Cybersecurity knowledge, the working reference
Reference entries for the regulations, methodologies and threat patterns CISOs ask us about most — NIS2, DORA and the EU AI Act, NYDFS Part 500, CMMC and the SEC disclosure rules, the Cyber Resilience Act, CTEM, SBOM, prompt injection and post-quantum cryptography. Definitions answer "what is X"; playbooks answer "what do I do when X happens". Free to read, source-cited and kept current by the team behind Zero Hunt, the on-premise autonomous AI red team.
Definitions
- Definitions6 min
What is an autonomous AI red team (autonomous pentesting)?
An autonomous AI red team, also called autonomous pentesting or AI pentesting, is a set of AI agents that plans and runs offensive security testing against your own networks and infrastructure continuously — discovering assets, validating which weaknesses are really exploitable, and producing evidence — with humans setting scope and approving risky actions.
- Definitions6 min
What is private AI in cybersecurity?
Private AI means the AI models that power a security tool run on infrastructure the organization controls — on-premise or in its own sovereign environment — so prompts, context and results never leave its perimeter and no third-party AI provider sits in the loop.
- Definitions5 min
Human-in-the-loop in autonomous AI security testing
Human-in-the-loop (HITL) is the design principle that an autonomous AI system acts within limits set by people and hands specific decisions — here, any action that could affect a production system — back to a human for approval before it happens.
- Definitions5 min
Black-box vs gray-box penetration testing
Black-box and gray-box describe how much the tester knows at the start. Black-box testing starts from nothing but what the target exposes, like an outside attacker. Gray-box testing starts with partial knowledge — typically user credentials, documentation or the software's source — like an insider or an attacker who has done their homework.
- Definitions6 min
What is TLPT (Threat-Led Penetration Testing)?
TLPT is a regulator-mandated form of penetration testing where the attack scenarios are explicitly driven by threat intelligence about adversaries currently targeting the tested entity, executed by an independent red team under a documented methodology with verifiable evidence chain.
- Definitions9 min
What is a high-risk AI system under the EU AI Act?
Under Regulation (EU) 2024/1689 an AI system is high-risk when it is a safety component of, or is itself, a product covered by the EU harmonization laws in Annex I, or when its intended use falls into one of the Annex III areas — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, justice and democratic processes. High-risk systems must meet Articles 8–15 before they reach the market.
- Definitions7 min
Decreto Legislativo 138/2024 — the Italian NIS2 transposition
Decreto Legislativo 138 of 4 September 2024 is the Italian transposition of NIS2 (Directive (EU) 2022/2555). It identifies essential and important entities, defines technical and organizational measures, attaches personal liability to top management, and operationalizes ACN as the competent national authority and CSIRT Italia as the national CSIRT.
- Definitions7 min
What is CTEM (Continuous Threat Exposure Management)?
CTEM is a five-stage, continuously running program — scoping, discovery, prioritization, validation, mobilization — that keeps an organization's exposure surface measured, ranked by exploitability, and provably reduced over time. It is the framework Gartner codified to replace point-in-time pentesting and standalone vulnerability scanning as the basis of cyber-risk management.
- Definitions8 min
What is the EU Cyber Resilience Act (CRA)?
The EU Cyber Resilience Act — Regulation (EU) 2024/2847 — sets horizontal cybersecurity requirements for any "product with digital elements" placed on the EU market. It mandates secure-by-design and secure-by-default engineering, a vulnerability-handling process, SBOM provision, and incident/vulnerability reporting to ENISA. Full application begins 11 December 2027; reporting obligations under Art. 14 already apply from 11 September 2026.
- Definitions6 min
What is an SBOM (Software Bill of Materials)?
An SBOM is a machine-readable inventory of every software component — direct dependencies, transitive dependencies, embedded libraries, build-time tools — that ships inside a software product, with version, supplier and cryptographic identifier per item. The two dominant formats are CycloneDX (OWASP) and SPDX (Linux Foundation, ISO/IEC 5962).
- Definitions7 min
What is prompt injection (OWASP LLM01)?
Prompt injection is an attack class where adversary-controlled text — supplied either directly to the model or indirectly via a document, web page, email, image, audio file or tool output the model consumes — overrides the system prompt and induces the model to perform actions or disclose information the system designer did not intend. It is ranked LLM01 — the highest-risk item — in the OWASP Top 10 for LLM Applications.
- Definitions8 min
What is Post-Quantum Cryptography (PQC)?
Post-Quantum Cryptography (PQC) is the family of cryptographic algorithms designed to remain secure against an adversary equipped with a large-scale quantum computer. As of August 2024, NIST has standardized three primary PQC algorithms — ML-KEM (FIPS 203, key encapsulation), ML-DSA (FIPS 204, digital signatures), and SLH-DSA (FIPS 205, hash-based signatures) — and explicitly recommends that organizations begin migration now.
- Definitions12 min
Automated Penetration Testing: How It Works, Limits, and How to Evaluate Tools
Automated penetration testing is software that carries out the steps of a penetration test (discovery, exploitation attempts, privilege escalation, lateral movement, reporting) without a person driving each step, and shows which weaknesses an attacker could actually use.
- Definitions9 min
Breach and Attack Simulation (BAS) vs Automated Pentesting vs AEV
Breach and attack simulation checks whether your security controls stop and detect known attack techniques. Automated penetration testing tries to break in and proves which paths an attacker can follow. Adversarial Exposure Validation (AEV) is the Gartner category that now covers both.
- Definitions9 min
Adversarial Exposure Validation (AEV): What Gartner's Category Means
Adversarial Exposure Validation (AEV) is Gartner's name for technologies that deliver consistent, continuous and automated evidence of the feasibility of an attack. As a market category it replaces breach and attack simulation and automated penetration testing.
- Definitions11 min
Vulnerability Assessment vs Penetration Testing (VA/PT): Differences and When You Need Each
A vulnerability assessment finds and rates known weaknesses across many systems. A penetration test tries to exploit weaknesses, chains them, and proves what an attacker can actually reach. VA/PT, or VAPT, is the common name for doing both.
- Definitions10 min
Continuous Automated Red Teaming (CART): What It Is and What It Isn't
Continuous automated red teaming (CART) is software that runs offensive tests against your own environment on a recurring basis and after changes, attempting real attacks and reporting which ones succeed, so exposure is measured continuously rather than once a year.
Playbooks
- Playbooks8 min
NIS2 Article 23 incident timeline — the practical playbook
A step-by-step operational reference for the NIS2 Article 23 incident reporting cadence: what to do in the first hour, by hour 24, by hour 72, and by month 1. Decision gates, evidence checklists, common failure modes.
- Playbooks9 min
Signed-malware supply-chain response — the CISO playbook
Operational playbook for the first 72 hours after a package you trusted — and that carried a valid signature — is reported compromised. Decision gates, credential rotation order, evidence list, regulator notification triggers.
- Playbooks9 min
DORA major ICT incident reporting — the 4h/72h/1-month playbook
Step-by-step operational reference for DORA Art. 19 major ICT incident reporting: what to classify, what to file at hour 4, hour 72, and month 1. Thresholds, templates, INFOSTAT submission, evidence checklist.
- Playbooks9 min
EDR bypass incident response — the playbook when the endpoint stack is the vector
Step-by-step response when an endpoint security platform (Defender, Apex One, CrowdStrike, SentinelOne, etc.) is suspected of being subverted, silenced or used as an attack channel — not when it merely missed a detection.
- Playbooks9 min
Identity provider compromise — the Entra ID / Okta incident-response playbook
Step-by-step response reference for a compromised identity provider: how to contain an Entra ID or Okta takeover, evict attacker persistence, and meet the notification clocks that fire in parallel.
- Playbooks9 min
Edge device compromise — the VPN and firewall appliance incident-response playbook
Step-by-step response when an internet-facing edge appliance — PAN-OS/GlobalProtect firewall, FortiGate SSL-VPN, Citrix NetScaler or Ivanti gateway — is exploited or suspected compromised, not merely unpatched.
- Playbooks9 min
NIS2 sanctions under art. 38 (d.lgs. 138/2024) — the response playbook
An operational reference for Italian essential and important entities facing an ACN NIS2 enforcement procedure: the fines and non-monetary measures at stake, ACN's procedural sequence, and exactly what to file at each gate to close the procedure without an interdictory measure.
- Playbooks9 min
Scattered Spider help-desk defense — the social-engineering playbook
An operational reference for stopping help-desk identity-recovery social engineering — the Scattered Spider vector: how to verify a caller before resetting a password or MFA, and when to refuse.
- Playbooks9 min
The KEV-driven emergency patch window — a CISO decision playbook for BOD 26-04
A decision playbook for when a product you run lands on the CISA KEV catalog: how to assign the right remediation clock under BOD 26-04 and choose between patch, mitigate, or isolate.
- Playbooks9 min
Microsoft 365 business email compromise — the response playbook
How to respond to a modern Microsoft 365 business email compromise: contain the identity, revoke OAuth tokens, eradicate hidden inbox rules and app grants, recall the wire, and notify regulators.
- Playbooks9 min
Your SaaS vendor was breached — the notification duties that are still yours
An operational reference for the moment a supplier, SaaS platform or cloud provider is breached and you have to work out which of your own regulatory filings fire, on what clock, using evidence somebody else controls.
- Playbooks10 min
DORA TLPT engagement playbook — from the authority notification to the attestation
Step-by-step operational reference for running a DORA Art. 26 threat-led penetration test: the binding RTS deadlines, the team roles, the scenario rules, and the evidence each gate consumes.
- Playbooks9 min
Ransomware pay-or-not-pay — the decision playbook for the board and the CISO
A neutral decision framework for the moment an extortion demand lands: who decides, which legal gates must clear before money can move, and what a payment does and does not buy.
- Playbooks9 min
The EU Cyber Resilience Act reporting playbook — 24h/72h, from 11 September 2026
An operational reference for CRA Article 14 reporting: what a maker of a product with digital elements files to the Single Reporting Platform within 24h, 72h and at closure, on two tracks.
- Playbooks9 min
Agentic AI ransomware — the containment playbook when the attacker is a model
An operational reference for containing ransomware driven end-to-end by an autonomous AI agent — when recon, lateral movement and encryption happen in seconds, with no human to interrupt.
- Playbooks9 min
Cloud exit plan — DORA Article 28 meets the EU Data Act
An operational playbook for building and testing a DORA Article 28(8) exit strategy that is actually executable under the EU Data Act cloud-switching rights — notice, port window, fees, and evidence.
- Playbooks8 min
CRA coordinated vulnerability disclosure & PSIRT — the setup playbook
How to stand up the Article 13 coordinated vulnerability disclosure policy and a PSIRT-grade intake–triage–remediation process before the CRA Article 14 reporting clock starts on 11 September 2026.
- Playbooks8 min
The detection-evidence pack — how to prove your detection works
How to build a standing, audit-grade detection-evidence pack — ATT&CK coverage, tested per-technique results, and MTTD — for the CISO who has to prove detection works, not just list tools.
- Playbooks9 min
The 2026 cyber insurance renewal questionnaire — the CISO answer playbook
A step-by-step reference for answering a 2026 cyber insurance renewal questionnaire defensibly: the controls underwriters verify, the evidence per answer, and the misstatements that void a claim.
- Playbooks9 min
External attack surface management — the 90-day onboarding playbook
A 90-day runbook for standing up an EASM program: discover the internet-facing assets you did not know you owned, attribute an owner to each, then set exploitability-based remediation SLAs.
- Playbooks10 min
NYDFS Part 500 penetration testing and vulnerability management — the §500.5 playbook
An operational guide to 23 NYCRR 500.5 as amended in November 2023: the penetration testing, scanning and remediation duties, who they cover, and the evidence behind the annual filing.
- Playbooks10 min
CMMC Phase 2 assessment evidence — the Level 2 and Level 3 playbook
A practical guide to CMMC Phase 2, from 10 November 2026: what C3PAO assessors test in the Risk Assessment and Security Assessment families, the POA&M limits, and Level 3 penetration tests.
- Playbooks9 min
SEC cybersecurity disclosure — the Form 8-K Item 1.05 and Item 106 playbook
A CISO playbook for the SEC's 2023 cybersecurity rules: the Form 8-K Item 1.05 filing due four business days after a materiality determination, and the annual Item 106 disclosure.
- Playbooks14 min
Penetration Testing Requirements by Regulation: A Worldwide Guide (2026)
A regulation-by-regulation map of who must run vulnerability assessments, penetration tests or threat-led red teaming, how often, who may test and what evidence to keep, with a detailed guide for each regime.
- Playbooks12 min
HIPAA penetration testing requirements — what the Security Rule requires today and what HHS has proposed
A clause-by-clause guide to what the HIPAA Security Rule requires on penetration testing and vulnerability scanning today, what the January 2025 HHS proposal would add, where that proposal stands, and the evidence a covered entity or business associate should keep.
- Playbooks13 min
PCI DSS penetration testing and scanning — Requirements 11.3 and 11.4 in v4.0.1
A requirement-by-requirement guide to PCI DSS 11.3 (internal and external vulnerability scans) and 11.4 (penetration testing, segmentation testing), who may perform each, what an automated or autonomous pentest can and cannot cover, and the evidence an assessor will ask for.
- Playbooks12 min
NIS2 penetration testing and vulnerability assessment requirements — what is mandatory and what is risk-based
A clause-by-clause guide to what NIS2, Implementing Regulation (EU) 2024/2690 and, for Italy, D.Lgs. 138/2024 and the ACN baseline measures require on vulnerability assessment and penetration testing, and the evidence that proves it.
- Playbooks11 min
DORA penetration testing requirements beyond TLPT — the Article 24–25 testing programme
A practical guide to the digital operational resilience testing programme that DORA Articles 24 and 25 require of almost every financial entity, how it differs from TLPT under Articles 26 and 27, and how to prepare for a TLPT with continuous internal testing.
- Playbooks10 min
MAS TRM penetration testing requirements — what section 13 of the Technology Risk Management Guidelines expects
A paragraph-by-paragraph guide to vulnerability assessment, penetration testing and red teaming in the MAS Technology Risk Management Guidelines, how binding they are, and the evidence that shows you follow them.
- Playbooks10 min
APRA CPS 234 security testing requirements — control testing, tester independence and what CPG 234 says about penetration testing
A guide to the testing paragraphs of APRA Prudential Standard CPS 234, APRA's guidance on penetration testing in CPG 234, who is in scope, and the records that show the testing program works.
- Playbooks11 min
UK penetration testing requirements — CBEST for financial firms and the NCSC Cyber Assessment Framework
How the Bank of England's CBEST intelligence-led testing and the NCSC Cyber Assessment Framework v4.0 treat penetration testing and vulnerability management: who they apply to, who may test, and what evidence counts.
- Playbooks10 min
Saudi NCA ECC penetration testing requirements — controls 2-10 and 2-11 and the CSCC frequencies for critical systems
A control-by-control guide to vulnerability management and penetration testing in the Saudi NCA Essential Cybersecurity Controls (ECC-2:2024) and the Critical Systems Cybersecurity Controls: who must comply, how often, and what to document.
- Playbooks11 min
Automated Pentesting Cost in 2026: Pentera, NodeZero, XBOW vs Manual Pentests
A sourced guide to what automated penetration testing costs in 2026: public contract records, third-party estimates, the factors that move the price, and a method to compare continuous testing with an annual manual pentest.
- Playbooks10 min
OWASP APTS: The Autonomous Penetration Testing Standard, Explained for Buyers
The OWASP Autonomous Penetration Testing Standard (APTS) is a governance standard for platforms that run penetration tests autonomously: 173 tier-required requirements in eight domains that say how such a platform must stay in scope, stay stoppable and stay accountable.
- Playbooks11 min
On-Premise & Air-Gapped Pentest Platforms: A Buyer's Guide
A procurement guide to on-premise and air-gapped platforms for automated and autonomous penetration testing: who needs them, which third-party rules make a vendor cloud hard to accept, and what on-premise should mean in the contract.
- Playbooks11 min
Does ISO 27001 Require Penetration Testing? Annex A 8.8, 8.29 and 5.35
A guide to where penetration testing fits in ISO/IEC 27001:2022: which Annex A controls it evidences, why the standard never makes it mandatory by name, how certification auditors judge whether your testing is adequate, and the records to keep.
- Playbooks10 min
Does SOC 2 Require a Penetration Test? What the Trust Services Criteria Say
A criterion-by-criterion guide to penetration testing and vulnerability scanning in SOC 2: what the 2017 Trust Services Criteria with the 2022 points of focus actually say, why a pentest is expected without being required, and the evidence a service auditor tests.
- Playbooks10 min
GDPR Article 32: Is Regular Security Testing Mandatory?
A guide to Article 32(1)(d) GDPR, the process for regularly testing, assessing and evaluating security measures: what the text requires of controllers and processors, why it is risk-based, what the EDPB and supervisory authorities have said about testing, and the records that demonstrate it.
Frequently asked
What is the difference between NIS2 and DORA?+
NIS2 (Directive 2022/2555) is the horizontal EU cybersecurity regime covering essential and important entities across most regulated sectors. DORA (Regulation 2022/2554) is the financial-sector-specific regime with stricter obligations on ICT operational resilience, TLPT (Threat-Led Penetration Testing) and ICT-third-party risk. Financial entities are subject to both in parallel.
Does the EU Cyber Resilience Act (CRA) apply to my product?+
The CRA applies to any "product with digital elements" — hardware or software — that connects directly or indirectly to a device or network and is placed on the EU market. Full application begins 11 December 2027; reporting obligations under Article 14 already apply from 11 September 2026. Open-source non-commercial contributors are out of scope; anyone monetizing open source is in.
What is CTEM and how does it differ from a pentest?+
Continuous Threat Exposure Management (CTEM) is a five-stage cyclic program (scoping, discovery, prioritization, validation, mobilization) that keeps an organization's exposure surface measured and provably reduced in continuous fashion. A pentest produces a point-in-time report; CTEM produces a continuously updated exposure ledger with cryptographic evidence per remediated item.
When does prompt injection (OWASP LLM01) become a regulatory issue?+
For LLM-powered systems that fall under the EU AI Act Annex III (high-risk), prompt-injection resistance is part of the Article 15 cybersecurity conformity property. For LLM tools used inside NIS2 essential and important entities, the same control sits under "appropriate and proportionate technical and organisational measures". A vendor that cannot demonstrate layered defenses against prompt injection is already at procurement disadvantage.
Should I start a post-quantum cryptography (PQC) migration now?+
Yes for any data with a confidentiality lifetime extending past the cryptographically relevant quantum computer (CRQC) horizon (typically 5-15 years). The "harvest now, decrypt later" threat model means encrypted traffic exfiltrated today can be decrypted retroactively once a CRQC exists. Hybrid TLS (X25519MLKEM768) and cryptographic inventory are the practical first steps for 2026.