Qualysec

Blog

Latest Articles

Page 1 of 160 · 1434 posts

Cyber Essentials vs. Cyber Essentials Plus What Is the Difference

October 8, 2026

Cyber Essentials vs. Cyber Essentials Plus: What Is the Difference?

Here’s a number worth knowing first. Organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance, according to the NCSC’s review of the scheme’s first decade. That comes from the insurer’s own data, so it counts claims, not every breach. It’s still striking for a scheme built on just […]

Understanding UK Medical Device Regulation (UK MDR 2002) A Complete Guide

October 7, 2026

Understanding UK Medical Device Regulation (UK MDR 2002): A Complete Guide

Meeting UK medical device regulation requirements can be difficult for companies launching their devices in the UK market. Issues such as classification, conformity assessment, technical documentation, registration, and post-marketing aspects need to be dealt with first. Regulatory changes are also taking place. According to the MHRA 2026 report, about 90% of medical devices in Great […]

Meeting DESC ISR Requirements Preparing for Mandatory Annual Penetration Testing

October 7, 2026

Meeting DESC ISR Requirements: Preparing for Mandatory Annual Penetration Testing

Your team may already run vulnerability scans every quarter. Findings are logged, remediation is tracked and another scan comes around before long. Then DESC ISR penetration testing becomes part of the discussion, and a few uncomfortable questions start coming up. Are the scans enough? What exactly needs to be tested? Who should perform the testing? […]

Australian Regulatory Guidelines for Medical Devices (ARGMD)

October 7, 2026

Australian Regulatory Guidelines for Medical Devices (ARGMD)

Australia’s medical device framework is supported by detailed TGA guidance. ARGMD helps you find the information relevant to each stage of the regulatory process. The Australian Regulatory Guidelines for Medical Devices is not a single piece of legislation or one complete regulatory manual. It now works as an index that connects manufacturers and sponsors with […]

ISO 27001 Certification in Australia

October 7, 2026

ISO 27001 Certification in Australia: The Complete Guide to Compliance, Costs, and VAPT Requirements

Australian businesses often need to show customers and partners how they protect sensitive information. For SaaS companies, technology providers and other data-focused businesses, ISO 27001 Australia certification can provide that assurance. ISO/IEC 27001:2022 sets the requirements for an information security management system ISMS. It helps an organisation manage information security risks within a defined scope. […]

Dubai Information Security Regulation (DESC ISR) What It Is and Who It Applies To

October 6, 2026

Dubai Information Security Regulation (DESC ISR): What It Is and Who It Applies To?

For a private company working with a Dubai Government Entity, there is one question that can be surprisingly difficult to answer: does the Dubai Information Security Regulation (ISR) apply to us, or are its requirements only for the government organisation? The confusion is easy to understand. A private company may provide IT services, manage systems, […]

CHECK Penetration Testing A Complete Security & Compliance Guide

October 6, 2026

CHECK Penetration Testing: A Complete Security & Compliance Guide

A tender document names CHECK penetration testing as a hard requirement. The compliance team pulls up its usual supplier list, only to find most of those firms hold CREST accreditation, not CHECK. The two get treated as interchangeable in casual conversation, but a procurement officer checking credentials against a government contract will not accept one […]

How to Pass Your Next ADHICS Audit The Role of Mandatory Penetration Testing

October 5, 2026

How to Pass Your Next ADHICS Audit: The Role of Mandatory Penetration Testing

An ADHICS audit can become uncomfortable long before an auditor finds a missing policy. The difficult questions usually start with evidence. Was every system handling health information covered by testing? Did the scope include APIs, internet-facing applications, cloud services and connected medical devices? If weaknesses were found, can your team show they were fixed and […]

Cyber Security and Resilience Bill Penetration Testing Requirements & Compliance Guide

October 5, 2026

Cyber Security and Resilience Bill: Penetration Testing Requirements & Compliance Guide

The Cyber Security and Resilience Bill just cleared a real milestone. It sits in the House of Lords as HL Bill 32, with Grand Committee scrutiny running across four sittings in September 2026. Peers have tabled dozens of amendments, including proposals on AI governance, vendor powers, and potential personal liability for company directors. Meanwhile, the […]

"Don't compromise between depth and speed. Own both. Connect with Swagat, Your trusted penetration testing advisor."

Swagat Kumar Dash

Swagat Kumar Dash

Head Of Business Development