エピソード

  • Vulnerability Deep Dive: Access Control Issues
    2024/12/02

    In the second of the Let's Talk Security Testing vulnerability deep dive episodes, Ben and Tom explore access control issues. They explore:

    • What are access control issues & practical examples
    • How to identify access control issues
    • How to prevent, find and fix them
    続きを読む 一部表示
    17 分
  • Depth vs Coverage in Security Testing
    2024/11/18

    Has the cyber security industry been ... lying to us? Do scanners provide the coverage whilst penetration tests provide the depth? Ben and Tom peel back the lid on this narrative to see if this is really the case...

    続きを読む 一部表示
    15 分
  • Vulnerability Deep Dive: Business Logic Flaws
    2024/11/04

    In this first-of-its-type episode of Let's Talk Security Testing, Ben and Tom exclusively dive into the vulnerability, business logic flaws.

    They discuss:

    • How business logic flaws are created
    • Where they're typically found
    • Why they're unique
    • Ways to optimise testing processes to find them more easily

    続きを読む 一部表示
    24 分
  • How to Build an Internal Security Testing Team
    2024/10/21

    Tom and Ben discuss:

    • Determining the need for an internal pentesting team
    • Setting up the team
    • Key processes that lead to success

    続きを読む 一部表示
    18 分
  • Where Do Vulnerabilities Come From?
    2024/10/07

    Ben and Tom discuss:

    • The 3 primary sources of vulnerability creation
    • A comparison of defensive cyber security approaches
    • Challenges of route cause analysis
    続きを読む 一部表示
    25 分
  • Why Context Matters In Security Testing
    2024/09/23

    Join Ben and Tom in discussing:

    • What do we mean by context in security testing?
    • The reality of context in security testing
    • Barriers to achieving context in security testing and how to overcome them
    続きを読む 一部表示
    17 分
  • How to Run an Enterprise Security Testing Programme
    2024/09/09

    Ben and Tom share strategy options, how this translates to operations and resourcing, and what output to expect from an enterprise testing programme.

    続きを読む 一部表示
    26 分
  • A Cyber Security Engineer and a Vendor Meet in A Podcast Studio...
    2024/08/26

    In episode 6 of Let's Talk Security Testing, we welcome our first guest to the studio, Senior Security Engineer, Christine Smoley.

    Tom and Christine have an honest conversation on the cyber security vendor landscape, how vendors can make things easier in the buying process, and shared experiences in dealing with challenges of coordinating a security testing team.

    続きを読む 一部表示
    27 分