why they are so dangerous, and how organizations can defend against them.",[400,401],"hr",{},[20,403,405],{"id":404},"what-are-zero-day-vulnerabilities","What Are Zero-Day Vulnerabilities?",[16,407,408],{},"A zero-day vulnerability refers to a security flaw in software or hardware that is unknown to the vendor or developer. Because the vulnerability is not publicly disclosed or addressed, attackers can exploit it to gain unauthorized access, deploy malware, or disrupt system operations. The term \"zero-day\" highlights the critical window of time where a fix is unavailable, leaving systems exposed.",[410,411,413],"h3",{"id":412},"characteristics-of-zero-day-vulnerabilities","Characteristics of Zero-Day Vulnerabilities:",[286,415,416,422,428],{},[108,417,418,421],{},[111,419,420],{},"Unknown to the Vendor:"," These vulnerabilities are not documented or patched.",[108,423,424,427],{},[111,425,426],{},"High Exploit Potential:"," Attackers can leverage them to breach systems undetected.",[108,429,430,433],{},[111,431,432],{},"Short Window for Response:"," Organizations have limited time to mitigate risks once the vulnerability becomes known.",[400,435],{},[20,437,439],{"id":438},"why-are-zero-day-vulnerabilities-dangerous","Why Are Zero-Day Vulnerabilities Dangerous?",[410,441,443,444],{"id":442},"_1-lack-of-preparedness","1. ",[111,445,446],{},"Lack of Preparedness",[16,448,449],{},"Since zero-day vulnerabilities are unknown to the vendor, there are no patches or security updates available to mitigate the risk. This makes it difficult for security teams to implement proactive defenses.",[410,451,453,454],{"id":452},"_2-sophisticated-attack-techniques","2. ",[111,455,456],{},"Sophisticated Attack Techniques",[16,458,459],{},"Exploits targeting zero-day vulnerabilities often use advanced tactics that evade traditional security measures like firewalls and antivirus programs.",[410,461,463,464],{"id":462},"_3-significant-impact-on-operations","3. ",[111,465,466],{},"Significant Impact on Operations",[16,468,469],{},"A successful zero-day attack can compromise sensitive data, disrupt critical business operations, or even cause widespread financial and reputational damage.",[400,471],{},[20,473,475],{"id":474},"how-attackers-exploit-zero-day-vulnerabilities","How Attackers Exploit Zero-Day Vulnerabilities",[410,477,443,479],{"id":478},"_1-targeted-attacks",[111,480,481],{},"Targeted Attacks",[16,483,484],{},"Attackers may use spear-phishing emails or malicious links to exploit the vulnerability.",[410,486,453,488],{"id":487},"_2-drive-by-downloads",[111,489,490],{},"Drive-by Downloads",[16,492,493],{},"Unsuspecting users might download malware by visiting compromised websites.",[410,495,463,497],{"id":496},"_3-exploit-kits",[111,498,499],{},"Exploit Kits",[16,501,502],{},"These are toolkits designed to identify and exploit vulnerabilities in real-time, automating the process for attackers.",[400,504],{},[20,506,508],{"id":507},"defending-against-zero-day-vulnerabilities","Defending Against Zero-Day Vulnerabilities",[16,510,511],{},"While no system is immune to zero-day threats, organizations can adopt several strategies to minimize their risk:",[410,513,443,515],{"id":514},"_1-implement-advanced-threat-detection",[111,516,517],{},"Implement Advanced Threat Detection",[16,519,520],{},"Using AI-powered security tools that analyze patterns and behaviors can help detect potential zero-day exploits.",[410,522,453,524],{"id":523},"_2-apply-defense-in-depth",[111,525,526],{},"Apply Defense-in-Depth",[16,528,529],{},"Layered security, including firewalls, intrusion detection systems (IDS), and endpoint protection, can provide multiple barriers to attackers.",[410,531,463,533],{"id":532},"_3-regular-security-audits-and-penetration-testing",[111,534,535],{},"Regular Security Audits and Penetration Testing",[16,537,538],{},"Frequent testing can help identify potential vulnerabilities before attackers do.",[410,540,542,543],{"id":541},"_4-employee-training","4. ",[111,544,545],{},"Employee Training",[16,547,548],{},"Educating staff about phishing and social engineering tactics can reduce the likelihood of human error leading to exploitation.",[400,550],{},[20,552,554],{"id":553},"notable-zero-day-exploits-in-history","Notable Zero-Day Exploits in History",[286,556,557,563,569],{},[108,558,559,562],{},[111,560,561],{},"Stuxnet (2010):"," A sophisticated worm targeting SCADA systems, exploiting multiple zero-day vulnerabilities.",[108,564,565,568],{},[111,566,567],{},"Heartbleed (2014):"," A vulnerability in the OpenSSL cryptographic library, exposing sensitive data.",[108,570,571,574],{},[111,572,573],{},"WannaCry (2017):"," A ransomware attack exploiting a zero-day vulnerability in Microsoft Windows SMB protocol.",[400,576],{},[20,578,580],{"id":579},"conclusion","Conclusion",[16,582,583],{},"Zero-day vulnerabilities pose a significant challenge to modern security systems. By understanding their nature and implementing robust defense mechanisms, organizations can reduce their exposure and safeguard critical assets. The battle against zero-day threats is ongoing, requiring vigilance, innovation, and a proactive approach to cybersecurity.",[400,585],{},[16,587,588],{},[111,589,590],{},"Stay Secure, Stay Vigilant!",{"title":67,"searchDepth":68,"depth":68,"links":592},[593,597,605,613,623,624],{"id":404,"depth":68,"text":405,"children":594},[595],{"id":412,"depth":596,"text":413},3,{"id":438,"depth":68,"text":439,"children":598},[599,601,603],{"id":442,"depth":596,"text":600},"1. Lack of Preparedness",{"id":452,"depth":596,"text":602},"2. Sophisticated Attack Techniques",{"id":462,"depth":596,"text":604},"3. Significant Impact on Operations",{"id":474,"depth":68,"text":475,"children":606},[607,609,611],{"id":478,"depth":596,"text":608},"1. Targeted Attacks",{"id":487,"depth":596,"text":610},"2. Drive-by Downloads",{"id":496,"depth":596,"text":612},"3. Exploit Kits",{"id":507,"depth":68,"text":508,"children":614},[615,617,619,621],{"id":514,"depth":596,"text":616},"1. Implement Advanced Threat Detection",{"id":523,"depth":596,"text":618},"2. Apply Defense-in-Depth",{"id":532,"depth":596,"text":620},"3. Regular Security Audits and Penetration Testing",{"id":541,"depth":596,"text":622},"4. Employee Training",{"id":553,"depth":68,"text":554},{"id":579,"depth":68,"text":580},"2025-01-15T00:00:00.000Z","Zero-day vulnerabilities pose a significant challenge to modern security systems. By understanding their nature and implementing robust defense mechanisms, organizations can reduce their exposure and safeguard critical assets.",{},"\u002Fblog\u002Funderstanding-zero-day-vulnerabilities",{"title":390,"description":626},"3.blog\u002F2025\u002Funderstanding-zero-day-vulnerabilities",[632],"Security","W5mfEd8f6l_eDO04EeR-RihuFo3PJLT-ELOfQkiDnec",{"id":635,"title":636,"authors":637,"body":640,"date":704,"description":705,"draft":76,"extension":77,"image":78,"meta":706,"navigation":80,"path":707,"seo":708,"stem":709,"tags":710,"__hash__":712},"news\u002F3.blog\u002F2026\u002Fauthentication-hardening-checklist.md","An Authentication Hardening Checklist for SaaS Teams",[638],{"name":8,"to":9,"avatar":639},{"src":11},{"type":13,"value":641,"toc":698},[642,645,649,660,664,676,680,688,692,695],[16,643,644],{},"Authentication flaws are consistently among the highest-impact findings in web application engagements — and most of them are preventable with well-known controls applied consistently.",[20,646,648],{"id":647},"credentials-and-sessions","Credentials and Sessions",[105,650,651,654,657],{},[108,652,653],{},"Enforce strong password policies validated against breach corpora, not arbitrary complexity rules.",[108,655,656],{},"Hash with a modern memory-hard algorithm (Argon2id or scrypt) — never fast hashes like SHA-256.",[108,658,659],{},"Regenerate session identifiers on login and privilege change; invalidate them server-side on logout.",[20,661,663],{"id":662},"rate-limiting-and-enumeration","Rate Limiting and Enumeration",[105,665,666,673],{},[108,667,668,669,672],{},"Rate-limit login, registration, and password reset per account ",[37,670,671],{},"and"," per source.",[108,674,675],{},"Return identical responses and timing whether or not an account exists.",[20,677,679],{"id":678},"multi-factor-authentication","Multi-Factor Authentication",[105,681,682,685],{},[108,683,684],{},"Offer phishing-resistant options (passkeys\u002FWebAuthn) ahead of TOTP; avoid SMS where possible.",[108,686,687],{},"Rate-limit and expire MFA challenges — a 6-digit code with unlimited attempts is decoration, not security.",[20,689,691],{"id":690},"recovery-flows","Recovery Flows",[16,693,694],{},"Password reset is an authentication bypass with better branding. Apply the same rigour: single-use time-boxed tokens, no account enumeration, and full session invalidation after reset.",[16,696,697],{},"Every item on this list is routinely probed within the first hours of an engagement. Better that your own testing finds the gaps first.",{"title":67,"searchDepth":68,"depth":68,"links":699},[700,701,702,703],{"id":647,"depth":68,"text":648},{"id":662,"depth":68,"text":663},{"id":678,"depth":68,"text":679},{"id":690,"depth":68,"text":691},"2026-05-14T00:00:00.000Z","Authentication is the front door to your application, and it's tested in every engagement we run. This checklist covers the controls that separate resilient login flows from fragile ones.",{},"\u002Fblog\u002Fauthentication-hardening-checklist",{"title":636,"description":705},"3.blog\u002F2026\u002Fauthentication-hardening-checklist",[711,86],"Authentication","1xHbmMZJL9r6g0CdX4mQXdvCelWx0bElty81GsOyi-A",{"id":714,"title":715,"authors":716,"body":719,"date":776,"description":777,"draft":76,"extension":77,"image":778,"meta":780,"navigation":80,"path":781,"seo":782,"stem":783,"tags":784,"__hash__":785},"news\u002F3.blog\u002F2026\u002Fhuman-in-the-loop-security.md","Why Expert Human Judgement Matters in AI Security Testing",[717],{"name":8,"to":9,"avatar":718},{"src":11},{"type":13,"value":720,"toc":771},[721,724,728,734,740,744,764,768],[16,722,723],{},"AI-powered penetration testing can provide broad, consistent coverage at a speed and price that makes a complete test practical for more businesses. For complex, regulated or high-risk environments, hands-on specialist testing adds another level of depth.",[20,725,727],{"id":726},"the-failure-modes-of-each-extreme","The Failure Modes of Each Extreme",[16,729,730,733],{},[111,731,732],{},"AI-powered automated testing"," can map attack surfaces, test consistently and capture technical evidence at machine speed. It is a complete penetration testing option for most organisations.",[16,735,736,739],{},[111,737,738],{},"Specialist human-led testing"," adds the creativity and niche expertise needed to investigate complex attack paths, unusual business logic and high-risk environments directly.",[20,741,743],{"id":742},"where-specialist-expertise-adds-value","Where Specialist Expertise Adds Value",[105,745,746,752,758],{},[108,747,748,751],{},[111,749,750],{},"AI drives breadth."," Every endpoint, parameter, and release gets continuous coverage.",[108,753,754,757],{},[111,755,756],{},"Specialists test directly."," Expert penetration testers investigate complex attack paths and business logic using hands-on techniques.",[108,759,760,763],{},[111,761,762],{},"Specialists apply judgement."," They assess exploitability and impact in the context of your systems, industry and risk profile.",[20,765,767],{"id":766},"the-result","The Result",[16,769,770],{},"Pensure Core provides complete AI-powered penetration testing. Core Plus is human-led, combining AI-powered coverage with hands-on specialist testing and expert human judgement.",{"title":67,"searchDepth":68,"depth":68,"links":772},[773,774,775],{"id":726,"depth":68,"text":727},{"id":742,"depth":68,"text":743},{"id":766,"depth":68,"text":767},"2026-07-09T00:00:00.000Z","AI-powered testing provides speed and breadth. For complex, regulated or high-risk environments, a specialist penetration tester adds hands-on testing and expert human judgement.",{"src":779},"\u002Funused-assets\u002Fasbtarct_upqy2o.avif",{},"\u002Fblog\u002Fhuman-in-the-loop-security",{"title":715,"description":777},"3.blog\u002F2026\u002Fhuman-in-the-loop-security",[153,261],"FjHppHYEEpkDNR9PfeIB6UQLzXFrgk3DbCZxdKEaXnU",{"id":787,"title":788,"authors":789,"body":792,"date":848,"description":849,"draft":76,"extension":77,"image":78,"meta":850,"navigation":80,"path":851,"seo":852,"stem":853,"tags":854,"__hash__":855},"news\u002F3.blog\u002F2026\u002Fscoping-your-first-pentest.md","Scoping Your First Penetration Test",[790],{"name":8,"to":9,"avatar":791},{"src":11},{"type":13,"value":793,"toc":842},[794,797,801,804,808,828,832,835,839],[16,795,796],{},"The quality of a penetration test is decided before it starts. Scope too narrowly and the critical finding sits just outside the boundary; scope too broadly and testers spread thin across surface that doesn't matter.",[20,798,800],{"id":799},"define-what-youre-protecting","Define What You're Protecting",[16,802,803],{},"Start from assets, not URLs. What data or capability would hurt most if compromised? Customer PII, payment flows, admin functionality, tenant isolation — name them explicitly, then work backwards to the systems that guard them.",[20,805,807],{"id":806},"choose-the-right-perspective","Choose the Right Perspective",[105,809,810,816,822],{},[108,811,812,815],{},[111,813,814],{},"Unauthenticated external"," answers \"what can an internet attacker reach?\"",[108,817,818,821],{},[111,819,820],{},"Authenticated testing"," answers \"what can a malicious or compromised user do?\" — usually where the highest-impact findings live.",[108,823,824,827],{},[111,825,826],{},"Multi-tenant testing"," answers \"can customer A reach customer B's data?\" — essential for SaaS.",[20,829,831],{"id":830},"be-honest-about-environments","Be Honest About Environments",[16,833,834],{},"Testing staging avoids production risk but only counts if staging genuinely mirrors production — same code, same configuration, same integrations. Document every known difference.",[20,836,838],{"id":837},"set-rules-of-engagement-early","Set Rules of Engagement Early",[16,840,841],{},"Agree on testing windows, rate limits, out-of-bounds systems, and an escalation contact before the engagement starts. Surprises during testing are avoidable with an hour of planning.",{"title":67,"searchDepth":68,"depth":68,"links":843},[844,845,846,847],{"id":799,"depth":68,"text":800},{"id":806,"depth":68,"text":807},{"id":830,"depth":68,"text":831},{"id":837,"depth":68,"text":838},"2026-01-21T00:00:00.000Z","A well-scoped penetration test delivers findings you can act on. A poorly scoped one wastes budget on the wrong targets. Here's how to get scoping right the first time.",{},"\u002Fblog\u002Fscoping-your-first-pentest",{"title":788,"description":849},"3.blog\u002F2026\u002Fscoping-your-first-pentest",[154,332],"jrNDpzcrJTw9Vygy-XUY59BP2pJo7Hfc29woCt275bY",{"id":857,"title":858,"authors":859,"body":862,"date":920,"description":921,"draft":76,"extension":77,"image":78,"meta":922,"navigation":80,"path":923,"seo":924,"stem":925,"tags":926,"__hash__":928},"news\u002F3.blog\u002F2026\u002Fsupply-chain-risk-dependencies.md","Your Dependencies Are Your Attack Surface",[860],{"name":8,"to":9,"avatar":861},{"src":11},{"type":13,"value":863,"toc":915},[864,867,871,878,882,908,912],[16,865,866],{},"A typical web application ships with hundreds of third-party packages, each one written, published, and maintained by someone outside your organisation. Attackers have noticed.",[20,868,870],{"id":869},"how-supply-chain-attacks-work","How Supply Chain Attacks Work",[16,872,873,874,877],{},"Rather than attacking your hardened perimeter, attackers compromise something you already trust: a popular package gets a malicious maintainer, a typosquatted name catches a hurried ",[28,875,876],{},"npm install",", or a build pipeline is poisoned upstream. The malicious code then runs with the full privileges of your application.",[20,879,881],{"id":880},"practical-defences","Practical Defences",[286,883,884,890,896,902],{},[108,885,886,889],{},[111,887,888],{},"Lock and verify."," Commit lockfiles, pin versions, and verify integrity hashes in CI.",[108,891,892,895],{},[111,893,894],{},"Reduce the surface."," Audit direct dependencies periodically — every package you drop removes a subtree of transitive risk.",[108,897,898,901],{},[111,899,900],{},"Watch behaviour, not just CVEs."," Vulnerability scanners catch known issues; unexpected network calls or install scripts from a minor version bump are the supply chain signal that matters.",[108,903,904,907],{},[111,905,906],{},"Isolate build systems."," CI runners with production credentials are a favourite target. Scope tokens tightly and expire them fast.",[20,909,911],{"id":910},"testing-the-whole-picture","Testing the Whole Picture",[16,913,914],{},"Application-level penetration testing should include how your application ingests and trusts third-party code — because your attacker won't respect the boundary between \"your code\" and \"your dependencies\".",{"title":67,"searchDepth":68,"depth":68,"links":916},[917,918,919],{"id":869,"depth":68,"text":870},{"id":880,"depth":68,"text":881},{"id":910,"depth":68,"text":911},"2026-03-05T00:00:00.000Z","Modern applications are mostly other people's code. Supply chain attacks exploit that reality — here's how to assess and reduce dependency risk without freezing development.",{},"\u002Fblog\u002Fsupply-chain-risk-dependencies",{"title":858,"description":921},"3.blog\u002F2026\u002Fsupply-chain-risk-dependencies",[927,632],"Supply Chain","EHISuK8kofdLmmVtaX0xxBL0D3gLubnhdLHgFUD980I",{"id":930,"title":931,"authors":932,"body":937,"date":1159,"description":1160,"draft":76,"extension":77,"image":78,"meta":1161,"navigation":80,"path":1162,"seo":1163,"stem":1164,"tags":1165,"__hash__":1168},"news\u002F3.blog\u002F2026\u002Ftesting-beyond-the-waf.md","Testing Past the WAF: How to Reach the App Safely",[933],{"name":934,"to":9,"avatar":935},"Josh Kam",{"src":936},"\u002Fimages\u002Fteam\u002Fjosh-kam.jpg",{"type":13,"value":938,"toc":1151},[939,942,945,948,951,955,962,968,971,979,982,986,989,1006,1009,1018,1021,1024,1028,1031,1057,1060,1064,1067,1070,1093,1096,1099,1103,1106,1132,1136,1139,1142,1145,1148],[16,940,941],{},"Your WAF blocks the first test payload. Good. That tells us the edge control saw the request and did its job.",[16,943,944],{},"It does not tell us whether the application behind it is secure.",[16,946,947],{},"If every assessment request stops at the edge, the engagement can quietly turn into an expensive test of Akamai, Cloudflare, AWS WAF or Vercel. Your application, APIs, authentication and business logic remain largely unanswered questions.",[16,949,950],{},"The better approach is dual-path testing: test the service through its normal protections, then use a narrow, temporary and monitored exception to assess the application behind them.",[20,952,954],{"id":953},"two-paths-answer-two-different-questions","Two paths answer two different questions",[16,956,957,958,961],{},"The ",[111,959,960],{},"protected path"," keeps your normal WAF, CDN, bot-management and rate controls in place. It shows what those controls recognise and stop today.",[16,963,957,964,967],{},[111,965,966],{},"controlled path"," lets authorised Pensure traffic pass only the edge controls that prevent the assessment. Application authentication, authorisation, logging, monitoring, network boundaries and every out-of-scope control stay on.",[16,969,970],{},"Together, those paths answer:",[286,972,973,976],{},[108,974,975],{},"Can an attacker reach the weakness through the service as it is exposed now?",[108,977,978],{},"Does the weakness still exist behind the edge if a rule is bypassed, misconfigured, applied inconsistently or changed later?",[16,980,981],{},"That distinction matters. A blocked injection payload may show that a managed rule worked. It does not prove the vulnerable code is absent. At the same time, broken access control, tenant-isolation failures and business-logic abuse often look like perfectly ordinary requests and can sail straight through a WAF.",[20,983,985],{"id":984},"build-the-narrowest-exception-your-platform-supports","Build the narrowest exception your platform supports",[16,987,988],{},"The preferred rule matches all available conditions:",[105,990,991,994,997,1000,1003],{},[108,992,993],{},"a fixed Pensure source IP or IP set;",[108,995,996],{},"the exact approved hostname and, where practical, path or API;",[108,998,999],{},"a unique, high-entropy engagement header where the platform supports it;",[108,1001,1002],{},"the approved environment; and",[108,1004,1005],{},"a short activation window tied to the assessment.",[16,1007,1008],{},"The logic should look like this:",[1010,1011,1016],"pre",{"className":1012,"code":1014,"language":1015,"meta":67},[1013],"language-text","IF source IP is in Pensure_Test_IPs\nAND request host is in Approved_Test_Hosts\nAND engagement header exactly matches the agreed value\nTHEN skip only the controls blocking authorised testing\nELSE apply the normal security policy\n","text",[28,1017,1014],{"__ignoreMap":67},[16,1019,1020],{},"Use AND, not OR. A rule that accepts either the IP address or the header is much broader than it first appears.",[16,1022,1023],{},"The engagement header must be unique to the test and exchanged through the agreed secure channel. Do not reuse a production credential, API key or session token. Keep the value out of ordinary email, tickets, screenshots, source code and long-lived documentation. Redact it from logs where your platform supports that, then revoke it when testing finishes.",[20,1025,1027],{"id":1026},"keep-the-controls-that-still-matter-switched-on","Keep the controls that still matter switched on",[16,1029,1030],{},"A controlled WAF exception should not flatten the rest of your security architecture. Keep these controls active unless the rules of engagement explicitly say otherwise:",[105,1032,1033,1036,1039,1042,1045,1048,1051,1054],{},[108,1034,1035],{},"TLS and certificate validation;",[108,1037,1038],{},"application login, MFA and session controls;",[108,1040,1041],{},"role, tenant and object-level authorisation;",[108,1043,1044],{},"application, infrastructure, WAF and security-event logging;",[108,1046,1047],{},"SIEM, SOC and endpoint monitoring;",[108,1049,1050],{},"network segmentation and origin restrictions;",[108,1052,1053],{},"protections for every out-of-scope host, path and environment; and",[108,1055,1056],{},"the normal incident, change and emergency-stop process.",[16,1058,1059],{},"Only skip the managed WAF rule, bot challenge, CAPTCHA, reputation control or rate policy that prevents the agreed test profile. Avoid exposing the origin directly to the internet. That creates a new risk instead of a controlled test route.",[20,1061,1063],{"id":1062},"prove-the-rule-before-active-testing","Prove the rule before active testing",[16,1065,1066],{},"Start with the platform’s preview, staging, count or log mode where one exists. Capture a protected-path baseline, then test the rule from both sides.",[16,1068,1069],{},"Confirm that:",[105,1071,1072,1075,1078,1081,1084,1087,1090],{},[108,1073,1074],{},"a normal request still follows the existing security policy;",[108,1076,1077],{},"the right IP without the engagement header does not bypass;",[108,1079,1080],{},"the header from an unapproved source does not bypass;",[108,1082,1083],{},"a valid request to the wrong host or path does not bypass;",[108,1085,1086],{},"a fully authorised request skips only the intended edge controls;",[108,1088,1089],{},"application authentication and authorisation still apply; and",[108,1091,1092],{},"matches are visible without logging the header value.",[16,1094,1095],{},"Do this before the assessment window. Debugging an over-broad rule while a penetration test is running is nobody’s idea of a relaxed afternoon.",[1097,1098],"waf-runbook-carousel",{},[20,1100,1102],{"id":1101},"mistakes-worth-catching-in-the-change-review","Mistakes worth catching in the change review",[16,1104,1105],{},"Most unsafe exceptions come from ordinary configuration mistakes rather than exotic attacks. Check for these before approval:",[105,1107,1108,1111,1114,1117,1120,1123,1126,1129],{},[108,1109,1110],{},"OR logic between source IP and the engagement header;",[108,1112,1113],{},"wildcards covering every hostname or path;",[108,1115,1116],{},"a broad Allow action that stops all later rules from running;",[108,1118,1119],{},"a bypass placed after an earlier terminating Block or Challenge rule;",[108,1121,1122],{},"assumptions that a WAF exception also covers bot management, rate limits or platform DDoS controls;",[108,1124,1125],{},"a proxy changing the client IP that the WAF actually sees;",[108,1127,1128],{},"the active header value appearing in logs or support records; and",[108,1130,1131],{},"no named owner or scheduled action to remove the rule.",[20,1133,1135],{"id":1134},"close-the-path-and-prove-it-is-closed","Close the path and prove it is closed",[16,1137,1138],{},"When testing finishes, disable or delete the exception, revoke the engagement header and remove temporary IP objects where appropriate. Repeat a representative request and confirm that it follows the normal protected path again.",[16,1140,1141],{},"Keep the change record, validation evidence and relevant request identifiers. Do not keep the active secret.",[16,1143,1144],{},"If your platform cannot express a sufficiently narrow exception, stop before switching controls off globally. A production-equivalent staging service, dedicated test hostname, customer-managed VPN, mTLS gateway or temporary reverse proxy may provide a safer route.",[16,1146,1147],{},"The goal is simple: test the perimeter and the application, without confusing one for the other.",[1149,1150],"article-test-cta",{},{"title":67,"searchDepth":68,"depth":68,"links":1152},[1153,1154,1155,1156,1157,1158],{"id":953,"depth":68,"text":954},{"id":984,"depth":68,"text":985},{"id":1026,"depth":68,"text":1027},{"id":1062,"depth":68,"text":1063},{"id":1101,"depth":68,"text":1102},{"id":1134,"depth":68,"text":1135},"2026-08-27T00:00:00.000Z","A practical technical guide to giving an authorised penetration test a narrow, temporary path through Vercel, Cloudflare, Akamai or AWS WAF without dropping the rest of your security controls.",{},"\u002Fblog\u002Ftesting-beyond-the-waf",{"title":931,"description":1160},"3.blog\u002F2026\u002Ftesting-beyond-the-waf",[1166,1167],"WAF","Technical Guide","mo2HEXo8WB2qWaYn6rIUsZPAnNsutPUX1A5cT14SrIw",{"id":1170,"title":1171,"authors":1172,"body":1175,"date":1243,"description":1244,"draft":76,"extension":77,"image":78,"meta":1245,"navigation":80,"path":1246,"seo":1247,"stem":1248,"tags":1249,"__hash__":1252},"news\u002F3.blog\u002F2026\u002Fthe-finding-is-medium-the-context-says-otherwise.md","It’s “Only a Medium” Until You Join the Dots.",[1173],{"name":934,"to":9,"avatar":1174},{"src":936},{"type":13,"value":1176,"toc":1238},[1177,1180,1183,1187,1190,1193,1196,1200,1203,1220,1223,1227,1230,1233,1235],[16,1178,1179],{},"The finding says “medium”. Everyone exhales. There are already higher-priority issues in the backlog, so this one can wait.",[16,1181,1182],{},"That may be the right decision. It may also miss what the finding makes possible.",[20,1184,1186],{"id":1185},"severity-is-a-starting-point","Severity is a starting point",[16,1188,1189],{},"Severity scores help teams compare technical characteristics consistently. They are useful. They also have no idea which system holds your customer data, which workflow controls money or how one weakness changes the value of another.",[16,1191,1192],{},"A modest information exposure may reveal an identifier. A separate permissions weakness may let a user act on that identifier. An old supplier account may provide the access needed to join the two.",[16,1194,1195],{},"Each issue can look manageable on its own. Join them together and the path may lead somewhere the business would consider critical.",[20,1197,1199],{"id":1198},"attackers-do-not-stop-at-the-first-finding","Attackers do not stop at the first finding",[16,1201,1202],{},"An attacker asks a sequence of questions:",[286,1204,1205,1208,1211,1214,1217],{},[108,1206,1207],{},"What can I reach?",[108,1209,1210],{},"What does this reveal?",[108,1212,1213],{},"Can I use it to gain more access?",[108,1215,1216],{},"What other system or privilege becomes available?",[108,1218,1219],{},"What business outcome can I cause?",[16,1221,1222],{},"A useful penetration test follows those questions. It tests whether findings can be combined and records the evidence behind the path.",[20,1224,1226],{"id":1225},"context-changes-the-remediation-decision","Context changes the remediation decision",[16,1228,1229],{},"When teams understand the path, prioritisation becomes easier. They can see which control breaks the chain earliest, which fix reduces the most exposure and which issue only looks minor because it was assessed in isolation.",[16,1231,1232],{},"This does not mean stamping “critical” on everything. That quickly becomes the security version of shouting fire whenever someone makes toast. Explain the conditions, confidence and business impact clearly enough for the team to make a sound decision.",[1149,1234],{},[16,1236,1237],{},"Good reporting shows where the weakness leads and what to fix first. The score can come along for the ride.",{"title":67,"searchDepth":68,"depth":68,"links":1239},[1240,1241,1242],{"id":1185,"depth":68,"text":1186},{"id":1198,"depth":68,"text":1199},{"id":1225,"depth":68,"text":1226},"2026-08-20T00:00:00.000Z","Severity scores help teams prioritise, but isolated ratings can miss the attack path created when several weaknesses work together.",{},"\u002Fblog\u002Fthe-finding-is-medium-the-context-says-otherwise",{"title":1171,"description":1244},"3.blog\u002F2026\u002Fthe-finding-is-medium-the-context-says-otherwise",[1250,1251],"Attack Paths","Technical","cgwK4Tm17qAP6XCqhNG5YGuTfbw6nq4vdL4blXhtsEg",{"id":1254,"title":1255,"authors":1256,"body":1259,"date":1355,"description":1356,"draft":76,"extension":77,"image":78,"meta":1357,"navigation":80,"path":1358,"seo":1359,"stem":1360,"tags":1361,"__hash__":1362},"news\u002F3.blog\u002F2026\u002Fvulnerability-scan-vs-penetration-test.md","Scan or Pentest? Buy the Evidence You Actually Need.",[1257],{"name":934,"to":9,"avatar":1258},{"src":936},{"type":13,"value":1260,"toc":1349},[1261,1264,1267,1271,1274,1277,1280,1284,1287,1290,1307,1311,1314,1317,1320,1337,1339,1343,1346],[16,1262,1263],{},"From the outside, the two services can look remarkably similar. You provide a target, some security checks run and a report comes back. Easy to see why buyers mix them up.",[16,1265,1266],{},"The confusion tends to surface at exactly the wrong moment, usually when a customer or procurement team has asked for a penetration test and the buyer needs a quick answer.",[20,1268,1270],{"id":1269},"a-scanner-looks-for-recognised-signals","A scanner looks for recognised signals",[16,1272,1273],{},"A vulnerability scanner checks systems for known patterns: exposed software, common misconfiguration, missing controls and signatures associated with published vulnerabilities.",[16,1275,1276],{},"That is useful work. Scanning is fast, repeatable and well suited to regular hygiene. Think of it as checking the smoke alarms: you should do it often, and you will be glad when it catches something obvious.",[16,1278,1279],{},"Its limitation is context. A scanner may detect a condition without knowing whether it is exploitable in your environment, whether another control blocks it or whether several modest issues can be combined.",[20,1281,1283],{"id":1282},"a-penetration-test-asks-what-can-actually-happen","A penetration test asks what can actually happen",[16,1285,1286],{},"A penetration test exercises the agreed target under controlled conditions. It investigates what an attacker could actually do with the conditions they find.",[16,1288,1289],{},"That requires a defined scope, authority to test, safeguards, evidence and analysis. The result should explain the reachable path, the business impact and practical remediation.",[16,1291,1292,1293,1300,1301,1306],{},"This distinction is reflected in established testing guidance. The ",[1294,1295,1299],"a",{"href":1296,"rel":1297},"https:\u002F\u002Fwstg.owasp.org\u002F",[1298],"nofollow","OWASP Web Security Testing Guide"," provides a structured framework for web application testing, while ",[1294,1302,1305],{"href":1303,"rel":1304},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F115\u002Ffinal",[1298],"NIST SP 800-115"," distinguishes testing techniques and stresses planning, analysis and mitigation.",[20,1308,1310],{"id":1309},"why-buyers-confuse-them","Why buyers confuse them",[16,1312,1313],{},"Both services may use automation. Both may identify vulnerabilities. Both may produce an impressively long PDF.",[16,1315,1316],{},"The useful distinction is how far the service goes beyond detection into controlled testing, validation and context.",[16,1318,1319],{},"Useful questions include:",[105,1321,1322,1325,1328,1331,1334],{},[108,1323,1324],{},"Is exploitability tested or inferred?",[108,1326,1327],{},"Are findings validated and deduplicated?",[108,1329,1330],{},"Does the scope include authenticated or business-critical workflows?",[108,1332,1333],{},"Does the report explain business impact?",[108,1335,1336],{},"Can the provider answer questions and support retesting?",[1149,1338],{},[20,1340,1342],{"id":1341},"you-may-need-both","You may need both",[16,1344,1345],{},"Scanning can provide frequent baseline coverage. Penetration testing can provide deeper evidence at important moments such as a customer review, major launch, tender, insurer request or material system change.",[16,1347,1348],{},"Problems start when one is expected to do the other’s job. Choose the service that gives you enough evidence for the decision in front of you.",{"title":67,"searchDepth":68,"depth":68,"links":1350},[1351,1352,1353,1354],{"id":1269,"depth":68,"text":1270},{"id":1282,"depth":68,"text":1283},{"id":1309,"depth":68,"text":1310},{"id":1341,"depth":68,"text":1342},"2026-08-23T00:00:00.000Z","Scanning and penetration testing both have a role. The difference matters when someone needs evidence of what an attacker could actually do.",{},"\u002Fblog\u002Fvulnerability-scan-vs-penetration-test",{"title":1255,"description":1356},"3.blog\u002F2026\u002Fvulnerability-scan-vs-penetration-test",[154,332],"wFA9V29WsVmp_Nm-uqnNyVMm2kf0IHOuFLjPVqFHHAU",{"id":1364,"title":1365,"authors":1366,"body":1369,"date":1512,"description":1513,"draft":76,"extension":77,"image":78,"meta":1514,"navigation":80,"path":1515,"seo":1516,"stem":1517,"tags":1518,"__hash__":1520},"news\u002F3.blog\u002F2026\u002Fwhat-does-a-99-dollar-pentest-buy.md","What Does a $99 Pentest Actually Buy? Turns Out, Some Things Are Too Cheap.",[1367],{"name":934,"to":9,"avatar":1368},{"src":936},{"type":13,"value":1370,"toc":1505},[1371,1374,1377,1380,1384,1387,1390,1393,1396,1399,1403,1406,1409,1435,1438,1440,1444,1447,1450,1453,1456,1460,1463,1466,1486,1489,1493,1496,1499,1502],[16,1372,1373],{},"A $99 penetration test sounds wonderfully simple. Someone has asked for a pentest, the deadline is close and, for less than the cost of a team lunch, the problem appears to go away.",[16,1375,1376],{},"I understand the appeal. Security requests often arrive with very little explanation and a great deal of implied urgency. Nobody wants to spend weeks comparing providers when a customer, insurer or tender is waiting.",[16,1378,1379],{},"Automation can genuinely help. It can explore faster, repeat checks consistently and give skilled testers more time to investigate the things that matter. We use it ourselves. The awkward bit is working out how a $99 service pays for enough of that work to produce a result you can trust.",[20,1381,1383],{"id":1382},"start-with-the-uncomfortable-maths","Start with the uncomfortable maths",[16,1385,1386],{},"The $99 has to pay for the whole service. That includes infrastructure, discovery, model inference, repeated exploration, orchestration, evidence capture, validation, deduplication, reporting, support and the provider's operating costs.",[16,1388,1389],{},"Whatever remains for AI inference will be less than $99, potentially much less. That is before a person has looked at the result or answered a question.",[16,1391,1392],{},"A thorough assessment cannot simply read a homepage once and produce a credible report. Modern applications contain routes, APIs, authentication flows, roles, parameters, error states and business processes. Useful testing needs to explore those surfaces, form hypotheses, test them safely, revisit promising paths and compare observations across the application.",[16,1394,1395],{},"That consumes time and compute. It also requires repeated reasoning. A model may need to inspect the same behaviour from several angles before it can distinguish a real weakness from an odd but harmless response.",[16,1397,1398],{},"At $99 all-in, something has to give. Perhaps the scope is tiny. Perhaps the service is subsidised. Perhaps the provider has found a genuinely clever operating model. Any of those could be reasonable, but you deserve a straight answer.",[20,1400,1402],{"id":1401},"automation-is-useful-when-it-has-room-to-work","Automation is useful when it has room to work",[16,1404,1405],{},"The cheapest possible model call is a strange thing to optimise in a penetration test. You want enough exploration to find less obvious paths, enough context to understand them and enough validation to avoid sending your engineers on a very expensive wild-goose chase.",[16,1407,1408],{},"Ask the provider:",[105,1410,1411,1414,1417,1420,1423,1426,1429,1432],{},[108,1412,1413],{},"How much of the application is actually explored?",[108,1415,1416],{},"Does testing follow links, APIs, authentication states and multi-step workflows?",[108,1418,1419],{},"Can the system revisit and deepen an investigation, or does each surface receive one pass?",[108,1421,1422],{},"Are potential findings validated before they reach the report?",[108,1424,1425],{},"Are related observations deduplicated into one clear underlying issue?",[108,1427,1428],{},"Does the evidence show what happened and why it matters?",[108,1430,1431],{},"Is the remediation specific enough for an engineer to act on?",[108,1433,1434],{},"What happens when you question a finding or need help interpreting it?",[16,1436,1437],{},"Good automation expands coverage and consistency. A severely constrained budget can still force shallow exploration, small context windows, limited validation and templated reporting, however capable the underlying technology may be.",[1149,1439],{},[20,1441,1443],{"id":1442},"a-long-report-can-still-leave-you-alone","A long report can still leave you alone",[16,1445,1446],{},"There is a particular kind of disappointment in opening a security report and finding 40 pages of alerts with no clear sense of what to do next. It is the security equivalent of receiving flat-pack furniture without the instructions.",[16,1448,1449],{},"False positives create unnecessary anxiety and send engineers towards problems that are not real. Poor deduplication can turn one underlying issue into a dozen findings. Generic remediation leaves your team to work out whether the advice applies to your architecture at all.",[16,1451,1452],{},"Even a technically correct observation may provide little assurance. “A security header is missing” does not tell you whether an attacker can use that gap, what the business impact could be or which fix should come first.",[16,1454,1455],{},"The report should reduce uncertainty. It should help your team move from “Are we exposed?” to “Here is what matters, here is the evidence, and here is what we will fix.”",[20,1457,1459],{"id":1458},"ask-where-your-vulnerability-data-goes","Ask where your vulnerability data goes",[16,1461,1462],{},"Testing can expose sensitive information about your URLs, technology, configuration, authentication behaviour and weaknesses that have not yet been fixed.",[16,1464,1465],{},"Before submitting a target, ask:",[105,1467,1468,1471,1474,1477,1480,1483],{},[108,1469,1470],{},"Where is the data processed and stored?",[108,1472,1473],{},"Which service providers and AI models can receive it?",[108,1475,1476],{},"In which countries does processing occur?",[108,1478,1479],{},"How long are prompts, responses, evidence and reports retained?",[108,1481,1482],{},"Can any of that information be used for model training or product improvement?",[108,1484,1485],{},"Who can access it, and how is it deleted?",[16,1487,1488],{},"Price and polished marketing will not answer those questions. A credible provider should explain its data handling plainly.",[20,1490,1492],{"id":1491},"buy-the-level-of-assurance-you-actually-need","Buy the level of assurance you actually need",[16,1494,1495],{},"A $99 automated scan may be perfectly useful for a quick hygiene check when its limits are clear. That can be a perfectly sensible product.",[16,1497,1498],{},"The standard changes when a customer, insurer, auditor, tender panel or leadership team will rely on the result. In that situation, you need enough coverage, validation and evidence to support a real decision. You also need findings your team can act on and a provider prepared to stand behind the work.",[16,1500,1501],{},"Before you buy, ask the awkward question: after everyone and everything involved has been paid, how much testing can $99 realistically contain?",[16,1503,1504],{},"A good answer leaves you clearer and more confident. Box-ticking relief tends to wear off quickly.",{"title":67,"searchDepth":68,"depth":68,"links":1506},[1507,1508,1509,1510,1511],{"id":1382,"depth":68,"text":1383},{"id":1401,"depth":68,"text":1402},{"id":1442,"depth":68,"text":1443},{"id":1458,"depth":68,"text":1459},{"id":1491,"depth":68,"text":1492},"2026-08-25T00:00:00.000Z","A $99 penetration test sounds like an easy answer to an uncomfortable request. Before buying, ask whether the economics leave enough room for thorough testing, useful evidence and findings your team can trust.",{},"\u002Fblog\u002Fwhat-does-a-99-dollar-pentest-buy",{"title":1365,"description":1513},"3.blog\u002F2026\u002Fwhat-does-a-99-dollar-pentest-buy",[154,1519],"Buyer Guide","43iq9GNgNI1lZOPxXID2I8u5tfcvXKIZFq1mzbsI5XY",{"id":1522,"title":1523,"authors":1524,"body":1527,"date":1649,"description":1650,"draft":76,"extension":77,"image":78,"meta":1651,"navigation":80,"path":1652,"seo":1653,"stem":1654,"tags":1655,"__hash__":1656},"news\u002F3.blog\u002F2026\u002Fyou-need-a-pentest-now-what.md","“Go Get a Pen Test.” Now What?",[1525],{"name":934,"to":9,"avatar":1526},{"src":936},{"type":13,"value":1528,"toc":1643},[1529,1532,1535,1538,1542,1545,1548,1565,1568,1572,1575,1578,1595,1598,1600,1604,1607,1610,1613,1617,1620,1623,1640],[16,1530,1531],{},"The request often arrives as one sentence: “We need a penetration test.”",[16,1533,1534],{},"It might come from a customer, insurer, tender or auditor. The deadline is usually closer than anyone would like, the scope is vague and suddenly you are wondering whether testing will disrupt production, uncover something awkward or delay the deal that started all this.",[16,1536,1537],{},"That reaction is normal. A good penetration test should reduce the uncertainty.",[20,1539,1541],{"id":1540},"start-with-why-you-were-asked","Start with why you were asked",[16,1543,1544],{},"The document may say “penetration test”. Usually, the person asking wants confidence. They need evidence that an independent party has looked for exploitable weaknesses and that your team has a practical plan for anything found.",[16,1546,1547],{},"Clarify the trigger first:",[105,1549,1550,1553,1556,1559,1562],{},[108,1551,1552],{},"Is a customer reviewing your security?",[108,1554,1555],{},"Is a tender or procurement process blocked?",[108,1557,1558],{},"Has an insurer requested independent testing?",[108,1560,1561],{},"Are you preparing for an audit, launch or material system change?",[108,1563,1564],{},"Does your own team want assurance before taking on more risk?",[16,1566,1567],{},"The trigger shapes the timing, reporting and evidence you will need.",[20,1569,1571],{"id":1570},"scope-turns-urgency-into-a-plan","Scope turns urgency into a plan",[16,1573,1574],{},"You do not need to learn every testing technique before you begin. Start with the system that matters, who relies on it and what would hurt if it were compromised.",[16,1576,1577],{},"Useful scoping questions include:",[105,1579,1580,1583,1586,1589,1592],{},[108,1581,1582],{},"Which website, application or API is under review?",[108,1584,1585],{},"Is the target production or non-production?",[108,1587,1588],{},"Should testing cover only the public surface, or authenticated customer and administrative workflows as well?",[108,1590,1591],{},"Are third-party services, payment actions or fragile workflows out of bounds?",[108,1593,1594],{},"When can testing run safely, and who should be contacted if something unexpected happens?",[16,1596,1597],{},"Clear answers create a testable brief and spare your team from surprises later.",[1149,1599],{},[20,1601,1603],{"id":1602},"finding-a-problem-is-not-a-judgement-on-your-team","Finding a problem is not a judgement on your team",[16,1605,1606],{},"Teams sometimes worry that a finding will make their engineering work look careless. I understand the feeling. Nobody enjoys paying someone to point at a problem in work they care about.",[16,1608,1609],{},"Modern systems change constantly. New features, integrations, permissions and configuration can create paths nobody intended. Testing finds those paths under controlled conditions, while they can still be fixed.",[16,1611,1612],{},"A useful report explains what an attacker could reach, why it matters to the business, the evidence behind the finding and what to do next. Your team should come away ready to act, rather than staring at a list of unexplained scores.",[20,1614,1616],{"id":1615},"know-what-happens-after-testing","Know what happens after testing",[16,1618,1619],{},"Before work starts, understand how findings will be communicated, whether material issues are escalated during testing, what the final report includes and how remediation can be verified.",[16,1621,1622],{},"The useful outcome is clarity:",[105,1624,1625,1628,1631,1634,1637],{},[108,1626,1627],{},"what was tested;",[108,1629,1630],{},"what could be exploited;",[108,1632,1633],{},"what matters most;",[108,1635,1636],{},"what should be fixed first; and",[108,1638,1639],{},"what evidence you can give the person who asked.",[16,1641,1642],{},"With those questions answered, the urgent request starts to look much more like a manageable piece of work.",{"title":67,"searchDepth":68,"depth":68,"links":1644},[1645,1646,1647,1648],{"id":1540,"depth":68,"text":1541},{"id":1570,"depth":68,"text":1571},{"id":1602,"depth":68,"text":1603},{"id":1615,"depth":68,"text":1616},"2026-08-26T00:00:00.000Z","An urgent penetration-test request can feel exposing and unclear. Here is how to turn it into a controlled plan without adding unnecessary stress.",{},"\u002Fblog\u002Fyou-need-a-pentest-now-what",{"title":1523,"description":1650},"3.blog\u002F2026\u002Fyou-need-a-pentest-now-what",[154,1519],"1C6HI5O6zU-HPg8zNOdbqoW-1cZu9LAQ6rtlhlA7FB0",1788789307394]