Notes from the engagement floor
Practical writing on penetration testing, application security and human risk — aimed at the people who have to scope the work, defend the budget and act on the findings.
What does a penetration test cost? A breakdown of what drives the price
There is no flat rate, and any firm quoting one before understanding your scope is guessing. Here are the five variables that actually move the number — and the questions to ask so you can compare quotes on equal terms.
Vulnerability scan vs penetration test: what you’re actually buying
These two get sold interchangeably and they are not the same product. One tells you what is known to be broken. The other tells you what an attacker can actually do with it. Knowing the difference stops you overpaying — and stops you buying the wrong thing entirely.
BOLA: why broken object level authorization keeps breaking APIs
The number one entry on the OWASP API Security Top 10 is also the one automated tooling is worst at finding. A walk through how BOLA works, why scanners structurally cannot detect it, and what manual testing for it looks like in practice.
Not sure what testing you need?
Tell us what you are running and what is driving the requirement. We will tell you what is worth testing — and what is not.
