<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PolkaSpots security writing</title>
    <link>https://polkaspots.com/security-due-diligence/blog/</link>
    <description>Writing on offensive security testing, technical due diligence for investors, and why compliance certificates are not evidence of security.</description>
    <language>en-GB</language>
    <atom:link href="https://polkaspots.com/security-due-diligence/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>What security due diligence should tell an investment committee</title>
      <link>https://polkaspots.com/security-due-diligence/blog/what-diligence-should-tell-an-investment-committee/</link>
      <guid isPermaLink="true">https://polkaspots.com/security-due-diligence/blog/what-diligence-should-tell-an-investment-committee/</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Not a severity distribution. Three things: does this change the price, does this change the plan, and what does it cost to fix. If the report cannot answer those, it was written for the wrong reader.</description>
      <category>due-diligence</category>
      <category>private-equity</category>
      <category>venture-capital</category>
      <category>m-and-a</category>
      <category>reporting</category>
    </item>
    <item>
      <title>A current ISO 27001 certificate is not evidence that you are secure</title>
      <link>https://polkaspots.com/security-due-diligence/blog/a-current-certificate-is-not-security/</link>
      <guid isPermaLink="true">https://polkaspots.com/security-due-diligence/blog/a-current-certificate-is-not-security/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>We have found production databases on the open internet at companies holding current certifications. The certificate was not fraudulent. It was answering a different question from the one the buyer thought it answered.</description>
      <category>due-diligence</category>
      <category>iso-27001</category>
      <category>compliance</category>
      <category>private-equity</category>
      <category>m-and-a</category>
    </item>
    <item>
      <title>What two hours of testing actually buys you</title>
      <link>https://polkaspots.com/security-due-diligence/blog/what-two-hours-of-testing-buys-you/</link>
      <guid isPermaLink="true">https://polkaspots.com/security-due-diligence/blog/what-two-hours-of-testing-buys-you/</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>A Flash Review is not a pentest and we do not pretend otherwise. Here is what fits in two hours, what does not, and why the constraint produces better results than it sounds like it should.</description>
      <category>penetration-testing</category>
      <category>flash-review</category>
      <category>methodology</category>
      <category>attack-surface</category>
    </item>
  </channel>
</rss>
