Blog

Security research, practical guidance and lessons from the field.

Securing AI Chatbots and RAG Integrations: The New Attack Surface

Australian businesses are shipping AI chatbots and RAG features faster than they secure them. What can go wrong and how AI security testing works.

Penetration Testing for SOC 2 and ISO 27001: What Australian SMBs Actually Need

Auditors expect an independent pentest, but the requirement is smaller and cheaper than most SMBs fear. What counts as evidence and when to book it.

How to Scope a Penetration Test (and Get an Accurate Fixed Price)

Pentest pricing depends on scope, and scope is something you control. What drives effort, black box versus grey box, and the questions a good provider asks.

CVE-2021-40661: Remote Unauthenticated Directory Traversal on IND780 OT System

SIDSECURE original research: a remote unauthenticated directory traversal vulnerability in Mettler Toledo IND780 Advanced Weighing Terminal OT systems.

Optus API Hack: Practical Lessons for API Security

What the Optus data breach teaches about API security: environment exposure, authentication, test data handling, and the case for API penetration testing.