Behind the Firewall ft. John Burkhart

by Morgan Prost / May 21, 2026

Audits aren’t just about ticking a checkbox; it's about building operational resilience.  During a recent SOC 2 gap assessment, Information Security Auditor, John Burkhart identified a major risk: the client lacked a formalized data backup and restoration process.  Backups to the cloud occurred sporadically, with no consistent schedule or oversight. Compounding the issue, restoration of these backups had never been tested, leaving significant uncertainty about their reliability in the event…

Behind the Firewall ft. Trevor Murphy

by Morgan Prost / May 21, 2026

Security headers are supposed to make things simpler, but what happens when they're misunderstood? Pentester, Trevor Murphy has spent the last five years focused on client-side security, and he’s seen the landscape shift dramatically. “When I first started in pen testing, web app security was a lot more fragmented. You had a separate header for each directive, one rule per line. Now, with Content Security Policies (CSPs), it’s all condensed into…

Behind the Firewall ft. Sean Rosado

by Morgan Prost / May 21, 2026

Not everything is a critical issue, but each deserves a closer look. During a recent engagement, Sean flagged a cross-site scripting vulnerability. Given the nature of the application and the use case for the affected functionality, the client believes the finding was a false positive. They agreed to schedule a session to dig deeper.Sean spent some time before the session building an additional proof of concept that further demonstrated the…

Behind the Firewall ft. Stu Skove

by Morgan Prost / May 21, 2026

What happens if your tools get it wrong? You trust your tools, but what happens when they get it wrong? While reviewing a newer team member’s finding, our Penetration Tester, Stu noticed a scanner had misidentified a vulnerability as Server-Side Template Injection (SSTI). Through manual testing, he discovered it was a Ruby Code Injection, an error that escalated into full remote command execution (RCE) on the server. From a web…

Behind the Firewall ft. Edmundo Delgado Jr.

by Morgan Prost / May 21, 2026

SOC 2 isn’t just about external validation. You may have seen the recent chatter claiming SOC 2 is a waste of time. We hear it too—usually from teams who treated compliance as a checkbox instead of a strategy. In today’s hyper‑competitive, security‑conscious market, customers expect more than features. They expect trust. Our Information Security Auditor, Edmundo Delgado Jr., explains why SOC 2 continues to matter for enterprise buyers: “It does matter because stakeholders notice…