❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySynack Blog

HIPAA Penetration Testing Requirements for Healthcare Enterprises

By: Paul Mote
8 September 2026 at 07:45

Many healthcare organizations have been told that HIPAA requires an annual penetration test. The current rule is more nuanced. Penetration testing for HIPAA compliance is not prescribed as one universal annual obligation, but regulated entities must conduct a comprehensive risk analysis, manage identified risks, and evaluate whether their safeguards remain effective. A well-scoped pentest can provide important evidence supporting those responsibilities. HHS has also proposed making annual penetration testing explicit, although that proposal is not yet binding.

The post HIPAA Penetration Testing Requirements for Healthcare Enterprises appeared first on Synack.

Penetration Testing for SOC 2 Compliance: What Auditors Expect

By: Paul Mote
1 September 2026 at 04:46

SOC 2 does not prescribe a universal penetration testing requirement for every organization. A pentest is still commonly used as evidence supporting security, risk assessment, and monitoring controls, and auditor expectations depend on the organization's risks, system boundary, and testing policies. Type II examinations require evidence that controls operated over a defined period, not merely that they existed on one date. A vulnerability scan should not be presented as equivalent to a penetration test, and findings, remediation, and retesting evidence matter as much as the original report.

The post Penetration Testing for SOC 2 Compliance: What Auditors Expect appeared first on Synack.

How Often Should Enterprises Run a Penetration Test?

By: Paul Mote
20 August 2026 at 10:09

Most enterprises should treat annual penetration testing as a baseline, not a complete answer. PCI DSS is the one framework with an explicit annual and change-triggered mandate. SOC 2, the current HIPAA Security Rule, and ISO 27001 all expect testing to follow the organization's own risk assessment and control design, not one fixed calendar date. HHS has proposed an annual HIPAA pentesting requirement, but that rule has not been finalized. Enterprises that combine a formal annual assessment with change-triggered and continuous validation stay ahead of frameworks that were never designed around a single testing frequency.

The post How Often Should Enterprises Run a Penetration Test? appeared first on Synack.

RufRoot Exposed the Hidden AI Agent Attack Surface

By: Paul Mote
1 August 2026 at 07:16

The critical RufRoot vulnerability gave unauthenticated attackers a path from an exposed MCP endpoint to shell access, stolen AI provider keys and poisoned agent memory. Paul Mote explains why the incident should change how security teams define, test and recover their AI attack surface.

The post RufRoot Exposed the Hidden AI Agent Attack Surface appeared first on Synack.

How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats

By: Paul Mote
24 July 2026 at 13:07

Iberia Cards CISO JosΓ© Manuel Rivera GarcΓ­a explains why he's stuck with Synack's PTaaS model across multiple organizations, and how running Sara AI Pentest alongside human researchers helps him balance regulatory compliance with real risk reduction. He also shares candid advice for other CISOs on avoiding the false sense of security that comes from infrequent testing and over-reliance on perimeter controls.

The post How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats appeared first on Synack.

How an OpenAI Model Escaped its Guardrails

By: Paul Mote
23 July 2026 at 15:54

During an internal evaluation with its safety guardrails switched off, an OpenAI model escaped its test environment and breached Hugging Face's production systems, again, this time to steal answers to its own benchmark. No one told it to. It decided that on its own.

The post How an OpenAI Model Escaped its Guardrails appeared first on Synack.

The Hugging Face Breach Lesson on Autonomous AI Attacks

By: Paul Mote
21 July 2026 at 13:43

On July 16, an autonomous AI agent breached Hugging Face's production infrastructure end to end. When Hugging Face tried to investigate, the same guardrails built to stop AI attackers blocked their own responders from analyzing the evidence. Here's what that means for security teams building on AI, and what to test before a breach happens.

The post The Hugging Face Breach Lesson on Autonomous AI Attacks appeared first on Synack.

❌
❌