// free resources
Take these. Free.
Practical checklists from real engagements. Use them internally, share them with your team — and when you want the full assessment behind them, you know where I am.
Before your penetration test
Scope defined in writing · test accounts for every role · staging parity confirmed · emergency contact named · logging enabled so you can watch the test · backup taken · legal authorisation signed. Arrive prepared, get more value per testing day.
Request this resourceIncident: first 24 hours
Isolate, don't wipe · start the incident log · pull auth/VPN logs before retention loss · rotate service credentials · engage counsel before public statements · single spokesperson. Full walkthrough in the blog.
Read the playbook →Vetting any security vendor
Who personally performs the work? · Manual or scanner-driven? · Sample report available? · Retest included? · Findings mapped to OWASP/PTES? If a vendor stumbles on these, keep looking.
Request this resourceCompliance: where to begin
Clients asking for proof? Start with a gap assessment against the standard they name — usually SOC 2 or ISO 27001 — before paying auditors. The gap report becomes your roadmap.
SOC 2 guide →LLM app pre-launch
Prompt injection (direct + indirect) · cross-tenant data leakage · tool-call authorisation · output sanitisation · guardrail bypass testing. Ship the assistant after it survives an adversary.
Full checklist →security.txt
This site publishes RFC 9116 vulnerability disclosure info at /.well-known/security.txt — the standard your own site should have too. Found something? Report it responsibly.
Request this resource