// RESOURCES
Resources
Practical guides to report better and prove more.
// GUIDE
The structure of a good pentest report
What a client really wants. And what they don't know.
Read →
// GUIDE
ISO 27001: which controls a scan can prove
Technical vs organizational evidence.
Read →
// GUIDE
NIS2 for firms: what changes
Obligations, supply chain, expected evidence.
Read →
// GUIDE
Nmap to report: the guide
From XML export to reviewed deliverable.
Read →
// GUIDE
CVSS scores, explained without the jargon
What the number means, what the vector hides, and where it misleads.
Read →
// GUIDE
Nessus vs OpenVAS: which scanner for what
The honest trade-offs between the commercial standard and the open-source workhorse.
Read →
// GUIDE
Cutting false positives in vulnerability scans
Why scanners cry wolf, and how to hand a client a clean report.
Read →
// GUIDE
Prioritising vulnerabilities: why CVSS is not enough
CVSS ranks severity. It does not rank your risk.
Read →