Plain-language definitions of the security and compliance terms that show up in audits, sales questionnaires, and board decks. Written to be accurate and quotable, by the team that delivers SOC 2, penetration testing, AI/LLM security, and fractional CISO work.
Security requirements for any organization that handles payment card data.
OffensiveThe difference between automated breadth (scan) and manual depth (pen test).
OffensiveAn authorized, manual assessment where testers actively exploit weaknesses like a real attacker.
AI SecurityAn attack where crafted input makes an LLM ignore its instructions and follow the attacker's.
Analyzing source code for security flaws without running the program.
ComplianceThe structured questions an enterprise buyer sends to assess a vendor's security posture.
OperationsA system that collects and correlates log data across systems to detect threats.
ComplianceAn AICPA auditing standard reporting on how a service organization manages customer data.
ComplianceDesign at a point in time (Type I) vs operating effectiveness over a period (Type II).
SOC 2 readiness, penetration testing with our partner Lorikeet Security, AI/LLM security, and fractional CISO leadership, backed by real published research.
Book a strategy call