Skip to content

Cyber security

Security testing, assessments and attack surface: how to find weaknesses, judge controls and know what you expose.

Courses

Cyber security beginner

Cyber risk assessment

Writing risks people can act on, scoring them honestly, and turning a register into decisions with owners and dates.

4 lessons 53 min Free

Guides

23 in this topic

Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025

Cyber security Guide · 2 min

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Cyber security 2 min read 21 May 2025

Cyber security Guide · 2 min

Testing Authentication and Session Management

Where real applications fail: reset flows, enrolment, federation, token lifetime and logout that does not log out.

Cyber security 2 min read 20 May 2025

Cyber security Guide · 2 min

Testing Business Logic

The weaknesses no scanner finds: legitimate requests in an illegitimate order.

Cyber security 2 min read 18 May 2025

Cyber security Guide · 2 min

Network Segmentation Testing

Proving that the boundaries on the diagram exist in the packets.

Cyber security 2 min read 16 May 2025

Cyber security Guide · 2 min

MITRE ATT&CK for Testing and Defence

A shared language for attacker behaviour, used well as a coverage map rather than a scoreboard.

Cyber security 2 min read 15 May 2025

Cyber security Guide · 2 min

Purple Teaming in Practice

Running attack and defence together so detection improves during the exercise rather than after the report.

Cyber security 2 min read 14 May 2025

Cyber security Guide · 2 min

Risk Registers That Stay Useful

Recording risk so decisions get made, rather than producing a spreadsheet nobody reads.

Cyber security 2 min read 13 May 2025

Cyber security Guide · 2 min

Security Questionnaires Worth Sending

Third-party assessment that produces information rather than a completed form.

Cyber security 2 min read 10 May 2025

Cyber security Guide · 2 min

SBOM and Software Supply Chain Visibility

Knowing what is in your software, so the next critical vulnerability is a query rather than a week.

Cyber security 2 min read 9 May 2025

Cyber security Guide · 2 min

Shadow IT and Unmanaged Assets

The systems nobody told you about, why they appear, and how to find them without becoming the enemy.

Cyber security 2 min read 7 May 2025

Cyber security Guide · 2 min

Identity as the Attack Surface

When the perimeter is a token, the attack surface is every account, key and consent in the directory.

Cyber security 2 min read 6 May 2025