Identity and cloud attack surface
When the perimeter is a token: accounts, keys, consents, cloud exposure and mapping the paths from a foothold to privilege.
Security testing, assessments and attack surface: how to find weaknesses, judge controls and know what you expose.
When the perimeter is a token: accounts, keys, consents, cloud exposure and mapping the paths from a foothold to privilege.
Continuous discovery of what you expose, triage of what is actually reachable, and remediation that holds.
What counts as attack surface, how to build an inventory that stays true, and why switching things off beats defending them.
Tiering suppliers, asking questions that produce information, reading audit reports and SBOMs, and contracting for what matters.
Choosing a framework, testing design and operation, gathering evidence that holds up, and reporting a gap plan.
Writing risks people can act on, scoring them honestly, and turning a register into decisions with owners and dates.
Objective-based exercises that test detection and response, and the collaborative loop that actually improves them.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.
A methodical way through an application: mapping, authentication flows, access control and business logic.
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
23 in this topic
A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.
Cyber security 2 min read 25 May 2025
What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.
Cyber security 2 min read 24 May 2025
Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.
Cyber security 2 min read 23 May 2025
Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.
Cyber security 2 min read 22 May 2025
A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.
Cyber security 2 min read 21 May 2025
Where real applications fail: reset flows, enrolment, federation, token lifetime and logout that does not log out.
Cyber security 2 min read 20 May 2025
The most common serious weakness in modern applications, and the methodical way to test for it.
Cyber security 2 min read 19 May 2025
The weaknesses no scanner finds: legitimate requests in an illegitimate order.
Cyber security 2 min read 18 May 2025
Finding what is actually listening, and why the inventory is always wrong.
Cyber security 2 min read 17 May 2025
Proving that the boundaries on the diagram exist in the packets.
Cyber security 2 min read 16 May 2025
A shared language for attacker behaviour, used well as a coverage map rather than a scoreboard.
Cyber security 2 min read 15 May 2025
Running attack and defence together so detection improves during the exercise rather than after the report.
Cyber security 2 min read 14 May 2025
Recording risk so decisions get made, rather than producing a spreadsheet nobody reads.
Cyber security 2 min read 13 May 2025
Three frameworks, three different jobs — and how to choose without buying all of them.
Cyber security 2 min read 12 May 2025
Testing whether a control works, not whether somebody says it does.
Cyber security 2 min read 11 May 2025
Third-party assessment that produces information rather than a completed form.
Cyber security 2 min read 10 May 2025
Knowing what is in your software, so the next critical vulnerability is a query rather than a week.
Cyber security 2 min read 9 May 2025
Finding the internet-facing things you own, including the ones nobody remembers creating.
Cyber security 2 min read 8 May 2025
The systems nobody told you about, why they appear, and how to find them without becoming the enemy.
Cyber security 2 min read 7 May 2025
When the perimeter is a token, the attack surface is every account, key and consent in the directory.
Cyber security 2 min read 6 May 2025