Free Resources
Insights & Articles
Practitioner-written explainers on offensive security, managed security, compliance and incident readiness. No registration. No paywall. New articles added regularly.
Articles
Each article links down to the relevant HackersHub service when you're ready to engage.
- Managed Security
What is an MSSP? Meaning, MSP vs MSSP & how to choose
A plain-language explainer of the Managed Security Service Provider model — what an MSSP actually delivers, how it differs from a generalist MSP, and the questions to ask when evaluating one.
8 min readRead article - Red Teaming
What is red teaming? Adversary simulation explained
Red teaming is more than a thorough pentest. This guide explains threat-led adversary simulation, the operating tempo, TIBER-EU and DORA alignment, and when a red team operation is the right next step.
10 min readRead article - Penetration Testing
What is penetration testing? A practitioner's guide
What manual penetration testing actually involves, the difference between vulnerability scanning and a real pentest, and how to scope an engagement for SOC 2, ISO 27001 or DORA reporting.
12 min readRead article - Managed Security
MSP vs MSSP — the difference that matters for your security posture
Side-by-side: what an MSP handles, where an MSSP picks up, and why mixing the two is a common security-posture mistake. Includes a decision matrix.
7 min readRead article - Vulnerability Scanning
Penetration test vs vulnerability scan: which do you need?
Automated vulnerability scanning and manual penetration testing answer two different questions. This guide compares depth, frequency and cost, and explains when to use each, or both.
7 min readRead article - Penetration Testing
External vs internal penetration testing: which do you need?
External and internal penetration tests model two different attackers, the outsider breaking in and the intruder already inside. This guide compares scope, starting point and typical findings, and explains when to run each, or both.
7 min readRead article - Compliance
NIS2 compliance and penetration testing: what you need to prepare
NIS2 raises the bar on cybersecurity risk management across the EU. This guide explains what it requires, who it applies to, and how penetration testing provides the effectiveness evidence NIS2 expects.
8 min readRead article - Compliance
ISO 27001 penetration testing: what the standard asks and what auditors expect
ISO 27001 never names penetration testing, yet every certification auditor asks for one. Which Annex A controls a test supports (8.8, 8.29, 9.1), how to scope it, cadence, and what a certification-ready report contains.
9 min readRead article - Compliance
SOC 2 penetration testing: requirements and auditor expectations
SOC 2 does not list penetration testing as a required control, yet nearly every auditor expects the report. How a test maps to the Trust Services Criteria (CC4.1, CC7.1), Type I versus Type II, scope and cadence.
9 min readRead article - Compliance
PCI DSS penetration testing: Requirement 11.4 explained
PCI DSS is the one framework that names penetration testing outright. What v4.0.1 Requirement 11.4 demands: internal and external tests every 12 months, segmentation testing, retests, and what a QSA accepts as evidence.
9 min readRead article - Compliance
DORA penetration testing and TLPT: Articles 24 to 27 explained
DORA has applied to EU financial entities since 17 January 2025 and is the first EU law that names penetration testing as an obligation. The annual testing programme, threat-led penetration testing every three years, tester requirements and supervisor expectations.
10 min readRead article - Compliance
NIST SP 800-115 penetration testing: the methodology explained
The four-phase method auditors have in mind when they ask for an industry-accepted methodology: planning, discovery, attack, reporting. Where it is required (NIST 800-53 CA-8, FedRAMP, PCI DSS 11.4.1) and what a compliant report contains.
9 min readRead article - Compliance
HIPAA penetration testing: what the Security Rule expects
HIPAA never named penetration testing, yet risk analysis and periodic evaluation cannot be evidenced without one, and the proposed 2025 Security Rule update would require it annually. Scope for ePHI systems and what OCR looks for.
9 min readRead article - Compliance
GDPR penetration testing: Article 32 and testing security of processing
Article 32(1)(d) requires a process for regularly testing the effectiveness of security measures. How penetration testing evidences it, scope from the Article 30 record, DPIA links and breach-notification readiness.
8 min readRead article - Buying guide
Penetration testing cost in 2026: what drives the price and how to compare quotes
Published market ranges by test type, the six variables behind every quote (scope, depth, type, seniority, reporting, retest), day-rate maths and a checklist for comparing two proposals that look nothing alike. No price list: HackersHub quotes on scope.
9 min readRead article - Buying guide
How to choose a penetration testing company: the 12 questions that separate testers from scanners
Named testers, certifications, manual share, methodology and sample report, scope rules, escalation, retest, report contents, data handling, insurance, framework mapping and references. Ask them in writing before you sign.
9 min readRead article - Buying guide
Penetration testing RFP and quote checklist: what to send, what to require back
The one-page request that makes every quote comparable: scope, roles, test positions, framework, deadline. Plus the ten things to require in every proposal and a weighted scoring table.
8 min readRead article - Buying guide
How often should you run a penetration test? The cadence each framework expects
Annual is the floor. What PCI DSS, DORA, ISO 27001, SOC 2, NIS2 and HIPAA expect, what counts as a significant change, three calendar tiers, and how to time the test against the audit.
8 min readRead article - Penetration Testing
Manual vs automated penetration testing: what each finds, and what only a human finds
Scanners, PTaaS platforms and AI-driven tools versus a certified tester: a class-by-class comparison of what each finds, where automation belongs in a programme, how to spot a scan sold as a pentest, and what auditors accept.
9 min readRead article - Penetration Testing
Types of penetration testing: by target, by position and by knowledge level
Three axes instead of one list: target (network, web, API, mobile, cloud, wireless, hardware, social engineering), position (external, internal, assumed breach, tenant) and knowledge (black, grey, white box), with the combinations that fit each situation.
9 min readRead article - Managed Security
MSSP vs MDR vs SOC as a service: what each delivers, and which one you actually need
Three models separated by one question: who acts when an alert fires. A side-by-side table, four questions that settle the choice, the combinations that work without paying twice, and how to test whether a provider actually detects attacks.
9 min readRead article - Managed Security
What an MSSP contract should include: the SLA, scope and exit clauses that decide everything
The clauses that matter during an incident (scope, triage and response SLAs, containment authority, escalation, legal reporting), at audit time (reporting, assurance, log retention, testing rights) and at exit (data and tooling ownership, transition). Plus the red flags.
9 min readRead article - Managed Security
SOC as a service and MSSP pricing: the eight things that drive the cost
Per asset, per data or per control: the three pricing models, the eight cost drivers, the line items that only appear after signature, and how to normalise two quotes before comparing totals. No price list.
9 min readRead article - Compliance
Managed security for NIS2: which Article 21 measures an MSSP or MDR actually covers
The Article 21(2) measures mapped to managed services, the Article 23 clocks (24 hours, 72 hours, one month) the provider must support, supply-chain duties, and the contract terms that turn the service into NIS2 evidence.
10 min readRead article
More coming
We're expanding the Insights library with deeper explainers across penetration testing methodologies, red team operations, managed security, compliance frameworks (NIS2, DORA, ISO 27001, SOC 2) and incident response. Check back, or follow the awareness library track-by-track.