// free resources

Take these. Free.

Practical checklists from real engagements. Use them internally, share them with your team — and when you want the full assessment behind them, you know where I am.

CHECKLIST

Before your penetration test

Scope defined in writing · test accounts for every role · staging parity confirmed · emergency contact named · logging enabled so you can watch the test · backup taken · legal authorisation signed. Arrive prepared, get more value per testing day.

Request this resource
PLAYBOOK

Incident: first 24 hours

Isolate, don't wipe · start the incident log · pull auth/VPN logs before retention loss · rotate service credentials · engage counsel before public statements · single spokesperson. Full walkthrough in the blog.

Read the playbook →
QUESTIONS

Vetting any security vendor

Who personally performs the work? · Manual or scanner-driven? · Sample report available? · Retest included? · Findings mapped to OWASP/PTES? If a vendor stumbles on these, keep looking.

Request this resource
STARTER

Compliance: where to begin

Clients asking for proof? Start with a gap assessment against the standard they name — usually SOC 2 or ISO 27001 — before paying auditors. The gap report becomes your roadmap.

SOC 2 guide →
CHECKLIST

LLM app pre-launch

Prompt injection (direct + indirect) · cross-tenant data leakage · tool-call authorisation · output sanitisation · guardrail bypass testing. Ship the assistant after it survives an adversary.

Full checklist →
DISCLOSURE

security.txt

This site publishes RFC 9116 vulnerability disclosure info at /.well-known/security.txt — the standard your own site should have too. Found something? Report it responsibly.

Request this resource
Get the full assessment →