Attack Vector resources
Practical guidance and research on penetration testing, compliance, AI security and best practice from our team of consultants.
OWASP Top 10 2025: What Changed and Why UK Teams Should Care
OWASP Top 10:2025 for UK teams: supply chain failures, rising misconfiguration risk, SSRF under access control, and how testing maps to the list.
Affordable Penetration Testing UK: What You Get From £1,500 (and What You Don’t)
What a UK penetration test from £1,500 typically covers, what it cannot cover, and how to scope honestly without buying a scanner dressed as a pentest.
Staging or Production? Where UK Organisations Should Run a Penetration Test
Staging is safer; production is truer. How UK organisations choose where to run a penetration test and how to handle environment parity risk.
Internal vs External Penetration Testing: Which Does Your Organisation Need?
External tests your internet-facing attack surface. Internal shows what happens after a foothold. How UK organisations decide which to commission first.
Cyber Insurance and Penetration Testing: Evidence Underwriters Often Ask For
What UK cyber insurance underwriters often ask for on penetration testing evidence: scope, findings and residual risk, with no promise of cover.
API vs Web Application Penetration Testing: When You Need Both
Web tests catch browser-facing flaws; API tests catch BOLA, authZ and inventory issues. How UK organisations decide on one, the other, or both.
What a Good Penetration Test Report Should Include (Buyer Checklist)
A buyer checklist for UK penetration test reports: executive summary, scope, evidence, severity, and remediation guidance you can act on yourself.
NCSC 10 Steps to Cyber Security: A Practical UK Guide
NCSC 10 Steps to Cyber Security explained for UK organisations: what each step covers, what it is not, and how independent testing supports resilience.
Dark Web Monitoring and Leaked Credential Monitoring Explained
Leaked credential monitoring explained: dark web alerts, credential stuffing risk, MFA, password hygiene, and when UK penetration testing still matters.
OWASP Top 10 Explained: What It Is and How to Use It in Testing
What the OWASP Top 10 is, the ten 2025 categories in plain English, and how developers and buyers should use it without treating it as a standard.
How to Scope a Penetration Test: What to Prepare for an Accurate Quote
What to prepare before you request a penetration test quote: asset counts, roles, environments and drivers, plus how our instant estimate and scoping call work.
Penetration Testing vs Vulnerability Scanning: What UK Buyers Actually Need
Scans find known issues fast. Penetration tests prove exploitability and business impact. How UK buyers use both and avoid the wrong product.
How Much Does a Penetration Test Cost in the UK? A Practical 2026 Pricing Guide
UK penetration test costs explained for 2026: day rates, scope drivers, typical budget bands, and how to spot a scan sold as a pentest. From £1,500.
NHS DSPT and DTAC Penetration Testing: What Health-Tech Vendors Need
How health-tech vendors use penetration testing evidence for NHS DTAC technical security and DSPT supplier assurance, without confusing the two frameworks.
DSPT Version 8 and DTAC Version 2: What Changed for Penetration Testing Evidence
What DSPT version 8 and the refreshed DTAC form change for NHS security evidence, and why independent penetration testing still identifies gaps.
Penetration Testing in the NHS DSPT: A Practical Guide for Trusts and Providers
How penetration testing supports NHS DSPT assurance: annual scoping, scan versus test, supplier versus trust angles, and briefing a UK testing partner.
The DSPT Is Evolving: Key Changes from Version 7 to Version 9 and Why They Matter
How the NHS DSPT moved to the NCSC CAF from version 7, what changed in versions 8 and 9, and what it means for trusts, suppliers and testing evidence.
MITRE ATLAS Explained: Mapping Attacks on AI Systems
MITRE ATLAS is the living knowledge base of adversary tactics and techniques against AI systems. How UK teams use it for threat modelling and testing.
LLM AI Security and Governance Checklist for UK Leaders
LLM security checklist for UK organisations: governance controls, trust boundaries, data handling, access and prompt injection risks to identify early.
LLM Security Guide: How AI Applications Get Attacked and How to Test Them
How LLM applications get attacked through prompts, retrieval, tools and output handling, which controls help, and how to scope a useful security test.
OWASP Top 10 for LLM Applications 2026: Risks UK Teams Must Test
OWASP Top 10 for LLM Applications 2026 for UK teams: prompt injection, excessive agency, unbounded consumption, and how to assess each risk.
Cheat Sheet Series: Web Service Security
Key web service security controls from the OWASP Cheat Sheet Series: authentication, transport, message validation and API hardening.
Cheat Sheet Series: Credential Stuffing
Credential stuffing explained: how account takeover attempts work and the controls that help, including MFA, breached-password checks and throttling.
Cheat Sheet Series: Authentication
OWASP authentication cheat sheet: MFA, secure password flows, session handling and anti-enumeration controls, as a quick reference for developers.
Cheat Sheet Series: Input Validation
OWASP input validation cheat sheet: allowlists, syntactic vs semantic checks, file uploads and encoding. A practical reference to reduce injection risk.
MPA Content Security Best Practices: Penetration Testing and Vulnerability Scanning
How MPA Content Security Best Practices and TPN expect annual penetration testing and regular vulnerability scanning for media and production vendors.