Blog

The value that Volkis brings as a company for penetration testing

The value that Volkis brings as a company for penetration testing

Posted on 2022-04-13by mattin Volkis News


When building a cyber security company there’s a question we have to keep front of mind at all times. What value do we bring as a company? It’s one thing to just say “yes of course we provide value as a company” but for me I’ve tried to make an actual list. I’ve put up the results of this up in a new handbook page.

Continue reading
How to Get the Most Out of Your Penetration Test 🤷

How to Get the Most Out of Your Penetration Test 🤷

Posted on 2022-04-05by Volkisin Business Security


Our experience performing thousands of penetration tests has given us an in-depth understanding of common issues when engaging a consultant to complete a penetration test. We like to see our customers get the most possible value out of their penetration tests. Much of the responsibility lies with the penetration test provider, but cooperation and communication from our customers is also a key factor in the value that is provided.

Continue reading
Basic security for humans in 4 Fridays

Basic security for humans in 4 Fridays

Posted on 2022-03-09by alexeiin Tools of the Trade


This post is going to be a little different. Instead of talking about the industry or business security, I’m going to share my guide on how to set up your own basic personal security. It is intended to be followed by non-technical people in 4 Fridays. My goal is to get as many people on this basic programme as I can, so I do ask you to share it with your friends and family. And, if you are a bit more tech-savvy, please help them along the way. 🙂

Continue reading
How to Share Social Media Credentials Securely

How to Share Social Media Credentials Securely

Posted on 2022-03-01by jessicain Tools of the trade


Social media has become the platform that companies all over the world use to communicate with their customers, clients, critics, and investors. An attacker who gains access to an organisation’s social media accounts is able to send any message that they wish, posing as the organisation. Sending the wrong message on social media can cause a backlash, bad publicity, and in rare cases even be illegal as Elon Musk found out in 2018 when he was sued by the SEC over one of his tweets.

Continue reading
What questions should a board ask about cyber security reports?

What questions should a board ask about cyber security reports?

Posted on 2022-02-07by mattin Business Security


Cyber security is now one of the top-of-mind topics for boards in Australia. Security assessment reports including technical reports such as from penetration testing are being placed in board papers. Although cyber security skills are becoming more commonly represented in boards, it is still the case that boards are called to interpret and act on the results of cyber security assessments without really understanding the practicalities that can underly it all.

Continue reading
State of Volkis - what do we do well and what should we improve?

State of Volkis - what do we do well and what should we improve?

Posted on 2022-02-04by mattin Volkis News


A few weeks ago we had an internal strategy session with everyone at Volkis. In this session we only discussed four questions:

Continue reading
PEN-300 Course Review

PEN-300 Course Review

Posted on 2021-05-21by alexeiin Certifications


It’s done! I just completed my OSEP exam and submitted the report. In true Offensive Security style, the course was challenging but very doable given enough motivation. But was it worth it? Did PEN-300, one of Offensive Security’s new replacement courses for the outdated and retired Cracking the Perimeter course live up to the expectations? If you’re thinking about taking the course, read on as I go into the good parts and bad parts of the course.

Continue reading
Cease and desist from calling our products insecure

Cease and desist from calling our products insecure

Posted on 2021-03-03by mattin Business Security


Earlier today Xerox reportedly threatened the Airbus Security Lab researcher Raphaël Rigo with legal action to prevent him from presenting at the Infiltrate security conference. Although obviously we haven’t seen the presentation, the summary said that he was going to talk about vulnerabilities in Xerox printers and give tips on how to secure them.

Continue reading
Our competitor has worse security, so we're doing well aren't we?

Our competitor has worse security, so we're doing well aren't we?

Posted on 2021-02-23by mattin Business Security


In business you have a day-to-day competition that feels very “survival of the fittest”. Your competitors come up constantly in meetings. You note their movements and announcements and try and match their moves. Companies don’t exist in a bubble, they exist in a constantly moving industry and competitive landscape.

Continue reading