Blog
Latest Articles
Page 1 of 158 · 1418 posts

September 24, 2026
CREST STAR-FS: Intelligence-Led Penetration Tests (ILPT) for UK Financial Services (Beyond CBEST)
CREST STAR-FS intelligence-led penetration tests provide UK financial organisations with a structured way to assess resilience against realistic cyber attacks. Unlike vulnerability testing alone, it relies on threat intelligence and attack simulations. These assess your organisation’s ability to defend, detect, and react in case of an attack when attackers target Important Business Services. In December […]

September 24, 2026
Why Mandatory Third-Party VAPT Is Critical for DFSA Compliance
In July 2026, the UAE Cybersecurity Council said it had stopped a series of sophisticated cyberattacks targeting financial-sector organisations. The attacks tried to exploit security vulnerabilities, compromise digital systems and deploy malware. For a DFSA-regulated fintech, this raises a practical question: is a vulnerability scan enough to know whether your customer-facing systems are secure? A […]

September 24, 2026
CREST VAPT Services in the Philippines
CREST VAPT services in the Philippines help organisations determine whether their security controls can withstand real-world cyberattacks. Many businesses still rely on automated vulnerability scans that identify known weaknesses without showing how attackers could exploit or chain them. According to Fortinet’s 2026 Global Cybersecurity Skills Gap Report, 93% of organisations surveyed in the Philippines reported […]

September 24, 2026
How to Achieve the CSA Cyber Trust Mark: Certification & Audit Guide for SG Businesses
From February 2026, the old CSA Cyber Trust Mark under Cyber Trust (2022) stopped being valid entirely. If your organisation is still working off the old framework, you’re preparing against a standard the Cyber Security Agency of Singapore no longer recognises. CSA publishes the current version, Cyber Trust (2025), as Singapore Standard SS 712:2025. It’s […]

September 23, 2026
The Ultimate AI Governance Compliance Checklist
AI adoption inside enterprises isn’t slowing down to let governance catch its breath, and regulators have made it clear they won’t wait either. Flying blind, deploying models without a documented inventory, without risk classification, without any real testing behind the guardrails, isn’t a viable posture anymore. Under the EU AI Act, prohibited practices have carried […]

September 23, 2026
What the CREST AI Charter Means for Enterprise Security Buyers
The CREST AI Charter gives security buyers a clear way to understand how cybersecurity providers should use AI in their institutions. You should know how a CREST AI-accredited provider handles your data, validates AI-generated outputs, manages third-party models, and maintains human oversight. The charter addresses these concerns through a set of principles for responsible AI […]

September 23, 2026
SFC Penetration Testing Requirements in Hong Kong: When Is It Required?
Hong Kong financial firms operate under strict regulatory and cybersecurity requirements. For firms supervised by the Securities and Futures Commission (SFC), cybersecurity is not limited to protecting networks and data. Firms must also identify, manage and address technology risks that could affect clients, trading systems and business operations. This raises an important question: Does the […]

September 23, 2026
Atlassian Security Compliance: Requirements, Risks, and Best Practices
Jira and Confluence are no longer used only for basic project tracking or internal notes. Many businesses now rely on them for day-to-day operations, sensitive information, approvals, development work, and customer-related processes. Marketplace apps can add even more access to that environment. Because of this, Atlassian security compliance cannot be judged by Atlassian’s certifications alone. […]

September 22, 2026
How to Pass the Property Finder Developer Network (PFDN) Security Audit: A VAPT Blueprint for CRMs
The Property Finder Developer Network (PFDN) is a dedicated integration platform that connects real estate CRMs, proptech tools, and digital marketing software with Property Finder, one of the region’s leading property portals. It allows these platforms to exchange listings, broker information, leads, and other data through APIs. However, connecting to PFDN involves more than configuring […]
"Don't compromise between depth and speed. Own both. Connect with Swagat, Your trusted penetration testing advisor."

Swagat Kumar Dash
Head Of Business Development
