LinkedIn·Tuesday, 25 August 2026·1d ago
Before you sign the next penetration test, check who the scope was written for. If it was written to satisfy an audit, it will pass an…
Curios
999 followers
Before you sign the next penetration test, check who the scope was written for.
If it was written to satisfy an audit, it will pass an audit. Whether someone can get in is a separate question. The scope document is where that gets decided.
Worth reading what the rules ask. NIS2 Article 21 asks you to assess whether your controls work, not to produce a certificate. DORA has been live since 17 January 2025, and significant entities run threat-led testing under TIBER-EU every three years. Three years. Your estate does not stand still that long.
Two things we would advise before the SOW is signed.
Scope from the attacker's route rather than the asset register. Ask where an intruder would actually go. The identity layer. The API nobody documented. The supplier added in March who never made the diagram.
Then let the compliance evidence fall out of the work instead of shaping it. It still gets produced. It just stops making the decisions.
A passed audit is not a measure of resistance.
#PenetrationTesting #NIS2
♥ 3↻ 1
View on LinkedIn Cross-referenced
Related on the wire
One of this week's 394 Microsoft fixes mentions us. CVE-2026-70324, elevation of privilege in SharePoint. The acknowledgement reads…
"Are we secure?" Someone asks it near the end. Item seven, after the budget, ten minutes left. We used to answer it. A slide, three green…
GDPR. NIS2. DORA. CRA. The AI Act. Five years ago your security program answered to one regulator. Soon it answers to five. The frameworks…
Every vulnerability you've ever patched had a name before you met it. Someone gave it that name. This week, that someone was one of ours.…
The CCB inspection notice lands on a Tuesday morning. No drama. Just a date. You registered long ago. But registration was never the finish…