Security writing that is useful
Short pieces from the engineers who do the work. No vendor recaps, no recycled threat-intel newsletters.
When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
ITSIGN Administrator · February 26, 2025
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
ITSIGN Administrator · February 19, 2025
Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
ITSIGN Administrator · February 12, 2025
Pentest vs vulnerability scan: stop mixing them up
Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.
ITSIGN Administrator · February 5, 2025
How to read a pentest report without getting lost
Skip the CVSS column. Start with the path that reaches a business system, then the owner and the due date.
ITSIGN Administrator · January 29, 2025
Web application pentesting for Canadian SMBs
Customer portals and admin consoles are where the money sits. Testing them is not the same as scanning the office firewall.
ITSIGN Administrator · January 22, 2025
Internal vs external penetration testing
External tests the internet edge. Internal assumes someone is already inside. You usually need both, in that order.
ITSIGN Administrator · January 15, 2025
What a penetration test actually buys you
A scan lists software versions. A pentest tells you whether someone can reach payroll. Here is how to buy the second one.
ITSIGN Administrator · January 8, 2025
