Cybersecurity and artificial intelligence: what actually changes
What risks generative AI brings into a company, why prompt injection is not the real problem, and what an AI pentest actually tests.
Walkthroughs, CVE disclosures and research written by the specialists who do the work, not by a content team paraphrasing them.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
You’re in.
The next Newsletter lands in your inbox on Tuesday.
Could not send. Please try again or email us.
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
What risks generative AI brings into a company, why prompt injection is not the real problem, and what an AI pentest actually tests.
What a penetration test is, what phases it has, what you get at the end, how long it takes and how it differs from a vulnerability scan.
How 2FA works, which methods are strong and which are not, why SMS is no longer enough and how today’s phishing gets around it.
How ransomware reaches a company today, which operations run as a service, what decides the ransom and which controls break the chain.
The threats actually reaching companies in Spain today, what NIS2, DORA and the ENS require, and where the attacks really get in.
What identity theft and impersonation are, how they differ, how they are committed against companies and people, and what to do once it has happened.
What to check before signing with an offensive security provider in Spain: scope, methodology, who does the work, the deliverable, the retest and what the applicable rules ask for.
What antimalware is, how it differs from antivirus, how it detects threats and where it falls short next to EDR and XDR in a business.
A practical guide to cybersecurity for companies: which measures produce results, in what order to put them in place, and how to check that they work.
The real sequence of an external network penetration test: scope and rules of engagement, reconnaissance, perimeter analysis, exploitation, reporting and retest, plus what the test will not cover.
The sequence of a real internal network penetration test: the starting point we agree, what a domain account becomes, what you get at the end, how long it takes and what the exercise deliberately does not cover.
The real sequence of an iOS or Android engagement: what gets agreed before day one, what happens on a device we control, what reaches your backend, what you receive, and the six things this test deliberately does not cover.
The real sequence of a cloud engagement: rules of engagement, external recon, identity mapping, proving the chain, the report and the retest. Including what it deliberately does not cover.
The seven phases of a web application penetration test, what has to be ready before day one, how long it runs, what lands in your inbox at the end, and the things it deliberately does not cover.
A plain account of an API penetration test from the rules of engagement to the retest: what happens in each phase, what you get at the end, and the limits of what the test can tell you.
The engagement behind the button, phase by phase: how scope and rules of engagement get set, what reconnaissance covers on an AI system, the four layers of the technical phase, how findings are proved and reported, how long it takes, and what the test deliberately leaves out.
The seven phases of an Asperis engagement, from scope and rules of engagement through to the retest, with the standard behind each one, the duration ranges we scope to, and a plain list of what a penetration test does not cover.
The real sequence of a wireless penetration test, from the rules of engagement to the retest: what happens at each phase, what you need ready, how long it takes, and what this test deliberately does not cover.
A connected product is hardware, firmware, a radio and a cloud backend at once. Here is the sequence we run across all four, what you receive, how long it takes and where the test stops.
What to do in the first hours after a breach at a company operating in Spain: containment, evidence, the 72 hour deadline for notifying the AEPD, and what NIS2 and DORA require.
We compare Hack The Box and TryHackMe: approach, levels, community and plans, and what each one is for when you are training a security team.
What kind of knowledge the free courses in the Cisco academy give you, where that road ends, and how you carry on towards offensive security.
The seven phases of Lockheed Martin’s Cyber Kill Chain, how they map onto MITRE ATT&CK, and the point at which it is cheapest to break a real attack.
The malware families seen in business today, classified by how they spread and what they are after, and step by step what to do if you suspect a machine is infected.
What network security is, how it is organised in layers, what segmentation and Zero Trust add, and what actually fails when it is tested from the inside.
What a domain controller is, the role it plays in Active Directory, how it lives alongside Entra ID today and why it is the asset every attacker looks for first.
Every Tuesday you will get the latest news from the world of cybersecurity.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
You’re subscribed.
Check your inbox. The next Newsletter is on its way.
Could not send. Please try again or email us.
We publish research from people outside the team: findings, walkthroughs and analysis with real data behind it. We review it technically in house, and if it delivers what it promises, it goes out under your name and your link, not ours. We read everything that arrives; we do not publish everything that arrives.
What people ask us most before the first call.
A boutique cybersecurity firm is a small specialist that works by hand: its senior people run each engagement end to end, no engagement is delivered by automated scanning alone, and no defensive cross-sell dilutes the core work. It typically runs between five and fifty specialists with deep offensive certification, and takes on fewer engagements each year than a large consultancy. For European companies that take their security posture seriously, that matters because the attacker you face will not use a scan-and-deliver template, and neither should the team you hire to test you.
Three differences. First, who does the work: the senior specialists who scope your engagement are the ones who run it, walk you through the findings in our platform, and retest your remediation. You deal with those specialists directly. And we rotate auditors between engagements, so the next look at the same scope comes from someone who has not seen it before: whoever already mapped a system starts reading it the way it was explained to them and stops questioning the parts they have accepted, while a new auditor has nothing to take for granted. Second, scope discipline: we only do offensive work (red team, pentesting, and Dark Web Monitoring). We do not upsell SIEM, managed SOC, or GRC. Third, deliverable: every engagement closes with a live walkthrough, not with a PDF dropped in an inbox. The report is evidence, not the product.
Yes. Our red team practice runs the same way regardless of regulatory context: multi-week, goal-driven, manual, end-to-end against your live production environment within scope. When the engagement is framed under TIBER-EU or under the threat-led penetration testing provisions of DORA, we work with your control function and the regulator’s white-team representative, and we deliver against the framework’s evidence and reporting requirements.
Yes, completely free. You enter your company’s domain and we run it against a continuously updated intelligence feed: forums, paste sites, breach dumps, credential exposure, executive exposure. Results land in your inbox. No credit card, no auto-subscription, no follow-up sales call unless you ask for one. It is free because it answers one specific question ("is anything of ours already exposed?") and that conversation tends to lead naturally into a longer one if the exposure is material enough to act on.
Senior offensive specialists. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO, and CRTP credentials, and most have prior experience inside enterprise security teams or research-led red team units before joining us. We are NASA Bug Bounty-verified contributors, which means our findings on a public aerospace target meet a published quality bar reviewed by NASA’s security team. For sector context, our specialists have run engagements in fintech, healthcare, SaaS, energy, industrial, and Spanish public administration.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.