Qualysec

Blog

Latest Articles

Page 3 of 158 · 1418 posts

WASA Audit Explained Complete Checklist, Sample Report, and Tools

September 18, 2026

WASA Audit Explained: Complete Checklist, Sample Report, and Tools

What Is a WASA Audit? A WASA audit, short for Web Application Security Assessment or Audit, is a structured examination of how a web application behaves under attack and is delivered as evidence that a regulator, auditor, or enterprise buyer will accept. It combines automated scanning with manual testing of authentication, authorisation, session handling, APIs […]

NHS Data Security and Protection Toolkit How to Achieve “Standards Met”

September 17, 2026

NHS Data Security and Protection Toolkit: How to Achieve “Standards Met”

The NHS Data Security and Protection Toolkit (DSPT) is not simply a compliance exercise. For organisations working with NHS systems, services, or patient information, it shows that the right data security arrangements are in place and maintained. The NHS Data Security and Protection Toolkit is an online assessment that measures how well an organisation meets […]

What is CBUAE Cybersecurity Compliance? Penetration Testing Requirements for UAE Banks

September 17, 2026

What is CBUAE Cybersecurity Compliance? Penetration Testing Requirements for UAE Banks

Your bank has a penetration testing report. We have completed the scope, documented the findings, and sent the report to the security or compliance team. Then a CBUAE examination raises a question you were not expecting. Does the testing actually cover what the regulator expects? That is where a security team can run into trouble. […]

Smart Contract Security Audit Explained: Checklist, Tools, and Report Standards

September 16, 2026

Smart Contract Security Audit Explained: Checklist, Tools, and Report Standards

A smart contract can pass its unit tests, compile successfully, and still contain a flaw that an attacker can exploit. Tests check the scenarios and behaviours developers have defined, while automated scanners can catch known vulnerability patterns. Neither will necessarily catch a problem in the protocol’s business logic. A contract could give the wrong user […]

Passing the NHS DTAC A Cybersecurity Guide for Health-Tech Vendors

September 16, 2026

Passing the NHS DTAC: A Cybersecurity Guide for Health-Tech Vendors

Your health-tech product may already be live, security-tested, and being used successfully. Then you start an NHS procurement process and discover that having a secure product is only part of the conversation. You need to show how that security is managed, what evidence supports your answers, and whether the product meets the NHS baseline for […]

Vulnerability Scanning & DORA Compliance What You Need to Know

September 15, 2026

Vulnerability Scanning & DORA Compliance: What You Need to Know

DORA now covers more than 22,000 financial entities and an estimated 15,000 ICT third-party providers across the EU, according to the European Banking Authority, and vulnerability scanning sits right at the foundation of how most of them prove they’re managing ICT risk properly. It’s the recurring, lower-cost testing layer that DORA’s Pillar 1 and Pillar […]

CREST Accredited Penetration Testing for HKMA iCAST (Hong Kong)

September 15, 2026

CREST Accredited Penetration Testing for HKMA iCAST (Hong Kong)

Identification of vulnerabilities is just one step in assessing the bank’s cyber resilience. Financial organizations must know if attackers can take advantage of the vulnerabilities identified in order to gain access to important banking systems. This is where penetration testing companies with CREST-accreditation become relevant, particularly for institutions preparing for HKMA’s intelligence-led testing requirements.  The […]

Understanding the New CREST AI Security Testing Accreditation

September 15, 2026

Understanding the New CREST AI Security Testing Accreditation

The integration of AI into cybersecurity activities and enterprises is growing quickly. This is why CREST has officially launched AI Security Testing Accreditation. Through this accreditation, CREST evaluates a provider’s technical expertise, testing methodologies, governance, and controls for conducting AI security assessments.  Currently, 69% of penetration testing providers use automated machine learning applications, and 76% […]

NIST Cybersecurity Framework 2.0 Everything CISOs and Tech Leads Need to Know

September 11, 2026

NIST Cybersecurity Framework 2.0: Everything CISOs and Tech Leads Need to Know

Two years after publication, the NIST Cybersecurity Framework 2.0 has become the document most boards ask about by name. It is the most downloaded NIST technical publication, with over 3 million views and downloads, and it is no longer a US critical infrastructure document. It is a global reference used by banks in São Paulo, […]

"Don't compromise between depth and speed. Own both. Connect with Swagat, Your trusted penetration testing advisor."

Swagat Kumar Dash

Swagat Kumar Dash

Head Of Business Development