Why Whitelisting Security Controls Can Lead to a Better Penetration Test
When conducting a penetration test, being asked to whitelist a tester’s IP address from certain security controls might sound counterintuitive. After all, aren’t those controls there to protect the application? They are. But depending on the objective of the penetration test, leaving them in place can actually prevent testers from properly assessing the security of… Continue reading Why Whitelisting Security Controls Can Lead to a Better Penetration Test
Why Are We Still Finding XSS in 2026?
“What is the most common vulnerability you still find in 2026?” It is a question we ask our penetration testers regularly. While Cross-Site Scripting (XSS) may not necessarily be the most common vulnerability we find, it is one that continues to stand out — both because of its potential impact and because, with the maturity… Continue reading Why Are We Still Finding XSS in 2026?
A Strategic Approach to Business Disaster Recovery
Planning for Disaster Recovery Disaster recovery is a critical component of business continuity, especially for medium to large enterprises that rely heavily on digital infrastructure, or use their digital infrastructure for any business operations. Cyber threats, natural disasters, hardware failures, and human errors can severely disrupt operations, resulting in financial losses and reputational damage. To… Continue reading A Strategic Approach to Business Disaster Recovery
Government Initiatives and Sanctions: Strengthening Cyber Security in Australia
The Australian Federal Government has launched several initiatives to combat cybercrime, with a particular focus on ransomware attacks. The introduction of new regulations, sanctions on cybercriminal groups, and the development of practical resources like the Ransomware Playbook signal a firm stance against digital threats. For companies affected by cyberattacks, cyber security service providers like Red… Continue reading Government Initiatives and Sanctions: Strengthening Cyber Security in Australia
Infostealers – The Risk Continues to Grow
Over recent years, Info stealer malware, also called infostealers, has grown as a formidable adversary for businesses worldwide, particularly in Australia. These malicious software programs are designed to infiltrate networks, stealthily collect sensitive data, and transfer it to cybercriminals who use it for financial gain, espionage, or other illicit activities. As Australian enterprises increasingly rely… Continue reading Infostealers – The Risk Continues to Grow
Building an Effective Cyber Security Plan
Building an effective cyber security strategy is no longer optional for medium to large businesses in today’s digital world. Businesses face an increasing threat to their systems, their data and criminal behaviour. Australian companies face not just local threats but a global spectrum of cyber risks, including data breaches, malware, ransomware, and phishing attacks. A… Continue reading Building an Effective Cyber Security Plan
Understanding Common Code Programming Issues Leading to Security Breaches
A great deal of focus when thinking about and or discussing security breaches is generally directed to issues with networks and or social engineering. In reality, many of these breaches stem from common issues in code writing. This blog explores different types of breaches, the potential damage each can inflict, and preventive measures that can… Continue reading Understanding Common Code Programming Issues Leading to Security Breaches
Embracing Zero Trust Security: A Strategic Imperative for Modern Businesses
Cyber threats are continuing to evolve, grow in sophistication and be more pervasive, causing traditional security measures to be no longer sufficient. This inadequacy has paved the way for the adoption of Zero Trust security strategies, a paradigm shift in how security is approached and implemented within organisations. Organisational adoption of Zero Trust security frameworks… Continue reading Embracing Zero Trust Security: A Strategic Imperative for Modern Businesses
The Rise of Info Stealer Malware: A Growing Threat to Businesses
Stealer malware, or information-stealing malware, is a type of malicious software designed to gather sensitive information typically targeting personal, financial, or business-related data. The data collected could include passwords, financial information, corporate data, and personal identification details. Once installed, this malware operates discreetly, often without triggering any noticeable alarms, making it particularly dangerous. The functionality… Continue reading The Rise of Info Stealer Malware: A Growing Threat to Businesses
Will AI Kill the Pen Testing Star
Those who use the different AI support technology available, are seeing a trend, that the results, generally speaking, produced by the tools are getting better every month. There is still the old computing issue of garbage in, garbage out, but as we learn to better seed the bots and the bots learn what data we… Continue reading Will AI Kill the Pen Testing Star









