<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pentestly Labs</title>
    <link>https://www.pentestly.io/blog</link>
    <description>Penetration testing research, attack techniques and practical remediation guidance from Pentestly.</description>
    <language>en-gb</language>
    <lastBuildDate>Wed, 19 Aug 2026 08:29:38 GMT</lastBuildDate>
    <ttl>60</ttl>
    <atom:link href="https://www.pentestly.io/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Internal Penetration Testing: Scope and Methods</title>
      <link>https://www.pentestly.io/blog/internal-penetration-testing-guide</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/internal-penetration-testing-guide</guid>
      <pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/internal-pentest-guide.png" alt="Internal Penetration Testing: Scope and Methods" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Plan an internal penetration test around identity, segmentation and critical assets, with practical guidance on scope, access, evidence, reporting and retesting.]]></description>
      <enclosure url="https://www.pentestly.io/internal-pentest-guide.png" type="image/png" length="0" />
      <category>Internal Security</category>
      <category>Penetration Testing</category>
      <category>Red Teaming</category>
      <category>Vulnerability Management</category>
      <category>Network Security</category>
      <category>Security Best Practices</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Supabase Security: Lessons from Real Pentests</title>
      <link>https://www.pentestly.io/blog/supabase-security-best-practices-2025-guide</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/supabase-security-best-practices-2025-guide</guid>
      <pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/supabasesecurity2.png" alt="Supabase Security: Lessons from Real Pentests" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.]]></description>
      <enclosure url="https://www.pentestly.io/supabasesecurity2.png" type="image/png" length="0" />
      <category>Database Security</category>
      <category>Penetration Testing</category>
      <category>Supabase Integration</category>
      <category>Data Compliance</category>
      <category>Security Best Practices</category>
      <category>Supabase Security</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>How Often Should Penetration Testing Be Done?</title>
      <link>https://www.pentestly.io/blog/how-often-should-penetration-testing-be-done</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/how-often-should-penetration-testing-be-done</guid>
      <pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/howoften.png" alt="How Often Should Penetration Testing Be Done?" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Learn when annual, quarterly and change-triggered penetration testing make sense, with a practical risk-based schedule for UK organisations.]]></description>
      <enclosure url="https://www.pentestly.io/howoften.png" type="image/png" length="0" />
      <category>Penetration Testing</category>
      <category>Testing Frequency</category>
      <category>Compliance</category>
      <category>Risk Management</category>
      <category>PTaaS</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Penetration Testing for MSPs: Delivery Guide</title>
      <link>https://www.pentestly.io/blog/penetration-testing-for-msps-how-to-offer-security-as-a-service</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/penetration-testing-for-msps-how-to-offer-security-as-a-service</guid>
      <pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/pentestingformsps.png" alt="Penetration Testing for MSPs: Delivery Guide" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>A practical guide for MSPs adding penetration testing to their services, covering permissions, scoping, supplier selection, client separation, reporting and retesting.]]></description>
      <enclosure url="https://www.pentestly.io/pentestingformsps.png" type="image/png" length="0" />
      <category>Penetration Testing</category>
      <category>Managed Service Providers</category>
      <category>PTaaS</category>
      <category>Scoping</category>
      <category>Security Services</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Penetration Testing vs PTaaS: What Actually Changes?</title>
      <link>https://www.pentestly.io/blog/penetration-testing-vs-penetration-testing-as-a-service-ptaas</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/penetration-testing-vs-penetration-testing-as-a-service-ptaas</guid>
      <pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/pentestvsptaas.png" alt="Penetration Testing vs PTaaS: What Actually Changes?" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Understand the real difference between a one-off penetration test and PTaaS, including delivery workflow, tester involvement, reporting, retesting and cost.]]></description>
      <enclosure url="https://www.pentestly.io/pentestvsptaas.png" type="image/png" length="0" />
      <category>Penetration Testing</category>
      <category>PTaaS</category>
      <category>Security Testing</category>
      <category>Retesting</category>
      <category>DevSecOps</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Penetration Testing for Startups: A Founder&apos;s Guide</title>
      <link>https://www.pentestly.io/blog/penetration-testing-for-startups-a-guide-for-founders</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/penetration-testing-for-startups-a-guide-for-founders</guid>
      <pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/pentestforstartups.png" alt="Penetration Testing for Startups: A Founder&apos;s Guide" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>A founder's guide to scoping penetration testing around launches, customer assurance and limited budgets, including the responsible use of AI.]]></description>
      <enclosure url="https://www.pentestly.io/pentestforstartups.png" type="image/png" length="0" />
      <category>Penetration Testing</category>
      <category>Cybersecurity</category>
      <category>Startups</category>
      <category>AI-assisted Testing</category>
      <category>Risk Management</category>
      <category>Compliance</category>
      <category>Security Assessment</category>
      <category>Vulnerability Detection</category>
      <category>Security Strategies</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>ISO 27001 Pentesting: Is It Required in the UK?</title>
      <link>https://www.pentestly.io/blog/iso27001-penetration-testing-do-you-really-need-it-for-compliance-in-the-uk</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/iso27001-penetration-testing-do-you-really-need-it-for-compliance-in-the-uk</guid>
      <pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/iso27001pentest.png" alt="ISO 27001 Pentesting: Is It Required in the UK?" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Learn where penetration testing fits ISO 27001:2022, when a risk-based test is appropriate, what evidence auditors may review and how to scope it.]]></description>
      <enclosure url="https://www.pentestly.io/iso27001pentest.png" type="image/png" length="0" />
      <category>ISO 27001</category>
      <category>Penetration Testing</category>
      <category>Compliance</category>
      <category>Risk Management</category>
      <category>UK Cybersecurity</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Pentesting and Cyber Insurance: A UK Guide</title>
      <link>https://www.pentestly.io/blog/the-role-of-penetration-testing-in-cyber-insurance-underwriting</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/the-role-of-penetration-testing-in-cyber-insurance-underwriting</guid>
      <pubDate>Sat, 30 Aug 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/pentestforinsurance.png" alt="Pentesting and Cyber Insurance: A UK Guide" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Understand how penetration-test evidence may support cyber-insurance applications and renewals without assuming it guarantees cover, pricing or a successful claim.]]></description>
      <enclosure url="https://www.pentestly.io/pentestforinsurance.png" type="image/png" length="0" />
      <category>Cyber Insurance</category>
      <category>Penetration Testing</category>
      <category>Risk Management</category>
      <category>UK Cybersecurity</category>
      <category>Underwriting</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>5 UK Penetration Testing Companies to Compare in 2026</title>
      <link>https://www.pentestly.io/blog/top-5-penetration-testing-companies-in-the-uk</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/top-5-penetration-testing-companies-in-the-uk</guid>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/top5pentestcompaniesuk.png" alt="5 UK Penetration Testing Companies to Compare in 2026" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Compare five penetration testing providers serving UK organisations, their published delivery models, and the questions that reveal which one fits your scope.]]></description>
      <enclosure url="https://www.pentestly.io/top5pentestcompaniesuk.png" type="image/png" length="0" />
      <category>Penetration Testing</category>
      <category>UK Cybersecurity</category>
      <category>Vendor Selection</category>
      <category>PTaaS</category>
      <category>Red Teaming</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>ISO 27001 vs SOC 2: Do You Need One or Both?</title>
      <link>https://www.pentestly.io/blog/iso-27001-vs-soc-2-do-you-need-both-security-frameworks</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/iso-27001-vs-soc-2-do-you-need-both-security-frameworks</guid>
      <pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/isovssoc2.png" alt="ISO 27001 vs SOC 2: Do You Need One or Both?" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Compare ISO 27001 certification and SOC 2 reports, including scope, audit outcomes, market expectations, control mapping and where penetration testing fits.]]></description>
      <enclosure url="https://www.pentestly.io/isovssoc2.png" type="image/png" length="0" />
      <category>ISO 27001</category>
      <category>SOC 2</category>
      <category>Compliance</category>
      <category>Information Security</category>
      <category>Penetration Testing</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Cyber Essentials 2026: Scope and Requirements</title>
      <link>https://www.pentestly.io/blog/the-ultimate-guide-to-cyber-essentials</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/the-ultimate-guide-to-cyber-essentials</guid>
      <pubDate>Wed, 06 Aug 2025 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/cyberessentials2025.png" alt="Cyber Essentials 2026: Scope and Requirements" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>A current guide to Cyber Essentials and Cyber Essentials Plus, including the five controls, version 3.3 changes, scope decisions and where pentesting fits.]]></description>
      <enclosure url="https://www.pentestly.io/cyberessentials2025.png" type="image/png" length="0" />
      <category>Cyber Essentials</category>
      <category>Cyber Essentials Plus</category>
      <category>Compliance</category>
      <category>Cloud Security</category>
      <category>Patch Management</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Vulnerability Management: 10 Practical Best Practices</title>
      <link>https://www.pentestly.io/blog/top-vulnerability-management-best-practices-2025</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/top-vulnerability-management-best-practices-2025</guid>
      <pubDate>Wed, 10 Jul 2024 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/vulnerability-management-2025.png" alt="Vulnerability Management: 10 Practical Best Practices" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Build a risk-based vulnerability management programme covering asset context, prioritisation, remediation ownership, automation, verification and useful metrics.]]></description>
      <enclosure url="https://www.pentestly.io/vulnerability-management-2025.png" type="image/png" length="0" />
      <category>Vulnerability Management</category>
      <category>Risk Management</category>
      <category>Security Operations</category>
      <category>Network Security</category>
      <category>Patch Management</category>
      <category>Security Best Practices</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Vulnerability Management Process: A Practical Guide</title>
      <link>https://www.pentestly.io/blog/master-the-vulnerability-management-process</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/master-the-vulnerability-management-process</guid>
      <pubDate>Wed, 22 May 2024 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/vulnerability-management-process.png" alt="Vulnerability Management Process: A Practical Guide" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Build a risk-based vulnerability management process spanning asset discovery, validation, prioritisation, ownership, remediation, verification and useful metrics.]]></description>
      <enclosure url="https://www.pentestly.io/vulnerability-management-process.png" type="image/png" length="0" />
      <category>Vulnerability Management</category>
      <category>Risk Management</category>
      <category>Security Operations</category>
      <category>Patch Management</category>
      <category>Cybersecurity Strategy</category>
      <category>Security Best Practices</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Your Guide to Certified Penetration Testing</title>
      <link>https://www.pentestly.io/blog/your-guide-to-certified-penetration-testing</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/your-guide-to-certified-penetration-testing</guid>
      <pubDate>Sun, 24 Mar 2024 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/certified-pentest-guide.png" alt="Your Guide to Certified Penetration Testing" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Understand penetration testing credentials and organisational accreditations, how to evaluate tester capability, define scope, review evidence and plan retesting.]]></description>
      <enclosure url="https://www.pentestly.io/certified-pentest-guide.png" type="image/png" length="0" />
      <category>Certified Penetration Testing</category>
      <category>Compliance</category>
      <category>Cybersecurity</category>
      <category>Vulnerability Management</category>
      <category>ISO 27001</category>
      <category>SOC 2</category>
      <category>PCI DSS</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Kerberos Attack Techniques and Defensive Controls</title>
      <link>https://www.pentestly.io/blog/how-to-attack-kerberos-101</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/how-to-attack-kerberos-101</guid>
      <pubDate>Sun, 10 Mar 2024 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/kerberos.png" alt="Kerberos Attack Techniques and Defensive Controls" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>A professional guide to Kerberos attack techniques and the defensive controls that stop them, covering tickets, delegation and Active Directory misconfigurations.]]></description>
      <enclosure url="https://www.pentestly.io/kerberos.png" type="image/png" length="0" />
      <category>Kerberos</category>
      <category>Active Directory</category>
      <category>Attack Techniques</category>
      <category>Defensive Security</category>
      <category>Windows Security</category>
      <author>Aidan Preston</author>
    </item>
    <item>
      <title>Your Guide to External Network Penetration Testing</title>
      <link>https://www.pentestly.io/blog/your-guide-to-external-penetration-testing</link>
      <guid isPermaLink="true">https://www.pentestly.io/blog/your-guide-to-external-penetration-testing</guid>
      <pubDate>Wed, 15 Nov 2023 00:00:00 GMT</pubDate>
      <description><![CDATA[<img src="https://www.pentestly.io/external-network-pentest.png" alt="Your Guide to External Network Penetration Testing" style="max-width: 100%; height: auto; margin-bottom: 16px;" /><br/>Plan an external network penetration test around exposed assets, safe exploitation, evidence, reporting and remediation, with practical scoping questions for buyers.]]></description>
      <enclosure url="https://www.pentestly.io/external-network-pentest.png" type="image/png" length="0" />
      <category>External Security</category>
      <category>Network Penetration</category>
      <category>Red Teaming</category>
      <category>Vulnerability Management</category>
      <category>Perimeter Security</category>
      <category>Security Best Practices</category>
      <author>Aidan Preston</author>
    </item>
  </channel>
</rss>
