Behind the Firewall ft. Sean Rosado

by Morgan Prost / May 21st, 2026

Not everything is a critical issue, but each deserves a closer look.

During a recent engagement, Sean flagged a cross-site scripting vulnerability. Given the nature of the application and the use case for the affected functionality, the client believes the finding was a false positive. They agreed to schedule a session to dig deeper.

Sean spent some time before the session building an additional proof of concept that further demonstrated the impact of the reported issue. After a thorough review, the client was able to understand why additional guardrails needed to be implemented around the affected feature to mitigate the impact that was demonstrated.

Sean’s message is clear “This kind of partnership is what makes penetration testing effective. It’s not just about identifying risks, but rather about working together to validate findings, separate signal from noise, and build trust through transparency.”

A good security partner doesn’t just deliver results; they stay with you until the truth is clear.

Clear, actionable communication is how we work.