❌

Reading view

There are new articles available, click to refresh the page.

HIPAA Penetration Testing Requirements for Healthcare Enterprises

Many healthcare organizations have been told that HIPAA requires an annual penetration test. The current rule is more nuanced. Penetration testing for HIPAA compliance is not prescribed as one universal annual obligation, but regulated entities must conduct a comprehensive risk analysis, manage identified risks, and evaluate whether their safeguards remain effective. A well-scoped pentest can provide important evidence supporting those responsibilities. HHS has also proposed making annual penetration testing explicit, although that proposal is not yet binding.

The post HIPAA Penetration Testing Requirements for Healthcare Enterprises appeared first on Synack.

Penetration Testing for SOC 2 Compliance: What Auditors Expect

SOC 2 does not prescribe a universal penetration testing requirement for every organization. A pentest is still commonly used as evidence supporting security, risk assessment, and monitoring controls, and auditor expectations depend on the organization's risks, system boundary, and testing policies. Type II examinations require evidence that controls operated over a defined period, not merely that they existed on one date. A vulnerability scan should not be presented as equivalent to a penetration test, and findings, remediation, and retesting evidence matter as much as the original report.

The post Penetration Testing for SOC 2 Compliance: What Auditors Expect appeared first on Synack.

How Often Should Enterprises Run a Penetration Test?

Most enterprises should treat annual penetration testing as a baseline, not a complete answer. PCI DSS is the one framework with an explicit annual and change-triggered mandate. SOC 2, the current HIPAA Security Rule, and ISO 27001 all expect testing to follow the organization's own risk assessment and control design, not one fixed calendar date. HHS has proposed an annual HIPAA pentesting requirement, but that rule has not been finalized. Enterprises that combine a formal annual assessment with change-triggered and continuous validation stay ahead of frameworks that were never designed around a single testing frequency.

The post How Often Should Enterprises Run a Penetration Test? appeared first on Synack.

How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats

Iberia Cards CISO JosΓ© Manuel Rivera GarcΓ­a explains why he's stuck with Synack's PTaaS model across multiple organizations, and how running Sara AI Pentest alongside human researchers helps him balance regulatory compliance with real risk reduction. He also shares candid advice for other CISOs on avoiding the false sense of security that comes from infrequent testing and over-reliance on perimeter controls.

The post How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats appeared first on Synack.

The Hugging Face Breach Lesson on Autonomous AI Attacks

On July 16, an autonomous AI agent breached Hugging Face's production infrastructure end to end. When Hugging Face tried to investigate, the same guardrails built to stop AI attackers blocked their own responders from analyzing the evidence. Here's what that means for security teams building on AI, and what to test before a breach happens.

The post The Hugging Face Breach Lesson on Autonomous AI Attacks appeared first on Synack.

❌