>> All posts>> Topic

Best practices

15 articles.

July 10, 2026Risk quantificationBest practices

When CVSS (and EPSS / KEV) still belong in the room

Breach risk isn't a CVSS average — but CVE context still earns a seat once a path is real. Here's how to use CVSS, EPSS, and KEV without letting them run the whole program.

July 2, 2026ComplianceBest practices

So HIPAA is on your plate — here's where to start

A healthcare customer or product decision just made HIPAA your problem. Clarify whether you're a covered entity or business associate, what PHI you actually touch, and how to spend the next 30 days without guessing regulatory details.

June 29, 2026ComplianceBest practices

So you're being asked for ISO 27001 — here's where to start

An international customer asked for ISO 27001. Before you buy a binder or book a stage audit, clarify whether they want certification, a statement of applicability story, or 'aligned' — then follow this 30-day start plan.

June 9, 2026Service providersBest practices

Talk to clients about breach risk without scaring them

A BreachRisk Score in a QBR should build trust, not theater. Here's how service providers can present outside-in findings — calm, ranked, and actionable — so clients lean in instead of tuning out.

May 15, 2026ComplianceBest practices

So you have to do PCI DSS — here's where to start

Card data or a payment flow just made PCI DSS your problem. Before you memorize requirements, clarify scope, who is assessing you, and what 'done' means for your business — then use this 30-day starter map.

May 5, 2026Risk quantificationBest practices

How to brief the board on breach risk without fear-mongering

Scare decks burn credibility. A calm BreachRisk briefing — score, trend, top verified paths, progress, one ask — builds it. Here's a pattern you can reuse every quarter.

February 19, 2026Risk quantificationBest practices

Likelihood × impact — the risk language boards already understand

Boards don't need a CVE tutorial. They need breach risk in the same shape as every other enterprise risk: how likely, how bad, what we're doing. Here's how to use that frame without drowning them in formula.

December 13, 2025Risk quantificationBest practices

Identified vs verified vs safe — why the middle word matters

Scanners identify maybes. Ratings estimate from signals. Proof starts when a finding is verified the way an attacker would care about it. 'Safe' is a state you earn — not a slide.

December 4, 2025Service providersBest practices

Tenants, not tickets: running many customers in one console

You can't hire three pen testers for every book of business. Multi-tenant delivery lets service providers run continuous assessments across clients — separate data, shared ops — without building an exploit shop.

November 19, 2025Service providersBest practices

Pack continuous assessment into an MSP offer

Monitoring and tickets keep the lights on. A continuous, attacker-grade risk assessment — delivered under your brand — is a reason clients stay, expand, and come to you before they go shopping for a pen-test firm.

October 13, 2025ComplianceBest practices

So you have to align to NIST 800-53 — here's where to start

A government-adjacent customer or RFP just said NIST SP 800-53. Before you drown in control IDs, decode whether this is a contractual baseline, a gap assessment ask, or 'be FedRAMP-ish' — then use this 30-day orientation.

September 30, 2025Risk quantificationBest practices

What a BreachRisk Score is (and isn't)

One number leaders can trend — built from assessed surface and verified exposure. Here's what the BreachRisk Score measures, what it deliberately isn't, and how to talk about it without overselling.

September 12, 2025Service providersBest practices

Turn assessments into recurring revenue — without becoming a pen-test firm

Annual point-in-time testing is a project. Continuous assessment is a retainer. How service providers position renewal, quarterly reviews, and expansion — while the platform does the attacker-grade work.

August 28, 2025ComplianceBest practices

So you have to get SOC 2 — here's where to start

Sales just told you enterprise buyers need SOC 2. Before you hire anyone or buy a binder of policies, clarify what was actually asked for — and use this as your first-30-days map.

August 5, 2025Risk quantificationBest practices

Critical CVE ≠ your breach risk

A CVSS 9.8 on something attackers can't reach is a different problem than a moderate finding on a live internet path. Severity labels aren't organizational breach risk — stop letting them set the whole queue.