Pentestly Labs

    Attack paths, testing notes and defensive guidance

    Technical research and practical buyer guides written around the work our offensive security team performs: scoping, exploitation, evidence, remediation and retesting.

    Featured Article
    Supabase Security: Lessons from Real Pentests
    20 min read

    Supabase Security: Lessons from Real Pentests

    Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.

    Database Security
    Penetration Testing
    Supabase Integration
    Data Compliance
    Security Best Practices
    Supabase Security

    Latest Articles

    Discover 16 articles on cybersecurity and penetration testing.

    Internal Penetration Testing: Scope and Methods
    25 min read

    Internal Penetration Testing: Scope and Methods

    Plan an internal penetration test around identity, segmentation and critical assets, with practical guidance on scope, access, evidence, reporting and retesting.

    Internal Security
    Penetration Testing
    Red Teaming
    +3 more
    How Often Should Penetration Testing Be Done?
    9 min read

    How Often Should Penetration Testing Be Done?

    Learn when annual, quarterly and change-triggered penetration testing make sense, with a practical risk-based schedule for UK organisations.

    Penetration Testing
    Testing Frequency
    Compliance
    +2 more
    Penetration Testing for MSPs: Delivery Guide
    10 min read

    Penetration Testing for MSPs: Delivery Guide

    A practical guide for MSPs adding penetration testing to their services, covering permissions, scoping, supplier selection, client separation, reporting and retesting.

    Penetration Testing
    Managed Service Providers
    PTaaS
    +2 more
    Penetration Testing vs PTaaS: What Actually Changes?
    9 min read

    Penetration Testing vs PTaaS: What Actually Changes?

    Understand the real difference between a one-off penetration test and PTaaS, including delivery workflow, tester involvement, reporting, retesting and cost.

    Penetration Testing
    PTaaS
    Security Testing
    +2 more
    Penetration Testing for Startups: A Founder's Guide
    8 min read

    Penetration Testing for Startups: A Founder's Guide

    A founder's guide to scoping penetration testing around launches, customer assurance and limited budgets, including the responsible use of AI.

    Penetration Testing
    Cybersecurity
    Startups
    +6 more
    ISO 27001 Pentesting: Is It Required in the UK?
    9 min read

    ISO 27001 Pentesting: Is It Required in the UK?

    Learn where penetration testing fits ISO 27001:2022, when a risk-based test is appropriate, what evidence auditors may review and how to scope it.

    ISO 27001
    Penetration Testing
    Compliance
    +2 more

    Stay Updated with Security Insights

    Get the latest cybersecurity news, threat intelligence, and security best practices delivered to your inbox.