Insights & Guides
Practical guides on penetration testing, security, and compliance — written by our operators.
Security Assessment Statement of Work: Acceptance and Evidence
A bounded assessment SOW structure covering authorization, ROE, evidence custody, retest, and supplier duties.
Third-Party Cybersecurity Questionnaire: Evidence, Scores, Owners
Evidence-led supplier questionnaire with scoring, ownership, exceptions, and remediation rules.
Security Testing Evidence for ISO/IEC 27001:2022
How to keep testing evidence useful to an ISO/IEC 27001 program without making certification claims.
SPBE Security Assessment Evidence: Reviewable Record
Source-aware evidence record for a security assessment supporting SPBE governance review.
OJK Information-Security Risk Management: Evidence Checklist
Practical source-grounded guide for OJK Information-Security Risk Management: Evidence Checklist
Personal Data Incident Response Requirements in Indonesia
Practical source-grounded guide for Personal Data Incident Response Requirements in Indonesia
Indonesia Personal Data Protection Law: Security-Control Workbook
Practical source-grounded guide for Indonesia Personal Data Protection Law: Security-Control Workbook
Ransomware Resilience Assessment Checklist
Practical source-grounded guide for Ransomware Resilience Assessment Checklist
Cybersecurity Incident-Response Tabletop Worksheet
Practical source-grounded guide for Cybersecurity Incident-Response Tabletop Worksheet
Retesting Security Findings and Preserving Remediation Evidence
Practical source-grounded guide for Retesting Security Findings and Preserving Remediation Evidence
How to Evaluate a Security Assessment Report
Practical source-grounded guide for How to Evaluate a Security Assessment Report
Security Assessment Scope Definition Workbook
Practical source-grounded guide for Security Assessment Scope Definition Workbook
Rules of Engagement for a Safe Security Assessment
Practical source-grounded guide for Rules of Engagement for a Safe Security Assessment
Vulnerability Remediation SLAs: A Practical Workbook
Practical source-grounded guide for Vulnerability Remediation SLAs: A Practical Workbook
Prioritizing Vulnerabilities with CVE, CWE, and CISA KEV
Practical source-grounded guide for Prioritizing Vulnerabilities with CVE, CWE, and CISA KEV
Network Segmentation Validation: From Diagram to Evidence
Practical source-grounded guide for Network Segmentation Validation: From Diagram to Evidence
Windows Server Hardening Baseline for Security Reviews
Practical source-grounded guide for Windows Server Hardening Baseline for Security Reviews
Windows LAPS and gMSA Review for Credential Exposure
Practical source-grounded guide for Windows LAPS and gMSA Review for Credential Exposure
Active Directory Tiering and Privileged-Account Review
Practical source-grounded guide for Active Directory Tiering and Privileged-Account Review
VPN and Remote-Access Security Review Checklist
Review VPN and remote access through gateway exposure, MFA, entitlement lifecycle, device posture, sessions, and evidence.
Zero Trust Architecture: Practical Assessment Worksheet
A per-resource zero-trust assessment method with policy decisions, evidence, owners, results, and remediation.
CI/CD Pipeline Security Controls Buyers Should Request
How to review CI/CD provenance, workflow protection, runner identity, and secret boundaries with evidence.
Terraform Security Review for Infrastructure as Code
Evidence-led Terraform review for state protection, sensitive values, pinned providers, and reviewed plans.
Kubernetes RBAC and NetworkPolicy Review
Evidence-led review of Kubernetes API access, service accounts, and default-deny network controls.
Container Image Security Review Checklist
Evidence-led review of container image provenance, layers, non-root runtime, and deployment policy.
Cloud Security Posture Review: A Buyer’s Evidence Checklist
Practical source-grounded guide for Cloud Security Posture Review: A Buyer’s Evidence Checklist
Cloud Audit Logging Baseline: Coverage, Protection, Integrity
Build auditable cloud logging with event coverage, protected sinks, retention, integrity checks, evidence, exceptions, and remediation.
Cloud KMS Key Management: Review Access and Lifecycle
Review KMS policies, grants, encryption context, rotation, deletion, evidence, exceptions, and remediation across cloud key services.
AWS S3 Security Review: Public Access to Evidence
Review S3 Block Public Access, Object Ownership, policies, ACLs, presigned URLs, and CloudTrail data-event evidence.
Cloud IAM Least-Privilege Review: Effective Permissions
Review cloud IAM effective permissions, role assumption paths, boundaries, evidence, exceptions, and remediation.
Mobile Permission and Privacy Manifest Review
Practical source-grounded guide for Mobile Permission and Privacy Manifest Review
Mobile Push Notification Privacy Review
Practical source-grounded guide for Mobile Push Notification Privacy Review
Mobile Biometric Authentication: What to Verify
Practical source-grounded guide for Mobile Biometric Authentication: What to Verify
iOS Universal Links Security Review
Evidence-led review for iOS Universal Links, associated domains, AASA routing, and hostile URL input.
iOS Keychain and Data Protection Review Checklist
Evidence-led review for iOS Keychain accessibility, access groups, and file Data Protection classes.
Android Exported Components: Security Review Worksheet
Evidence-led review for Android component exposure, permissions, provider access, and API behavior.
Android App Links and Deep Links Security Review
Evidence-led review method for Android App Links, deep-link routing, and untrusted URI input.
Android Network Security Configuration Review
Release-focused review of Android Network Security Configuration trust anchors, debug overrides, cleartext policy, and pinning.
Android Keystore Security Review Checklist
A release-focused Android Keystore review with authentication-bound key, StrongBox, evidence, and remediation checks.
Mapping Mobile Security Testing to OWASP MASVS
A practical OWASP MASVS control-to-test map with evidence, owners, acceptance, and remediation.
Secure Error Handling and Information Disclosure Review
Source-grounded practical guide for Secure Error Handling and Information Disclosure Review
Secure Logging: Preventing Sensitive Data Leakage
Source-grounded practical guide for Secure Logging: Preventing Sensitive Data Leakage
Secrets in Source Code: Review and Remediation Checklist
Source-grounded practical guide for Secrets in Source Code: Review and Remediation Checklist
SBOM Requirements for Software Procurement and Assurance
Source-grounded practical guide for SBOM Requirements for Software Procurement and Assurance
Dependency Vulnerability Management Without Blind Trust in Scanners
Source-grounded practical guide for Dependency Vulnerability Management Without Blind Trust in Scanners
SAST, DAST, and IAST: Choosing the Right Security Test
Source-grounded practical guide for SAST, DAST, and IAST: Choosing the Right Security Test
Security Gates for a Practical Software Development Lifecycle
Source-grounded practical guide for Security Gates for a Practical Software Development Lifecycle
SQL Injection Prevention Review for Application Teams
Source-grounded practical guide for SQL Injection Prevention Review for Application Teams
CSRF and SameSite Cookie Review Checklist
Source-grounded practical guide for CSRF and SameSite Cookie Review Checklist
XSS Prevention Review: Contextual Output Encoding
Source-grounded practical guide for XSS Prevention Review: Contextual Output Encoding
CSP and Security Header Review for Production Websites
Source-grounded practical guide for CSP and Security Header Review for Production Websites
Safe URL Fetching: SSRF-Resistant Design Worksheet
Source-grounded practical guide for Safe URL Fetching: SSRF-Resistant Design Worksheet
Secure File Upload Review Checklist
Source-grounded practical guide for Secure File Upload Review Checklist
SSRF Testing Against Cloud Metadata Boundaries
Source-grounded practical guide for SSRF Testing Against Cloud Metadata Boundaries
Webhook Security: Signature Verification and Replay Protection
Source-grounded practical guide for Webhook Security: Signature Verification and Replay Protection
Password Reset Security Review: Tokens, Enumeration, and Expiry
Practical, source-grounded review guide for Password Reset Security Review: Tokens, Enumeration, and Expiry
MFA Enrollment and Account-Recovery Security Review
Practical, source-grounded review guide for MFA Enrollment and Account-Recovery Security Review
Session Management Controls to Verify Before Release
Practical, source-grounded review guide for Session Management Controls to Verify Before Release
JWT Security Review Checklist for Web APIs
Practical, source-grounded review guide for JWT Security Review Checklist for Web APIs
OAuth 2.0 and OpenID Connect Security Review Worksheet
Practical, source-grounded review guide for OAuth 2.0 and OpenID Connect Security Review Worksheet
GraphQL Security Review Checklist
Practical, source-grounded review guide for GraphQL Security Review Checklist
How to Build an API Inventory and Find Shadow Endpoints
Practical, source-grounded review guide for How to Build an API Inventory and Find Shadow Endpoints
API Rate-Limit Testing for Abuse and Cost Control
Practical, source-grounded review guide for API Rate-Limit Testing for Abuse and Cost Control
API Function-Level Authorization Review Guide
Practical, source-grounded review guide for API Function-Level Authorization Review Guide
Testing Broken Object-Level Authorization in APIs
Practical, source-grounded review guide for Testing Broken Object-Level Authorization in APIs
OWASP API Security Testing Checklist for Engineering Teams
Practical, source-grounded review guide for OWASP API Security Testing Checklist for Engineering Teams
How to Choose a Penetration Testing Vendor: A Buyer's Guide
Compare penetration testing vendors by asking how manual work, retesting, reporting, scope, and standards mapping are defined for your engagement.
BSSN & SPBE Compliance: Security Testing for Indonesian Government Systems
Security testing can support assurance for Indonesian government electronic systems. Applicable SPBE and BSSN considerations depend on system scope and current official guidance.
CVSS Explained: How We Score Vulnerability Severity
CVSS is the open industry standard for scoring how severe a vulnerability is, on a 0–10 scale derived from a vector string of metrics like Attack Vector, Privileges Required, and impact to confidentiality, integrity, and availability. Here's how to read a score, what 3.1 and 4.0 measure, and why the number is a starting point, not the whole story.
Active Directory Penetration Testing: From Foothold to Domain Admin
An Active Directory penetration test simulates an attacker who already has a foothold inside your network and maps the path to Domain Admin — through enumeration, credential attacks like Kerberoasting, lateral movement, and privilege escalation. Here's the attack chain we walk, and the misconfigurations that hand over the whole domain.
Mobile Application Penetration Testing: iOS & Android, Explained
A mobile application penetration test assesses three layers — the app on the device, its local data storage, and the backend API it talks to — against the OWASP MASVS standard. It covers insecure storage, certificate pinning bypass, reverse engineering, and the IPC and deep-link attack surface. Here's how it works.
Web Application Penetration Testing: What It Actually Tests
A web application penetration test is a manual, attacker-led assessment that maps to the OWASP Testing Guide and hunts the OWASP Top 10 — broken access control, injection, authentication flaws, SSRF, and business-logic abuse — then proves real impact. Here's what happens under the hood.
How Much Does a Penetration Test Cost? A Pricing Guide for Indonesia
The price of a penetration test depends mostly on how big and complex the application is — not a fixed rate. Here's what drives pentest cost in Indonesia and how to get an accurate quote.
Source Code Review vs Penetration Testing: Which Do You Need?
A source code review reads your application from the inside; a penetration test attacks it from the outside. Here's how the two differ, what each one finds, and when to use which — or both.
Penetration Testing & Compliance in Indonesia: OJK, UU PDP, and ISO 27001
Penetration testing can support security assurance in Indonesia. Applicable obligations and assessment needs depend on sector, system, and current legal advice.
Types of Penetration Testing: Black-Box vs Grey-Box vs White-Box
The main types of penetration testing are defined two ways: by how much access the tester is given (black-box, grey-box, white-box) and by what is tested (web, mobile, infrastructure, Active Directory). Here's how to choose.
What Is Penetration Testing? A Practical Guide for 2026
Penetration testing is an authorized, simulated cyberattack on your systems to find and prove exploitable vulnerabilities before real attackers do. Here's how it works, what you get, and when you need one.