Blog

Welcome to our blog. We are regularly sharing our cyber security insights and company updates.

Content Type
Article
Case Studies
Category
AI Security
AppSec
Cloud & Container Security
Company News
Compliance & Regulations
Mobile Security
Penetration Testing
Skills
Uncategorized
Web & API Security

PCI DSS Penetration Testing Requirements: Scope, Frequency, and Reporting

PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD), as well

Read more

Active Directory Attack Paths: From Domain User to Domain Admin

When teams prepare for an Active Directory security review, patch levels and domain controller hardening usually receive most of the

Read more

Iterasec Is Now a CREST-Accredited Penetration Testing Provider

Choosing a pentest provider requires more than comparing service lists and certifications. Almost any company can claim to follow best

Read more

Penetration Testing Checklist: How to Prepare for a Pen Test

For organizations working under PCI DSS, SOC 2, ISO 27001, DORA, NIS 2, HIPAA, or similar frameworks, penetration testing is

Read more

Penetration Testing for Compliance: Regulatory Standards Guide

For many years, cybersecurity compliance was treated primarily as a matter of documentation. Organizations were expected to formalize processes, define

Read more

Kubernetes Security Assessment: Scope, Access Requirements, and Risk Validation

When preparing for a whitebox Kubernetes security assessment, platform engineers, cloud architects, and security teams often pay close attention to

Read more

DORA Is Now in Force: Testing Requirements for Financial Entities

⚠ Enforcement Note The Digital Operational Resilience Act (DORA) — EU Regulation 2022/2554 — has been applicable since 17 January

Read more

AI-assisted Software Development Security: Risks, Vulnerabilities, and Best Practices

At Iterasec, we are watching a fundamental shift in how software is built. In 2026, manual syntax is no longer

Read more

Navigating the European Cyber Resilience Act (CRA): Essential Compliance Guide for Tech Companies

Disclaimer: Article 14 reporting obligations take effect 11 September 2026. Full compliance is mandatory by 11 December 2027. This guide

Read more