Skip to main content
ITSIGNSolutions
Insights

Security writing that is useful

Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.

Penetration Testing2 min read

When a pentest is really for the insurance form

Be honest about the audience. Then still do the work so the form is not the only thing you get.

ITSIGN Administrator · February 26, 2025

Penetration Testing2 min read

Why the retest is the part you should not skip

A finding list without a retest is homework you never marked. Insurers and customers notice.

ITSIGN Administrator · February 19, 2025

Penetration Testing2 min read

Scoping a pentest without wasting money

Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.

ITSIGN Administrator · February 12, 2025

Penetration Testing2 min read

Pentest vs vulnerability scan: stop mixing them up

Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.

ITSIGN Administrator · February 5, 2025

Penetration Testing2 min read

How to read a pentest report without getting lost

Skip the CVSS column. Start with the path that reaches a business system, then the owner and the due date.

ITSIGN Administrator · January 29, 2025

Penetration Testing2 min read

Web application pentesting for Canadian SMBs

Customer portals and admin consoles are where the money sits. Testing them is not the same as scanning the office firewall.

ITSIGN Administrator · January 22, 2025

Penetration Testing2 min read

Internal vs external penetration testing

External tests the internet edge. Internal assumes someone is already inside. You usually need both, in that order.

ITSIGN Administrator · January 15, 2025

Penetration Testing2 min read

What a penetration test actually buys you

A scan lists software versions. A pentest tells you whether someone can reach payroll. Here is how to buy the second one.

ITSIGN Administrator · January 8, 2025