Cyber security field guides
Cyber security resources for penetration testing.
Practical resources for teams choosing a penetration test, preparing for SOC 2, or fixing a real finding. Each guide separates standards from judgment and shows what useful evidence looks like.
Reviewed September 3, 2026
Start with your question
An auditor or customer asked for a pentest
Work out whether the request applies to SOC 2, what evidence is useful, and which systems belong in scope.
Review SOC 2 requirementsYou need to choose black, gray, or white box
Compare access levels, coverage, realism, and effort before you write the rules of engagement.
Compare testing methodsYou need examples of reportable findings
See safe proof-of-concept examples, realistic severity ranges, evidence, fixes, and retest criteria.
Open the vulnerability guideQuick reference
CVSS severity is a starting point, not the decision.
CVSS v4.0 maps technical scores to five ratings. Prioritization should also account for the exposed asset, data sensitivity, reachable users, exploit prerequisites, and controls already in place.
Learn how to rate a findingThe labels and score bands follow the FIRST CVSS v4.0 qualitative rating scale. A score does not replace environment-specific risk analysis.
The library
One search intent per guide.
Use the SOC 2 page for audit planning, the method comparison for scope design, and the vulnerability guide when triaging findings with engineering.
SOC 2 Penetration Testing Requirements
When a pentest supports SOC 2, how Type I and Type II evidence differs, and what to put in scope.
Black Box vs Gray Box vs White Box Penetration Testing
Compare access, realism, depth, cost, and the situations where each penetration testing method fits.
Common Web Application Vulnerabilities
Safe exploit examples, likely impact, severity ranges, evidence to capture, and practical fixes.
From research to scope
Get your penetration test report in 24 hours.
Share the audit driver, attack surface, and access model. We confirm the scope, authorization, access, and delivery window before testing begins.