The Raptoric JournalVol. 01 · 61 pieces

Practical writing
from the field.

Our engineers write about penetration testing, threat detection, and building security programs, based on work with regulated companies.
§ 02All writing
02
AI Security
AI penetration testing: how to test LLM apps, agents, and RAG
AI penetration testing covers an attack surface a standard pentest was never built for. See what it tests, how it works, and how it differs from red teaming.
June 13, 2026
8 min read
03
AI Security
AI red teaming: a practical guide for security teams
AI red teaming simulates a determined adversary against your models, agents, and guardrails. See how it differs from a pentest and how to run it well.
June 13, 2026
7 min read
04
AI Security
Securing AI agents: the new attack surface of agentic AI
When AI can take actions, a manipulated model becomes a manipulated actor. See why agentic AI is a new attack surface and how to secure your agents.
June 13, 2026
6 min read
05
Security Program & Risk
The NIST AI Risk Management Framework (AI RMF) explained
The NIST AI RMF is the leading voluntary framework for managing AI risk. See its four core functions and how to use it alongside the EU AI Act and ISO 42001.
June 13, 2026
5 min read
06
Security Program & Risk
AI governance: framework, documentation, and how to start
AI governance is how an organization controls the AI it builds and uses. See what it covers, the documentation it requires, and a practical way to start.
June 13, 2026
5 min read
07
Security Program & Risk
The EU AI Act explained: risk tiers, obligations, and timeline
The EU AI Act is the first comprehensive law on artificial intelligence. See how its risk tiers work, what high-risk providers must do, and the timeline.
June 14, 2026
6 min read
08
AI Security
MCP security: risks of the Model Context Protocol and how to manage them
The Model Context Protocol connects AI models to tools and data, and that link is a new attack surface. See the risks it adds and how to secure it.
June 14, 2026
5 min read
09
AI Security
RAG security: protecting retrieval-augmented generation systems
Retrieval-augmented generation gives models access to your data, and that data joins the attack surface. See how RAG gets attacked and how to secure it.
June 14, 2026
11 min read
10
AI Security
AI data and model poisoning: how it works and how to defend against it
Data poisoning corrupts what an AI system learns or retrieves, so it fails in ways the attacker chooses. See how these attacks work and how to defend.
June 14, 2026
10 min read
11
AI Security
LLM jailbreaks explained: how they work and how to defend
A jailbreak makes a model do what its safety controls were meant to prevent. See how LLM jailbreaks work, how they differ from injection, and the defenses.
June 14, 2026
11 min read
12
AI Security
The OWASP Top 10 for LLM Applications, explained
The OWASP Top 10 for LLM Applications is the reference list of the most critical AI application risks. See what each of the ten risks means and how to fix it.
June 14, 2026
10 min read
13
Security Program & Risk
ISO 42001: the AI management system standard, explained
ISO 42001 is the first certifiable standard for an AI management system, the AI equivalent of ISO 27001. See what it covers and how it fits the EU AI Act.
June 14, 2026
11 min read
14
Security Program & Risk
Shadow AI: the risk of unsanctioned AI use, and how to manage it
Shadow AI is the unsanctioned use of AI tools by employees, and a fast-growing data risk. See why it happens and how to manage the risk it creates.
June 14, 2026
11 min read
15
AI Security
Deepfake fraud: AI-generated voice and video attacks on business
Deepfake fraud uses AI-generated voice and video to impersonate executives and authorize payments. See how the attacks work and how to defend your business.
June 14, 2026
10 min read
16
Security Program & Risk
What is a virtual CISO (vCISO), and when do you need one?
A virtual CISO gives you senior security leadership on a fractional basis. See what the role covers, how it differs from a full-time CISO, and when it fits.
June 11, 2026
10 min read
17
Security Program & Risk
NIS2 explained: who is in scope, what it requires, and the deadlines
NIS2 raises the cybersecurity baseline across 18 EU sectors and holds management personally accountable. See who it covers, what it demands, and what to do.
June 10, 2026
15 min read
18
Offensive Security
How much does a penetration test cost?
Most pentest quotes land between a few thousand and low six figures. What matters is what sits behind it: scope, seniority, and whether anyone breaks in.
June 9, 2026
12 min read
19
Offensive Security
Penetration testing services: what you actually get
A penetration test is a person trying to break into your systems on purpose, under rules you set. See what the types cover and what you get at the end.
June 8, 2026
11 min read
20
Offensive Security
How to choose a penetration testing company
The brief is the same everywhere; the work is not. See how to tell a real offensive team from a scan with an invoice, and the questions to put in your RFP.
June 7, 2026
13 min read
21
Offensive Security
PTaaS vs traditional pentest vs automated scanning
Three things get sold as testing, and they are not the same. See what PTaaS, a pentest, and a scan each find, what they miss, and how to combine them.
June 6, 2026
13 min read
22
Offensive Security
What is VAPT? Vulnerability assessment and penetration testing explained
VAPT bundles two jobs: a broad sweep for known weaknesses and a deep test that proves which ones matter. See how each works and why they belong together.
June 5, 2026
13 min read
23
Application & Cloud
Web application penetration testing: a buyer's guide
Your web app is the front door to your data, and scanners only rattle the handle. See what real web app testing covers, what tools miss, and how to scope it.
June 4, 2026
13 min read
24
Application & Cloud
API security testing and the OWASP API Security Top 10
APIs are the new perimeter, and they fail differently from web pages. See what API security testing covers and why authorization is at the heart of it.
June 3, 2026
12 min read
25
Application & Cloud
Cloud security assessment: what it covers, and why IAM comes first
Cloud breaches rarely start with a clever exploit. They start with a permission nobody walked back. See what a cloud assessment covers and where risk hides.
June 2, 2026
12 min read
26
Offensive Security
Network penetration testing explained
External testing asks how someone gets in; internal testing asks how far they get. See what network penetration testing covers and why assume-breach matters.
June 1, 2026
12 min read
27
Offensive Security
External attack surface management (EASM) explained
You cannot defend what you do not know you own. EASM continuously finds your internet-facing assets, including the ones no one remembers, before attackers do.
May 30, 2026
12 min read
28
Threat Detection & Response
Managed detection and response (MDR): what it is and when you need it
MDR is a team that watches your environment, decides what is real, and acts when it matters. See how it differs from SIEM, MSSP, and EDR, and when to buy it.
May 26, 2026
12 min read
29
Threat Detection & Response
What a Security Operations Center (SOC) does
A SOC is the team and tech that watch your environment around the clock and triage what matters. See the roles a SOC needs and when to build one in-house.
Jun 16, 2026
11 min read
30
Threat Detection & Response
SIEM, EDR, and XDR: what's the difference
SIEM, EDR, and XDR are detection tools that get confused constantly. See what each one does, how they differ, and how they fit together as one defense.
Jun 16, 2026
10 min read
31
Threat Detection & Response
How to build an incident response plan
A plan you write for the first time during an attack is worthless. See how to build an incident response plan, the phases it covers, and how to rehearse it.
Jun 16, 2026
10 min read
32
Security Program & Risk
Risk assessment: how to run one step by step
A risk assessment is the foundation of a serious security program; without it you invest at random. See how to run one step by step and turn it into a plan.
Jun 16, 2026
11 min read
33
Security Program & Risk
Cyber risk management: from assessment to decision
A risk assessment tells you where you are exposed. Risk management is what you do about it. See how to run risk as a continuous process, not a one-off doc.
Jun 16, 2026
11 min read
34
Security Program & Risk
Business continuity and disaster recovery (BCP and DR)
When a system goes down, the question is how fast you recover. See what a business continuity plan and a disaster recovery plan are, and how to build each.
Jun 16, 2026
11 min read
35
Security Program & Risk
Vendor risk management (third-party risk)
Your security is only as strong as your vendors' security. See why third-party risk keeps growing and how to manage it before a partner's weakness is yours.
Jun 16, 2026
9 min read
36
Security Program & Risk
ISMS: the information security management system
An ISMS turns security from a pile of tools into a system you can actually manage. See what an ISMS is, what it rests on, and why ISO 27001 is built on it.
Jun 16, 2026
10 min read
37
Security Program & Risk
ISO 27001 Annex A: 93 controls in four themes
Annex A is the catalog of security controls ISO 27001 relies on. See how it splits into four themes, what the controls cover, and how to choose yours.
Jun 16, 2026
10 min read
38
Security Program & Risk
The Statement of Applicability (SoA) in ISO 27001
The Statement of Applicability is a core ISO 27001 document. See what the SoA contains, why auditors check it first, and how to produce one correctly.
Jun 16, 2026
10 min read
39
Application & Cloud Security
OWASP Top 10: the most common web application vulnerabilities
The OWASP Top 10 lists the most serious security risks in web applications. See what each category means, why it matters, and how to address it in code.
Jun 16, 2026
10 min read
40
Application & Cloud Security
DevSecOps: security built into development
DevSecOps builds security into development from the start instead of checking it just before launch. See what it covers and how to adopt it without friction.
Jun 16, 2026
5 min read
41
Offensive Security
Operational technology (OT) and industrial cybersecurity
In industrial environments, downtime is not just an IT problem; it has physical consequences. See how OT security differs from IT and how to build it safely.
Jun 16, 2026
6 min read
42
Offensive Security
ICS and SCADA security: what makes it different
ICS and SCADA systems control physical processes, so an attack on them has real-world consequences. See what makes their security different and how to start.
Jun 16, 2026
12 min read
43
Offensive Security
IEC 62443: the standard for industrial system security
IEC 62443 is the leading international framework for securing industrial and OT systems. See how it is structured, what security levels mean, and who it fits.
Jun 16, 2026
6 min read
44
Offensive Security
Red teaming: simulating a real attack
Red teaming goes a step beyond a pentest. It simulates a real attacker across technology, people, and physical access to test your defense, not just systems.
Jun 16, 2026
10 min read
45
Offensive Security
Ransomware: how to protect against it and respond to an attack
Ransomware encrypts your data, demands a ransom, and increasingly steals it first. See what an attack looks like, how to prevent it, and how to respond fast.
Jun 16, 2026
7 min read
46
Offensive Security
Phishing and social engineering: how to spot and stop an attack
Most serious breaches start with a message, not a vulnerability. Phishing targets people, not systems. See what the attacks look like and how to stop them.
Jun 16, 2026
7 min read
47
Offensive Security
Malware: the main types and how to defend against them
Viruses, trojans, ransomware, and spyware are different malware with one goal: compromising your systems. See how they differ, get in, and how to defend.
Jun 16, 2026
10 min read
48
Offensive Security
DDoS attacks: how they work and how to defend
A DDoS attack floods a system with traffic until it goes down. Here is how it works, the main types, and how a company defends itself and prepares to respond.
Jun 16, 2026
12 min read
49
Offensive Security
Business email compromise (BEC): how to spot it and stop it
Business email compromise is among the costliest attacks there is. An attacker poses as an executive or supplier and asks for a payment. See how to stop it.
Jun 16, 2026
10 min read
50
Offensive Security
Identity theft: how it happens and how to protect yourself
Identity theft lets an attacker pose as you or one of your staff. See how it happens, what the consequences are, and how to cut the risk for you and the firm.
Jun 16, 2026
8 min read
51
AI Security
AI security: how to secure LLM applications
LLM apps add an attack surface that behaves like nothing before it, and better prompts will not save you. The controls that work live in the architecture.
May 24, 2026
14 min read
52
Security Program & Risk
DORA compliance checklist for financial entities
DORA has applied across the EU financial sector since January 2025 and rests on five pillars. This checklist turns them into work you can assign and track.
May 22, 2026
12 min read
53
Security Program & Risk
NIS2 vs DORA: which one applies to you?
Two EU cybersecurity rules overlap but are not identical. NIS2 is broad; DORA is the financial-sector specialist. Here is how to tell which one governs you.
May 20, 2026
12 min read
54
Security Program & Risk
ISO 27001 certification: the engineering path to the certificate
ISO 27001 certifies that you manage information security as a governed, ongoing process. See what it involves, how it runs, and why security comes first.
May 18, 2026
13 min read
55
Security Program & Risk
SOC 2 compliance: a technical readiness guide
A SOC 2 report tells customers you have security controls and follow them. See what it covers, how Type I and Type II differ, and how to get ready honestly.
May 12, 2026
12 min read
56
Security Program & Risk
SOC 2 vs ISO 27001: which should you do first?
Both prove you take security seriously: one a US attestation, the other a global certification. The right first move depends on who you sell to. Here is how.
May 10, 2026
13 min read
57
Security Program & Risk
SOC 1 vs SOC 2 vs SOC 3: what is the difference?
Three reports, one confusing scheme. SOC 1 covers financial controls, SOC 2 security, SOC 3 public proof. See which one a customer is really asking for.
May 8, 2026
13 min read
58
Offensive Security
A scan is not a pentest
Automated scanners find only what they are told to look for, but attackers do not read the rulebook. See why a scan and a pentest are not the same thing.
May 14, 2026
13 min read
59
Threat Detection & Response
Most alerts are noise. The job is the signal.
A detection program that pages you for everything trains you to ignore the one alert that matters. Here is how to separate real signal from noise in MDR.
Apr 30, 2026
14 min read
60
Security Program & Risk
SOC 2 is a floor, not a finish line
A clean SOC 2 report tells a customer you have controls. It does not tell an attacker to stay out. Here is the gap between passing an audit and being secure.
Apr 16, 2026
11 min read
61
Application & Cloud Security
The quietest risk in your cloud is IAM
Nobody reviews the permission granted two years ago for a migration that finished a year ago. Here is why cloud IAM is the quiet risk that builds up unseen.
Apr 2, 2026
12 min read