RESEARCH & WRITING

Notes from the team

What we learn breaking and defending things, written plainly. No gatekeeping, no fluff.

2026-07-24 · RESEARCH

Is p=none enough? Publishing DMARC is not the same as enforcing it

We resolved the email authentication of 300 top domains. 84.7% publish a DMARC record but only 67.3% enforce one, and just 4.7% deploy MTA-STS.

2026-07-21 · RESEARCH

How many top domains restrict who can issue their certificates?

We read the public CAA records of the 1,000 busiest domains. Only 32.4% limit which authorities can issue their TLS certificates; the rest set none.

2026-07-21 · GUIDE

How often should you get a penetration test?

At least once every 12 months and after any significant change. What PCI DSS, SOC 2, and ISO 27001 actually require, and when annual is not enough.

2026-07-20 · RESEARCH

How exposed are the top 1,000 domains to email spoofing?

We read the public email-authentication DNS of the 1,000 busiest domains. 41.5% publish no enforcing DMARC, so mail forging their name can reach inboxes.

2026-07-19 · GUIDE

Red team or penetration test: which do you need?

Two terms, two different jobs. The real difference in goal and scope, and an honest gate on which your company actually needs.

2026-07-19 · GUIDE

How to prepare for your first penetration test

A practical checklist so day one is not wasted: scope, environment, access, timing, and the documents to have ready.

2026-07-19 · GUIDE

Does SOC 2 require a penetration test?

The standard never names one, but your auditor expects it. What the AICPA criteria actually say, and what auditors accept.

2026-07-19 · GUIDE

Do I need a pentest for cyber insurance?

It depends on the carrier and your coverage. What applications really ask, and why honest answers matter more than the test.

2026-07-19 · GUIDE

How much does a penetration test cost in 2026?

Real market ranges from public pricing guides, what actually drives a quote, and where a $100 check fits. No sales math.

2026-07-19 · GUIDE

What can attackers actually see about your company?

Subdomains you forgot, services that should never have been public, leaked passwords, and mail records anyone can forge. In plain language.

2026-07-15 · PRACTICE

Why every engagement starts with a signature

Authorization and scope are not paperwork. They are the line between a penetration test and a crime. Here is how we draw it, every time.

2026-06-30 · GUIDE

Check, scan, or full pentest?

Three very different services get sold under the word "pentest." A plain guide to telling them apart and picking the one you actually need.

2026-06-12 · CRAFT

What OSCP, OSEP, and CRTO actually prove

The alphabet soup on a security team's page, translated into what each certification really tells you about the work you will get.