
How to Scope a Penetration Test Properly
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Practical briefings on cybersecurity, regulation, cloud and technology decisions — written by NAZZTEC consultants from the engagements we deliver.

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

There is no best cloud — only the best fit for a specific workload. A neutral look at where each hyperscaler is strongest and the criteria that should decide.

The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.

All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.

The eight design areas every landing zone must settle before the first production workload arrives — and the mistakes that are expensive to undo later.

Enterprise GRC suites and lightweight compliance automation tools solve different problems. How to work out which one you need — and avoid paying for the other.
Every briefing reflects work we deliver for clients. Tell us the challenge you are facing and a senior consultant will respond within one business day.
We respond to every enquiry within one business day.