Attack Vector resources
Practical guidance and research on penetration testing, compliance, AI security and best practice from our team of consultants.
Unpacking the OWASP Top 10 2025: What's New and Why It Matters
For over two decades the OWASP Top 10 has been a common reference for developers and security teams. The 2025 edition signals a fundamental shift — away from isolated coding errors and towards systemic, architectural risk.
10 Steps to Cyber Resilience
A proactive, well-informed approach to defence is essential. We break down the NCSC's 10 Steps to Cyber Security and how to apply them.
Dark Web Monitoring: A Deep Dive into Leaked Credential Monitoring
The dark web is a breeding ground for the illicit trade in stolen data. A closer look at leaked-credential monitoring and why it matters.
OWASP Top 10
An introduction to OWASP and its foundational Top 10 list of the most critical web application security risks.
How to Streamline Project Scoping and Enhance Pentest Efficiency
Our innovative approach to scoping lets you get instant quotes right in the scoping form — no sign-up and no aggressive sales tactics.
Penetration Testing vs Vulnerability Scanning
Two fundamental methods for assessing risk — how vulnerability scanning and penetration testing differ, and when to use each.
DSPT Version 8 and DTAC Version 2: Why Penetration Testing Still Matters
NHS England has updated DSPT and DTAC with a sharper focus on verifiable evidence. Here is what changed and why penetration testing remains central.
Penetration Testing in the NHS DSPT
The NHS Data Security and Protection Toolkit (DSPT) mandates robust measures to protect patient data. Here is where penetration testing fits in.
DTAC, DSPT, and the Importance of Penetration Testing
The DSPT is evolving to align with the NCSC Cyber Assessment Framework. What is changing, and what it means for your organisation.
MITRE ATLAS
MITRE ATLAS is a knowledge base of adversarial tactics and techniques against AI systems — an essential resource for securing machine learning.
LLM AI Security & Governance Checklist
As generative AI reshapes business, a practical checklist for governing and securing LLM adoption across your organisation.
A Comprehensive Guide to LLM Security
Large Language Models bring new utility — and new risks. A comprehensive look at the security and ethical concerns they raise.
OWASP Top 10 for LLM 2025 (Large Language Model)
An overview of the OWASP Top 10 risks specific to LLM applications — from prompt injection to unbounded consumption.
Cheat Sheet Series – Web Service Security
A concise reference on web service (WS-Security) protocols and standards, distilled from the OWASP guidance.
Cheat Sheet Series – Credential Stuffing
A quick-reference guide to preventing credential-stuffing attacks, distilled from the OWASP cheat sheet.
Cheat Sheet Series – Authentication
Security best practices for authentication in one concise, user-friendly reference, distilled from OWASP guidance.
Cheat Sheet Series – Input Validation
A concise reference on user input validation and how to get it right, distilled from the OWASP cheat sheet.
Motion Picture Association (MPA) and Penetration Testing Requirements
The MPA publishes Content Security Best Practices for its member studios. How penetration testing supports MPA compliance.