Skip to content
Pentesys

Author

James Hinton

Founder & CEO, Pentesys

James Hinton is the founder of Pentesys, a CREST-approved UK company working only on offensive security: penetration testing, PTaaS, CTEM, external attack surface management and red teaming. He built the business around one discipline rather than a broad consultancy menu, and most of his time still goes on how engagements get scoped, delivered and reported. He writes here about the practical side of security testing and what buyers should be asking for.

LinkedIn profile
Knowledge Base

Articles by James Hinton

Pentesys News & Research

Pentesys Signs the CREST AI Charter

Pentesys has signed the CREST AI Charter, reinforcing our commitment to the responsible, transparent and professionally governed use of artificial intelligence in cybersecurity.

Read article
Penetration Testing

Validating Penetration Test Findings

How findings get validated before they reach your team, why false positives cause friction with developers, and what to ask your tester.

Read article
CTEM & Exposure Management

Building a Vulnerability Remediation Plan

What a remediation plan needs to contain, how to assign owners and deadlines, and how to track findings through to verified closure.

Read article
Penetration Testing

What Happens After a Penetration Test

From draft report to retest: the debrief, the remediation window, and the decisions that determine whether the test was worth commissioning.

Read article
Penetration Testing

How Penetration Test Severity Ratings Work

CVSS, tester-assigned severity and business risk are three different things. How to read the ratings in your report without over-reacting.

Read article
Penetration Testing

How to Read a Penetration Test Report

What each section of a penetration test report is for, which parts matter to whom, and the details that reveal how the testing was done.

Read article
Compliance & Assurance

Third-Party Security Validation Testing

Independent validation of a supplier's security controls: what it covers, how it differs from an audit, and when it is worth asking for.

Read article
Penetration Testing

Choosing a Penetration Testing Provider

How to tell consultant-led testing from a rebranded scan: accreditation, methodology, reporting samples and the questions that expose the difference.

Read article
Red Teaming

Making the Case for a Red Team Exercise

How to explain to a board what a red team exercise buys that a penetration test does not, and how to set objectives worth paying for.

Read article
Penetration Testing

Scoping a Web Application Penetration Test

Roles, user journeys, APIs and environments. The scoping decisions that decide whether a web application test finds anything worth having.

Read article
Penetration Testing

Bug Bounty vs Penetration Testing

Two different models with different coverage guarantees. What each finds, what neither covers, and when running both makes sense.

Read article
Penetration Testing

What to Expect From a Penetration Test

A first-time buyer's walkthrough: scoping calls, rules of engagement, testing windows, findings as they land, and the report at the end.

Read article
Compliance & Assurance

Cybersecurity Due Diligence in M&A

What technical due diligence covers during an acquisition, how much can realistically be done pre-completion, and what changes deal terms.

Read article
Penetration Testing

How to Scope a Penetration Test

Getting scope right decides what a test can find. Asset inventory, environments, credentials, exclusions, and the mistakes that waste days.

Read article
Compliance & Assurance

GDPR Article 32 and Security Testing

Article 32 requires regular testing of security measures without naming a method. How penetration testing can help evidence that obligation.

Read article
Compliance & Assurance

PCI DSS Penetration Testing Requirements

If you’re still treating your annual audit as a checkbox exercise, you’re likely missing the strategic shift toward continuous security validation….

Read article
Penetration Testing

Internal Network Penetration Testing

What an internal assessment looks for once an attacker is already inside: credentials, lateral movement, and the path to domain admin.

Read article
Application Security

Mobile Application Penetration Testing

iOS and Android testing beyond the app binary: local storage, certificate pinning, backend APIs and platform-specific weaknesses.

Read article
Application Security

API Penetration Testing

Authorisation flaws, object-level access control and undocumented endpoints. Why API testing needs documentation and credentials to be useful.

Read article
Penetration Testing

Web Application Penetration Testing Costs

Why quotes for the same application vary so widely, what a day rate actually buys, and how to compare proposals on a like-for-like basis.

Read article
Red Teaming

Threat-Led Penetration Testing (TLPT) Explained

How threat-led penetration testing works in practice: intelligence-driven scenarios, the frameworks that ask for it, and where it differs from a standard red team engagement.

Read article
Compliance & Assurance

Protecting Special Category Data

Where special category data tends to leak — logs, exports, integrations, access control — and what to test when your systems hold it.

Read article
Penetration Testing

The Benefits of Penetration Testing

What organisations get from testing beyond a list of vulnerabilities: validated risk, evidence for customers, and a plan worth acting on.

Read article
Red Teaming

Penetration Testing vs Red Teaming

Coverage versus objectives: what each engagement type is designed to answer, and which one your organisation actually needs.

Read article
Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.