Pentiq

Insights

Security insights and practical perspective

Latest insight

Industry Events

Pentiq Places 2nd in Great Britain at Hack The Box CTF 2026: Project Nightfall

Pentiq finished 2nd in GB and 38th globally (top 7%) at the Hack The Box Global Cyber Skills Benchmark CTF 2026, solving 116 of 126 challenges.

22 May 20264 min readRead article →
16 articles
Supply Chain Security

How a poisoned VS Code extension led to GitHub's May 2026 internal repository breach, the chain of connected companies compromised by TeamPCP, and the controls that actually reduce developer supply chain risk.

21 May 202610 min read
Application Security

What CVE-2026-44578 reveals about how server-side request forgery still slips into web frameworks, where it bites hardest, and how to defend beyond patching.

20 May 20264 min read
Vulnerability Management

Why CVSS base scores create noise, what CVSS 4.0 changes, and how to combine CVSS with KEV and EPSS for defensible vulnerability prioritisation.

14 May 20266 min read
Vulnerability Management

How the CISA KEV catalogue transforms vulnerability prioritisation, where it fits alongside EPSS and CVSS, and a simple defensible workflow.

14 May 20266 min read
Penetration Testing

Understand the factors that determine how often to schedule penetration tests, including compliance requirements, organisational complexity and change frequency.

28 Apr 20265 min read
Penetration Testing

Learn how external and internal penetration tests differ, what each aims to uncover, and why both are essential to a comprehensive security programme.

10 Apr 20265 min read
Application Security

Why APIs fail differently to web apps, the OWASP API issues that keep surfacing in 2026, and what a credible API security baseline looks like.

1 Apr 20266 min read
Attack Surface Management

How attackers map your internet-facing assets, the entry points they most often exploit, and the small set of changes that meaningfully reduce risk.

23 Mar 20266 min read
Penetration Testing

A practical guide to evaluating penetration test reports — what good reporting contains, what to ignore, and how to judge quality from the first three pages.

12 Mar 20269 min read
Governance & Policy

The UK ransomware payment ban, notification regime and mandatory reporting requirements explained — plus the controls that materially reduce impact.

27 Feb 20267 min read
Identity & Access

Why password complexity rules fail against modern Active Directory attacks, how AD compromise actually unfolds, and the controls that genuinely reduce risk.

19 Feb 20266 min read
Penetration Testing

Why SaaS organisations need focused penetration testing across applications, APIs, cloud platforms, identity systems and multi-tenant architecture.

2 Feb 20266 min read
Penetration Testing

A practical guide to help organisations prepare for penetration testing engagements, including scoping, documentation, rules of engagement and scheduling.

30 Jan 20265 min read
Penetration Testing

An evidence‑based walkthrough of a well‑run penetration test, covering pre‑engagement planning, discovery, exploitation, reporting and retesting.

28 Jan 20266 min read
Penetration Testing

Penetration testing and vulnerability scanning serve different purposes. A clear, practical guide to what each delivers, where each falls short, and how to choose the right mix.

13 Jan 20268 min read