Behind the Firewall ft. Mark Dube

by Morgan Prost / May 21, 2026

In the worst-case scenario, if any user within the organization were compromised, all of this sensitive information could be leaked externally. During a recent internal penetration test, Mark uncovered a critical security gap that the client was completely unaware of. While performing network enumeration using a custom file share enumeration tool, he discovered several SMB shares that were accessible to all users without any restrictions. These shares contained over 30,000 files, the…

Behind the Firewall ft. Joseph Kirkpatrick

by Morgan Prost / May 21, 2026

Audits are hard, but we make sure it's worth it. Not everyone loves audits, but the right experience can change everything. Joseph Kirkpatrick recently spoke with a new client who had already signed on after meeting him at a roundtable. During their first call, the client admitted he’d never had a good experience with auditors. He didn’t think highly of them, and frankly, he hated audits. Joseph told him this…

Behind the Firewall ft. Joseph Kirkpatrick

by Morgan Prost / July 28, 2026

Audits work best when there's transparency, not secrecy. During a recent engagement, Joseph encountered a situation that revealed much more than just a technical risk... a cultural one.  The client confirmed their penetration test was set for the weekend, but buried in the same email thread were plans to shut down vulnerable servers that Friday at 4:00p.m., then quietly bring them back on after the test.   The intent behind this wasn’t…

Behind the Firewall ft. Steven Collins

by Morgan Prost / May 21, 2026

What happens when important services, assumed to be covered, aren't? Many companies employ third parties to perform critical IT and security functions. These third parties often maintain high levels of access to an environment and are governed by contracts/MSAs. But what happens when the services assumed to be covered... aren’t?Lead Practitioner, Steven Collins worked with a healthcare organization that believed their third-party vendor was handling a significant amount of their IT…

Behind the Firewall ft. John Burkhart

by Morgan Prost / May 21, 2026

Audits aren’t just about ticking a checkbox; it's about building operational resilience.  During a recent SOC 2 gap assessment, Information Security Auditor, John Burkhart identified a major risk: the client lacked a formalized data backup and restoration process.  Backups to the cloud occurred sporadically, with no consistent schedule or oversight. Compounding the issue, restoration of these backups had never been tested, leaving significant uncertainty about their reliability in the event…