HIPAA Security Rule Penetration Testing
Does HIPAA require penetration testing? Not yet, but the proposed HIPAA Security Rule update would mandate annual pen tests. Here’s what to know.
Read the post →How manual, goal-driven penetration testing differs from scanning, what a useful report contains, and how to scope an engagement that answers a real question.
41 posts
Does HIPAA require penetration testing? Not yet, but the proposed HIPAA Security Rule update would mandate annual pen tests. Here’s what to know.
Read the post →A pentest is a project, not a purchase. Learn how dedicated project management gets you more testing time, faster critical alerts, and findings that get fixed.
Read the post →What actually drives the scope and cost of an LLM penetration test: the questions to answer before you buy, a full scoping checklist, and a sample sow.
Read the post →A daily start and stop email from your penetration testing partner isn’t a formality — it’s a safety net, a scope check, and a real paper trail.
Read the post →CSP is a powerful XSS defense that is routinely misconfigured. How it works, a strict 2026 policy, and the bypasses you will actually run into.
Read the post →Test, receive a report, fix the criticals, file the PDF, repeat next year. Why that cycle stopped being good enough, and what retesting should look like.
Read the post →If 95% of your estate is a priority and 32% of it is tested, you do not have a program, you have a bet. Where the gap comes from and how it widens.
Read the post →The annual penetration test satisfied compliance and reassured boards for a decade. The numbers now say that model has been overtaken. What replaces it.
Read the post →Scoping, rules of engagement, and the real difference between a penetration test, a vulnerability scan, and a red team engagement. What you are buying.
Read the post →Attackers used to give you a month to patch and now give you five days, while regulators remove the choice about testing. What good looks like in 2026.
Read the post →Compliance verifies that controls exist. Security verifies they hold. Here is where the gap opens up, and why breached organizations were often fully certified.
Read the post →Attackers chain low-severity findings into serious compromise. Why severity scores rank issues badly on their own, and what to prioritize instead.
Read the post →The findings we reported most often on external network engagements in 2025, ranked, with what each one usually means about the environment behind it.
Read the post →External assets stay the most attacked entry point into any organization. What external testing looks like in 2026, and how we approach the engagement.
Read the post →A critical SharePoint flaw let attackers run code with no password at all. What the breach revealed about relying on vendor patches and nothing else.
Read the post →Testing is moving from annual audit to continuous validation, and AI is accelerating both attack and defense. What that shift means for security leaders.
Read the post →An annual test is a snapshot of an environment that changes daily. What continuous penetration testing involves, and how to judge whether you need it.
Read the post →A penetration test asks what is vulnerable. A red team asks whether a determined adversary gets caught. Which question you are ready to have answered.
Read the post →What a network penetration test involves, stage by stage: scoping, enumeration, exploitation, privilege escalation, and the lateral movement that follows.
Read the post →The TSA’s proposed rule puts pipeline, rail, and bus operators under real cybersecurity obligations. What it asks for, and where testing fits the requirements.
Read the post →Default credentials are the shortest path from the outside to full control, and they are still everywhere. Where we find them, and how to hunt yours down.
Read the post →What penetration testing is, the main types, the misconceptions worth clearing up, and why doing it regularly changes what it is worth to you.
Read the post →Some testing you can genuinely do yourself on a tight budget. Where to start, which tools are worth learning, and the point at which you need an outside team.
Read the post →Staging and QA environments hold production data and get a fraction of the hardening. Why they keep appearing in findings, and how to get them off the internet.
Read the post →Network, web, mobile, API, IoT, wireless, physical, and social engineering. What each type of penetration testing covers, and when you need which one.
Read the post →A plain-language introduction for business owners: what a penetration test is, how it is run, and what you should expect to receive when it is finished.
Read the post →One more account of taking the OSCP, written for anyone weighing it up: what the preparation actually demanded, and what the exam does and does not measure.
Read the post →A connected device is a network host, a radio, a mobile app, and a cloud API at once. Why partial IoT testing misses the paths that actually get exploited.
Read the post →Two engagements with the same name can differ enormously in depth. What separates a real penetration test from an automated scan with a report attached.
Read the post →Being small is not protection; it makes you a cheaper target. Why smaller organizations get tested less, and a practical route to a first engagement.
Read the post →A vulnerability assessment lists what might be wrong. A penetration test proves what an attacker can do with it. The differences, and which one you need.
Read the post →Attackers use models to turn public DNS, GitHub, and job posts into a working map of you. The incident looks sophisticated when the first step was free.
Read the post →Small businesses assume real testing is out of reach. What drives the price of an engagement, and how to get meaningful coverage on a constrained budget.
Read the post →An internal penetration test answers the question an external one cannot: what happens once somebody is already inside. The process, and the usual findings.
Read the post →The Clorox cyberattack cost far more than remediation. Why reputational damage outlasts the incident, and where regular testing changes the outcome.
Read the post →An external penetration test covers everything an attacker can reach from the internet without credentials. What is in scope, and what the results tell you.
Read the post →Source code access changes how you test a web application. Finding targets, running semgrep, and reading code for the bugs a black box test never reaches.
Read the post →White box, black box, and grey box describe how much the tester knows before starting. What each approach finds, misses, and costs, and how to choose.
Read the post →Connected devices ship fast and get tested rarely. The methodologies, the practical obstacles, and the best practices behind a real IoT penetration test.
Read the post →What a penetration test is, the types available, and what you actually get out of one. A plain introduction for businesses that have never commissioned one.
Read the post →Default credentials turned up in five of our last five engagements, and several led straight to critical access. Why this keeps happening, and the fix.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.