// Resources

Insights & Guides

Practical guides on penetration testing, security, and compliance — written by our operators.

Aug 13, 2026

Security Assessment Statement of Work: Acceptance and Evidence

A bounded assessment SOW structure covering authorization, ROE, evidence custody, retest, and supplier duties.

Read
Aug 12, 2026

Third-Party Cybersecurity Questionnaire: Evidence, Scores, Owners

Evidence-led supplier questionnaire with scoring, ownership, exceptions, and remediation rules.

Read
Aug 11, 2026

Security Testing Evidence for ISO/IEC 27001:2022

How to keep testing evidence useful to an ISO/IEC 27001 program without making certification claims.

Read
Aug 10, 2026

SPBE Security Assessment Evidence: Reviewable Record

Source-aware evidence record for a security assessment supporting SPBE governance review.

Read
Aug 9, 2026

OJK Information-Security Risk Management: Evidence Checklist

Practical source-grounded guide for OJK Information-Security Risk Management: Evidence Checklist

Read
Aug 8, 2026

Personal Data Incident Response Requirements in Indonesia

Practical source-grounded guide for Personal Data Incident Response Requirements in Indonesia

Read
Aug 7, 2026

Indonesia Personal Data Protection Law: Security-Control Workbook

Practical source-grounded guide for Indonesia Personal Data Protection Law: Security-Control Workbook

Read
Aug 6, 2026

Ransomware Resilience Assessment Checklist

Practical source-grounded guide for Ransomware Resilience Assessment Checklist

Read
Aug 5, 2026

Cybersecurity Incident-Response Tabletop Worksheet

Practical source-grounded guide for Cybersecurity Incident-Response Tabletop Worksheet

Read
Aug 4, 2026

Retesting Security Findings and Preserving Remediation Evidence

Practical source-grounded guide for Retesting Security Findings and Preserving Remediation Evidence

Read
Aug 3, 2026

How to Evaluate a Security Assessment Report

Practical source-grounded guide for How to Evaluate a Security Assessment Report

Read
Aug 2, 2026

Security Assessment Scope Definition Workbook

Practical source-grounded guide for Security Assessment Scope Definition Workbook

Read
Aug 1, 2026

Rules of Engagement for a Safe Security Assessment

Practical source-grounded guide for Rules of Engagement for a Safe Security Assessment

Read
Jul 31, 2026

Vulnerability Remediation SLAs: A Practical Workbook

Practical source-grounded guide for Vulnerability Remediation SLAs: A Practical Workbook

Read
Jul 30, 2026

Prioritizing Vulnerabilities with CVE, CWE, and CISA KEV

Practical source-grounded guide for Prioritizing Vulnerabilities with CVE, CWE, and CISA KEV

Read
Jul 29, 2026

Network Segmentation Validation: From Diagram to Evidence

Practical source-grounded guide for Network Segmentation Validation: From Diagram to Evidence

Read
Jul 28, 2026

Windows Server Hardening Baseline for Security Reviews

Practical source-grounded guide for Windows Server Hardening Baseline for Security Reviews

Read
Jul 27, 2026

Windows LAPS and gMSA Review for Credential Exposure

Practical source-grounded guide for Windows LAPS and gMSA Review for Credential Exposure

Read
Jul 26, 2026

Active Directory Tiering and Privileged-Account Review

Practical source-grounded guide for Active Directory Tiering and Privileged-Account Review

Read
Jul 25, 2026

VPN and Remote-Access Security Review Checklist

Review VPN and remote access through gateway exposure, MFA, entitlement lifecycle, device posture, sessions, and evidence.

Read
Jul 24, 2026

Zero Trust Architecture: Practical Assessment Worksheet

A per-resource zero-trust assessment method with policy decisions, evidence, owners, results, and remediation.

Read
Jul 23, 2026

CI/CD Pipeline Security Controls Buyers Should Request

How to review CI/CD provenance, workflow protection, runner identity, and secret boundaries with evidence.

Read
Jul 22, 2026

Terraform Security Review for Infrastructure as Code

Evidence-led Terraform review for state protection, sensitive values, pinned providers, and reviewed plans.

Read
Jul 21, 2026

Kubernetes RBAC and NetworkPolicy Review

Evidence-led review of Kubernetes API access, service accounts, and default-deny network controls.

Read
Jul 20, 2026

Container Image Security Review Checklist

Evidence-led review of container image provenance, layers, non-root runtime, and deployment policy.

Read
Jul 19, 2026

Cloud Security Posture Review: A Buyer’s Evidence Checklist

Practical source-grounded guide for Cloud Security Posture Review: A Buyer’s Evidence Checklist

Read
Jul 18, 2026

Cloud Audit Logging Baseline: Coverage, Protection, Integrity

Build auditable cloud logging with event coverage, protected sinks, retention, integrity checks, evidence, exceptions, and remediation.

Read
Jul 17, 2026

Cloud KMS Key Management: Review Access and Lifecycle

Review KMS policies, grants, encryption context, rotation, deletion, evidence, exceptions, and remediation across cloud key services.

Read
Jul 16, 2026

AWS S3 Security Review: Public Access to Evidence

Review S3 Block Public Access, Object Ownership, policies, ACLs, presigned URLs, and CloudTrail data-event evidence.

Read
Jul 15, 2026

Cloud IAM Least-Privilege Review: Effective Permissions

Review cloud IAM effective permissions, role assumption paths, boundaries, evidence, exceptions, and remediation.

Read
Jul 14, 2026

Mobile Permission and Privacy Manifest Review

Practical source-grounded guide for Mobile Permission and Privacy Manifest Review

Read
Jul 13, 2026

Mobile Push Notification Privacy Review

Practical source-grounded guide for Mobile Push Notification Privacy Review

Read
Jul 12, 2026

Mobile Biometric Authentication: What to Verify

Practical source-grounded guide for Mobile Biometric Authentication: What to Verify

Read
Jul 11, 2026

iOS Universal Links Security Review

Evidence-led review for iOS Universal Links, associated domains, AASA routing, and hostile URL input.

Read
Jul 10, 2026

iOS Keychain and Data Protection Review Checklist

Evidence-led review for iOS Keychain accessibility, access groups, and file Data Protection classes.

Read
Jul 9, 2026

Android Exported Components: Security Review Worksheet

Evidence-led review for Android component exposure, permissions, provider access, and API behavior.

Read
Jul 8, 2026

Android App Links and Deep Links Security Review

Evidence-led review method for Android App Links, deep-link routing, and untrusted URI input.

Read
Jul 7, 2026

Android Network Security Configuration Review

Release-focused review of Android Network Security Configuration trust anchors, debug overrides, cleartext policy, and pinning.

Read
Jul 6, 2026

Android Keystore Security Review Checklist

A release-focused Android Keystore review with authentication-bound key, StrongBox, evidence, and remediation checks.

Read
Jul 5, 2026

Mapping Mobile Security Testing to OWASP MASVS

A practical OWASP MASVS control-to-test map with evidence, owners, acceptance, and remediation.

Read
Jul 4, 2026

Secure Error Handling and Information Disclosure Review

Source-grounded practical guide for Secure Error Handling and Information Disclosure Review

Read
Jul 3, 2026

Secure Logging: Preventing Sensitive Data Leakage

Source-grounded practical guide for Secure Logging: Preventing Sensitive Data Leakage

Read
Jul 2, 2026

Secrets in Source Code: Review and Remediation Checklist

Source-grounded practical guide for Secrets in Source Code: Review and Remediation Checklist

Read
Jul 1, 2026

SBOM Requirements for Software Procurement and Assurance

Source-grounded practical guide for SBOM Requirements for Software Procurement and Assurance

Read
Jun 30, 2026

Dependency Vulnerability Management Without Blind Trust in Scanners

Source-grounded practical guide for Dependency Vulnerability Management Without Blind Trust in Scanners

Read
Jun 29, 2026

SAST, DAST, and IAST: Choosing the Right Security Test

Source-grounded practical guide for SAST, DAST, and IAST: Choosing the Right Security Test

Read
Jun 28, 2026

Security Gates for a Practical Software Development Lifecycle

Source-grounded practical guide for Security Gates for a Practical Software Development Lifecycle

Read
Jun 27, 2026

SQL Injection Prevention Review for Application Teams

Source-grounded practical guide for SQL Injection Prevention Review for Application Teams

Read
Jun 26, 2026

CSRF and SameSite Cookie Review Checklist

Source-grounded practical guide for CSRF and SameSite Cookie Review Checklist

Read
Jun 25, 2026

XSS Prevention Review: Contextual Output Encoding

Source-grounded practical guide for XSS Prevention Review: Contextual Output Encoding

Read
Jun 24, 2026

CSP and Security Header Review for Production Websites

Source-grounded practical guide for CSP and Security Header Review for Production Websites

Read
Jun 23, 2026

Safe URL Fetching: SSRF-Resistant Design Worksheet

Source-grounded practical guide for Safe URL Fetching: SSRF-Resistant Design Worksheet

Read
Jun 22, 2026

Secure File Upload Review Checklist

Source-grounded practical guide for Secure File Upload Review Checklist

Read
Jun 21, 2026

SSRF Testing Against Cloud Metadata Boundaries

Source-grounded practical guide for SSRF Testing Against Cloud Metadata Boundaries

Read
Jun 20, 2026

Webhook Security: Signature Verification and Replay Protection

Source-grounded practical guide for Webhook Security: Signature Verification and Replay Protection

Read
Jun 19, 2026

Password Reset Security Review: Tokens, Enumeration, and Expiry

Practical, source-grounded review guide for Password Reset Security Review: Tokens, Enumeration, and Expiry

Read
Jun 18, 2026

MFA Enrollment and Account-Recovery Security Review

Practical, source-grounded review guide for MFA Enrollment and Account-Recovery Security Review

Read
Jun 17, 2026

Session Management Controls to Verify Before Release

Practical, source-grounded review guide for Session Management Controls to Verify Before Release

Read
Jun 16, 2026

JWT Security Review Checklist for Web APIs

Practical, source-grounded review guide for JWT Security Review Checklist for Web APIs

Read
Jun 15, 2026

OAuth 2.0 and OpenID Connect Security Review Worksheet

Practical, source-grounded review guide for OAuth 2.0 and OpenID Connect Security Review Worksheet

Read
Jun 14, 2026

GraphQL Security Review Checklist

Practical, source-grounded review guide for GraphQL Security Review Checklist

Read
Jun 13, 2026

How to Build an API Inventory and Find Shadow Endpoints

Practical, source-grounded review guide for How to Build an API Inventory and Find Shadow Endpoints

Read
Jun 12, 2026

API Rate-Limit Testing for Abuse and Cost Control

Practical, source-grounded review guide for API Rate-Limit Testing for Abuse and Cost Control

Read
Jun 11, 2026

API Function-Level Authorization Review Guide

Practical, source-grounded review guide for API Function-Level Authorization Review Guide

Read
Jun 10, 2026

Testing Broken Object-Level Authorization in APIs

Practical, source-grounded review guide for Testing Broken Object-Level Authorization in APIs

Read
Jun 9, 2026

OWASP API Security Testing Checklist for Engineering Teams

Practical, source-grounded review guide for OWASP API Security Testing Checklist for Engineering Teams

Read
Jun 8, 2026

How to Choose a Penetration Testing Vendor: A Buyer's Guide

Compare penetration testing vendors by asking how manual work, retesting, reporting, scope, and standards mapping are defined for your engagement.

Read
Jun 8, 2026

BSSN & SPBE Compliance: Security Testing for Indonesian Government Systems

Security testing can support assurance for Indonesian government electronic systems. Applicable SPBE and BSSN considerations depend on system scope and current official guidance.

Read
Jun 6, 2026

CVSS Explained: How We Score Vulnerability Severity

CVSS is the open industry standard for scoring how severe a vulnerability is, on a 0–10 scale derived from a vector string of metrics like Attack Vector, Privileges Required, and impact to confidentiality, integrity, and availability. Here's how to read a score, what 3.1 and 4.0 measure, and why the number is a starting point, not the whole story.

Read
Jun 6, 2026

Active Directory Penetration Testing: From Foothold to Domain Admin

An Active Directory penetration test simulates an attacker who already has a foothold inside your network and maps the path to Domain Admin — through enumeration, credential attacks like Kerberoasting, lateral movement, and privilege escalation. Here's the attack chain we walk, and the misconfigurations that hand over the whole domain.

Read
Jun 5, 2026

Mobile Application Penetration Testing: iOS & Android, Explained

A mobile application penetration test assesses three layers — the app on the device, its local data storage, and the backend API it talks to — against the OWASP MASVS standard. It covers insecure storage, certificate pinning bypass, reverse engineering, and the IPC and deep-link attack surface. Here's how it works.

Read
Jun 5, 2026

Web Application Penetration Testing: What It Actually Tests

A web application penetration test is a manual, attacker-led assessment that maps to the OWASP Testing Guide and hunts the OWASP Top 10 — broken access control, injection, authentication flaws, SSRF, and business-logic abuse — then proves real impact. Here's what happens under the hood.

Read
Jun 4, 2026

How Much Does a Penetration Test Cost? A Pricing Guide for Indonesia

The price of a penetration test depends mostly on how big and complex the application is — not a fixed rate. Here's what drives pentest cost in Indonesia and how to get an accurate quote.

Read
Jun 4, 2026

Source Code Review vs Penetration Testing: Which Do You Need?

A source code review reads your application from the inside; a penetration test attacks it from the outside. Here's how the two differ, what each one finds, and when to use which — or both.

Read
Jun 3, 2026

Penetration Testing & Compliance in Indonesia: OJK, UU PDP, and ISO 27001

Penetration testing can support security assurance in Indonesia. Applicable obligations and assessment needs depend on sector, system, and current legal advice.

Read
Jun 3, 2026

Types of Penetration Testing: Black-Box vs Grey-Box vs White-Box

The main types of penetration testing are defined two ways: by how much access the tester is given (black-box, grey-box, white-box) and by what is tested (web, mobile, infrastructure, Active Directory). Here's how to choose.

Read
Jun 3, 2026

What Is Penetration Testing? A Practical Guide for 2026

Penetration testing is an authorized, simulated cyberattack on your systems to find and prove exploitable vulnerabilities before real attackers do. Here's how it works, what you get, and when you need one.

Read