Blog

Research and field notes on AI security, penetration testing and offensive security from the Ironbark Cyber team.

External Attack Surface Management: A Practical Guide

External Attack Surface Management: A Practical Guide

External attack surface management explained: why organisations lose track of what they expose online, and how continuous discovery closes the gap.

BOLA and IDOR Explained: Broken Object Level Authorisation

BOLA and IDOR Explained: Broken Object Level Authorisation

BOLA and IDOR explained: how attackers manipulate object IDs to access other users' data, why scanners miss it, and how to test for it properly.

OWASP Top 10 Explained: What Each Category Means in Practice

OWASP Top 10 Explained: What Each Category Means in Practice

The OWASP Top 10 explained in plain terms: what each category actually means for your dev team, how the flaws happen in practice, and how to fix them.

How to Run a Phishing Simulation That Actually Teaches

How to Run a Phishing Simulation That Actually Teaches

Learn how to run a phishing simulation that builds real resilience, goals, targeting, ethical lure design, metrics that matter, and how to debrief well.

Subdomain Takeover Explained: Dangling DNS and How to Fix It

Subdomain Takeover Explained: Dangling DNS and How to Fix It

Subdomain takeover happens when dangling DNS records point at unclaimed services. How attackers exploit them, the impact, and how to detect and prevent it.

What Is OSINT? How Attackers Use Open-Source Intelligence

What Is OSINT? How Attackers Use Open-Source Intelligence

OSINT is intelligence gathered from public sources. Learn what is OSINT in practice, how attackers use it against your organisation, and how to defend.

How to Prepare for a Penetration Test: A Practical Checklist

How to Prepare for a Penetration Test: A Practical Checklist

Prepare for a penetration test with our practical checklist: scope, environments, test accounts, rules of engagement and comms, so testing days aren't wasted.

How Often Should You Do a Penetration Test?

How Often Should You Do a Penetration Test?

Most organisations need a penetration test at least annually, plus after major changes. Here's how to set the right cadence for your risk and compliance.

Penetration Test vs Vulnerability Scan: What's the Difference?

Penetration Test vs Vulnerability Scan: What's the Difference?

A vulnerability scan finds known issues automatically; a penetration test proves what an attacker can do. Here's when each fits and how to tell them apart.

What Is Penetration Testing? A Plain-English Guide

What Is Penetration Testing? A Plain-English Guide

Penetration testing is a controlled, authorised attack on your systems to find real vulnerabilities before criminals do. Here's how it works and what it costs.

Put this into practice

A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.