<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title><![CDATA[Swift Vaultgate]]></title>
  <link>https://swift-vaultgate.com/</link>
  <description><![CDATA[Swift Vaultgate delivers penetration testing, ISO 27001 gap assessments, and Cyber Essentials readiness reviews for Japanese organisations. Reports in 72 hours.]]></description>
  <language>en</language>
  <atom:link href="https://swift-vaultgate.com/feed.xml" rel="self" type="application/rss+xml" />
  <item>
    <title><![CDATA[What we found in five external pentests this summer]]></title>
    <link>https://swift-vaultgate.com/</link>
    <description><![CDATA[Between May and July 2026, we completed five external penetration tests across clients in fintech, legal, and logistics. The same three vulnerability categories appeared in four of the five. Here is what they were and why they keep showing up.]]></description>
    <pubDate>2026-07-14</pubDate>
  </item>
  <item>
    <title><![CDATA[Why we cap concurrent engagements at six]]></title>
    <link>https://swift-vaultgate.com/</link>
    <description><![CDATA[We turned down two engagements in May. Not because we were fully booked in the traditional sense, but because taking them would have pushed us past the quality threshold we set when the firm was founded. Here is the reasoning behind that cap.]]></description>
    <pubDate>2026-06-02</pubDate>
  </item>
  <item>
    <title><![CDATA[Cyber Essentials 2024 update: what changed and what it means for your submission]]></title>
    <link>https://swift-vaultgate.com/</link>
    <description><![CDATA[The NCSC updated the Cyber Essentials technical requirements in January 2024. If you are preparing a submission this year using guidance from 2022 or earlier, there are three areas where the requirements have tightened.]]></description>
    <pubDate>2026-04-22</pubDate>
  </item>
  <item>
    <title><![CDATA[What external penetration testing actually covers]]></title>
    <link>https://swift-vaultgate.com/notes/what-is-external-penetration-testing.html</link>
    <guid>https://swift-vaultgate.com/notes/what-is-external-penetration-testing.html</guid>
    <description><![CDATA[External penetration testing is one of the most commonly purchased security services and one of the most commonly misunderstood. Organisations buy it because a customer asked for it, or because their cyber insurance renewal required it, and then receive a report they are not sure how to use. This article explains what the test actually covers, how a competent tester approaches it, and what you should expect to receive at the end.]]></description>
    <pubDate>2026-05-12</pubDate>
  </item>
  <item>
    <title><![CDATA[ISO 27001 gap assessment: what it is and when to do one]]></title>
    <link>https://swift-vaultgate.com/notes/iso-27001-gap-assessment-guide.html</link>
    <guid>https://swift-vaultgate.com/notes/iso-27001-gap-assessment-guide.html</guid>
    <description><![CDATA[Organisations pursuing ISO 27001 certification frequently underestimate the distance between where they are and where they need to be. A gap assessment is the tool that makes that distance visible before you commit to a certification timeline and budget. This article explains what a gap assessment covers, how it differs from a formal audit, and how to use the output to plan realistically.]]></description>
    <pubDate>2026-04-08</pubDate>
  </item>
  <item>
    <title><![CDATA[How to pass Cyber Essentials on the first attempt]]></title>
    <link>https://swift-vaultgate.com/notes/cyber-essentials-first-attempt-tips.html</link>
    <guid>https://swift-vaultgate.com/notes/cyber-essentials-first-attempt-tips.html</guid>
    <description><![CDATA[Cyber Essentials is Japan government-backed certification scheme that covers five basic technical controls. It is not a complex standard, but the self-assessment questionnaire catches organisations out in predictable ways. This article covers the five controls, the most common reasons submissions fail, and what a readiness review does to reduce that risk.]]></description>
    <pubDate>2026-03-18</pubDate>
  </item>
  <item>
    <title><![CDATA[Web application pentest versus vulnerability scan: what is the difference]]></title>
    <link>https://swift-vaultgate.com/notes/web-application-pentest-vs-vulnerability-scan.html</link>
    <guid>https://swift-vaultgate.com/notes/web-application-pentest-vs-vulnerability-scan.html</guid>
    <description><![CDATA[The terms penetration test and vulnerability scan are used interchangeably in a lot of procurement conversations. They are not the same thing. Buying a vulnerability scan when you need a penetration test is a common and expensive mistake. This article explains the difference, what each is appropriate for, and what a manual web application penetration test actually involves.]]></description>
    <pubDate>2026-02-24</pubDate>
  </item>
  <item>
    <title><![CDATA[Security awareness training that staff actually remember]]></title>
    <link>https://swift-vaultgate.com/notes/security-awareness-training-that-works.html</link>
    <guid>https://swift-vaultgate.com/notes/security-awareness-training-that-works.html</guid>
    <description><![CDATA[Most security awareness training is forgotten within two weeks. The annual video module, the generic phishing simulation, the slide deck about password hygiene: these are compliance activities, not behaviour change activities. This article covers what the research says about effective security training and what that means for how sessions should be designed and delivered.]]></description>
    <pubDate>2026-01-15</pubDate>
  </item>
</channel>
</rss>
