ISO 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While the standard does not explicitly mandate penetration testing, it remains a critical supporting activity for demonstrating technical assurance and verifying the effectiveness of security controls. By incorporating regular, scoped, and risk-aligned penetration testing into their […]
As organisations race to integrate AI for competitive advantage, we rarely see a lack of activity. Instead, we see a variation in strategy, often resulting in missed opportunities for efficiency. We tend to see businesses fall into one of three categories. First, there are those pushing for speed; deploying AI rapidly to gain an edge while viewing […]
Email remains the most exploited attack vector in cybersecurity despite years of investment in secure email gateways, phishing filters, awareness training, and cloud-native tools. For many organisations, these defences are simply no longer enough. At Dionach, we see this reality firsthand. Across penetration tests, adversary simulations, and threat-led assessments, email continues to be one of the most […]