HelixML

Cyber security field guides

Cyber security resources for penetration testing.

Practical resources for teams choosing a penetration test, preparing for SOC 2, or fixing a real finding. Each guide separates standards from judgment and shows what useful evidence looks like.

Reviewed September 3, 2026

Start with your question

Quick reference

CVSS severity is a starting point, not the decision.

CVSS v4.0 maps technical scores to five ratings. Prioritization should also account for the exposed asset, data sensitivity, reachable users, exploit prerequisites, and controls already in place.

Learn how to rate a finding
None0.0
Low0.1–3.9
Medium4.0–6.9
High7.0–8.9
Critical9.0–10.0

The labels and score bands follow the FIRST CVSS v4.0 qualitative rating scale. A score does not replace environment-specific risk analysis.

The library

One search intent per guide.

Use the SOC 2 page for audit planning, the method comparison for scope design, and the vulnerability guide when triaging findings with engineering.

From research to scope

Get your penetration test report in 24 hours.

Share the audit driver, attack surface, and access model. We confirm the scope, authorization, access, and delivery window before testing begins.

Scope a penetration test →