Insights
What we have learned, written down
No news posts and no announcements. These are the answers we find ourselves giving repeatedly — about when to automate, what a security assessment really covers, which EU rules actually apply to the software you ship, and how nearshore engagements work in practice.
More reading
OWASP assessment vs penetration test: which one your requirement names
Suppliers use the two terms interchangeably. Contracts, insurers and regulators do not. How to read the clause you have been given before you buy the wrong thing.
How to write a bug report a developer can act on
A defect report is a handover of an unfinished investigation. Most of them fail in the same three places, and none of the repairs involve a longer template.
Diagnosing flaky tests: a procedure, not a retry
A retry policy converts an unreliable suite into a slow one that sounds confident. Four families of flake, the tell that identifies each, and the order to work through them.
Test data management: five strategies and what each one costs
How a test obtains the state it needs decides whether a suite survives parallel execution. Five approaches, the failure mode of each, and the problems nobody puts in the estimate.
Playwright vs Cypress: one architectural difference, and its consequences
The two runners differ structurally in one way, and nearly every practical distinction falls out of it. What that means for redirects, parallelism, debugging, and who ends up maintaining the suite.
When to automate a test, and when the answer is no
Not a philosophy of automation but a decision taken one case at a time. Five signals, four possible verdicts, and why "keep it manual" is not the losing option.
Broken object level authorisation: the API risk no scanner will find for you
The top entry on the OWASP API Security Top 10 returns a perfectly normal 200 to the wrong person. Why tooling cannot see it, and how the testing actually runs.
Triaging dependency vulnerabilities: what to do with 400 open alerts
A scanner dashboard nobody opens is worse than no scanner. How to sort advisories by whether they can actually be triggered, and how to record the ones you defer.
Your first enterprise security questionnaire: how to answer it honestly
Two hundred questions arrive attached to the largest deal in your pipeline. What the buyer is really assessing, the only three answers worth giving, and where suppliers get caught.
NIS2 when your customers are in scope and you are not
The directive binds essential and important entities. Its supply-chain article reaches everyone who sells to them, and it arrives as contract clauses rather than as law.
DORA’s testing programme: what a financial entity has to prove, and how often
DORA asks for a documented testing programme over the systems behind critical functions, and a much heavier threat-led test for entities singled out for it. The two are not the same product.
In-house QA vs outsourced QA: how to decide which one you need
The comparison is rarely about the day rate. It is about hiring lead time, what happens between releases, and how much of your quality knowledge sits in one person’s head.
Testing with production-like data without breaking GDPR
Restoring the production database into staging is processing personal data. What that obliges you to do, why anonymised and pseudonymised are not interchangeable words, and what belongs in the test plan.
The European Accessibility Act and your website: what it actually requires
The Act has applied since June 2025. What it covers, which technical standard sets the bar today, and the accessibility failures no automated checker will ever find for you.
The Cyber Resilience Act’s first deadline: what changes on 11 September 2026
From 11 September 2026, manufacturers must report an actively exploited vulnerability within 24 hours. Who that binds, what the clock actually demands, and what to have in place before it starts.
Nearshore QA outsourcing in Poland: how engagements actually work
What nearshore testing costs, why the time zone matters more than the day rate, and the questions worth asking before you sign anything.
Manual testing vs test automation: which to invest in first
Automation is not a more advanced form of manual testing. They answer different questions, and picking the wrong one first is an expensive way to learn that.
What an OWASP-based security assessment covers — and what it does not
The difference between a vulnerability assessment and a penetration test, what a report should contain, and why "we ran a scanner" is not an assessment.
Building a test automation framework from scratch: the first 90 days
What actually gets built, in what order, and why the teams that start by recording scripts end up rewriting everything.
Contact
Have a question we have not written up yet?
Ask it directly. We would rather answer the specific version of your problem than point you at a general article about it.