Insights

Notes from the engagement floor

Practical writing on penetration testing, application security and human risk — aimed at the people who have to scope the work, defend the budget and act on the findings.

Buying security testing

What does a penetration test cost? A breakdown of what drives the price

There is no flat rate, and any firm quoting one before understanding your scope is guessing. Here are the five variables that actually move the number — and the questions to ask so you can compare quotes on equal terms.

18 Aug 2026  ·  9 min read
Read article →
Buying security testing

Vulnerability scan vs penetration test: what you’re actually buying

These two get sold interchangeably and they are not the same product. One tells you what is known to be broken. The other tells you what an attacker can actually do with it. Knowing the difference stops you overpaying — and stops you buying the wrong thing entirely.

04 Aug 2026  ·  8 min read
Read article →
Application security

BOLA: why broken object level authorization keeps breaking APIs

The number one entry on the OWASP API Security Top 10 is also the one automated tooling is worst at finding. A walk through how BOLA works, why scanners structurally cannot detect it, and what manual testing for it looks like in practice.

21 Jul 2026  ·  11 min read
Read article →

Not sure what testing you need?

Tell us what you are running and what is driving the requirement. We will tell you what is worth testing — and what is not.