Blog

"Why test what we know is bad?"

"Why test what we know is bad?"

Posted on 2023-08-01by nathanin Industry


“Why bother getting a penetration test when we already know they will compromise us? ”

Continue reading
How many vulnerabilities does it take to hack a system?

How many vulnerabilities does it take to hack a system?

Posted on 2023-05-23by mattin Industry


If you see penetration testing reports for two different systems, one with 10 vulnerabilities and one with 20, which system has worse security?

Continue reading
CRTO vs. CRTE

CRTO vs. CRTE

Posted on 2023-05-05by nathanin Certifications


Late last year I was looking into “What happens next?” after OSCP and PNPT certifications, and it is common to hear from those in the industry that the next step for network penetration testing is to complete Certified Red Team Operator (CRTO) or Certified Red Team Expert (CRTE).

Continue reading
Initial impressions of the NIST Cybersecurity Framework version 2.0 draft

Initial impressions of the NIST Cybersecurity Framework version 2.0 draft

Posted on 2023-04-27by mattin Compliance


The latest draft of NIST Cybersecurity Framework (NIST CSF) has just been released! This is the first preview of the new 2.0 version of the framework that updates the hugely successful framework. The draft follows from a Concept Paper released at the beginning of the year. The final version is due to be released in 2024.

Continue reading
Penetration test, red team, vulnerability assessment... what???

Penetration test, red team, vulnerability assessment... what???

Posted on 2023-04-20by alexeiin Industry


You’re probably here because, like many others, you’ve gone out looking for offensive cyber-security services only to be give a bunch of buzz words that don’t really describe what they are or what they mean for you. Fear not; in this post I hope to demystify the most common ones, in simple terms and explain the benefits and shortcomings of each. I’ll also give a few examples of when each one would be useful.

Continue reading
Hacker Origin Stories: Yianna Paris

Hacker Origin Stories: Yianna Paris

Posted on 2023-04-14by Volkisin Feature


Welcome back to Hacker Origin Stories! We’re excited to continue sharing personal experiences from professionals in the hacking and cybersecurity industry. Our goal is to highlight the diverse paths individuals take to get where they are today and motivate the next generation of hackers to join in.

Continue reading
Our first growing pains

Our first growing pains

Posted on 2023-03-21by mattin Volkis News


Earlier this year Alexei and I were staring at the screen, looking at a report that was less than flattering for the company. The reading of the report was simple: we were doing less billable work than we expected.

Continue reading
Questions for a certification addict

Questions for a certification addict

Posted on 2023-03-01by nathanin Industry


Recently I have encountered a few people in various channels ask about how to approach certifications. Common questions like:

Continue reading
Hacker Origin Stories: Alexei Doudkine

Hacker Origin Stories: Alexei Doudkine

Posted on 2023-02-23by alexeiin Feature


Welcome to the first episode of Hacker Origin Stories. We have started this series to create a space where professionals can share their own personal experiences about their journey into hacking and cybersecurity. The aim is to showcase the many different paths into the industry and inspire the next generation of hackers to carry the torch.

Continue reading
Report Ranger roadmap

Report Ranger roadmap

Posted on 2023-02-23by mattin Volkis News


When we started Volkis, Alexei and I had a big ranty discussion on how reports should be done. The next day I hacked together a PoC. We looked at it and went “damn, we already like this better than what’s already out there!”

Continue reading