Skip to content

Home » Insights

Insights

Guides from our penetration testers and certification assessors. Browse by topic:

Book a call

black and white number 9

The five Cyber Essentials controls: what they are and what assessors check

  • 9 min read

The five Cyber Essentials technical controls (firewalls, secure configuration, security update management, user access control and malware protection) explained by a certification body: what each requires, what the assessor checks, and where applicants fall short.

a calculator sitting on top of a table next to a laptop

How to build a defensible cyber security budget

  • 7 min read

In short. A defensible cyber security budget starts with a risk assessment, not last year’s figures or a vendor’s shopping list. Identify your most valuable assets and the threats most likely to hit them, then spread spend across people, process and technology so every pound maps to a business risk you can explain to the board. A defensible cyber security… 

group of people walking on the stairs

Cyber security for law firms: why cyber resilience is now part of professional practice

  • 8 min read

In short. Cyber security is a regulatory obligation for law firms, not just an IT concern: the SRA expects reasonable steps to protect client money, confidential information and systems, and both the SRA and the ICO can act after a breach. This guide covers what the regulator expects, the threats that target solicitors, and the controls that reduce the risk.… 

man standing in front of people sitting beside table with laptop computers

How to report cyber risk to the board

  • 7 min read

In short. Boards and technical teams want the same thing, a protected business, but talk past each other. Report cyber risk in business terms: link each vulnerability to an impact, choose a few metrics that show trend, answer “so what?” every time, and bring evidence from testing rather than assurances. Technical teams and boards have the same objective when it… 

low angle photo of city high rise buildings during daytime

Cyber security for financial services: what UK regulators expect and how to test against it

  • 8 min read

UK financial services firms are regulated for cyber security through operational resilience rules: important business services, impact tolerances and scenario testing, plus CBEST and STAR-FS for systemic firms, DORA for EU exposure and the new critical third parties regime. What each expects and what a proportionate testing programme looks like.

a person sitting at a desk with a laptop and a computer monitor

What is penetration testing, and why should you do it?

  • 9 min read

A penetration test is a controlled, authorised attempt to break into your systems so you find the weaknesses first. How it differs from a vulnerability scan, the types of test, the process from scoping to retest, and what a good report looks like.

macbook pro turned on displaying music

CREST vs The Cyber Scheme vs CHECK: what the qualifications mean

  • 11 min read

CREST and The Cyber Scheme certify UK penetration testers; CHECK is the NCSC scheme for testing government systems. What CSTM, CSTL, CRT and CCT involve, how they map to each other, and how they lead to UK Cyber Security Council titles and CHECK status.