Skip to content

Offensive Security

Offensive security resources for security practitioners.
Guides on autonomous pen testing, red teaming, BAS, and COST.

Breach and attack simulation explained

Breach and Attack Simulation (BAS): What It Validates, and How It Differs from CART, AI Pen Testing, and COST

Plenty of organizations end a quarter with a clean Breach and Attack Simulation (BAS) dashboard and a real breach in the same window. That is not a contradiction. It is a category being asked to answer a question it was never built to answer. BAS tells you whether your controls catch known attacker techniques. That… Read More »Breach and Attack Simulation (BAS): What It Validates, and How It Differs from CART, AI Pen Testing, and COST

Promotional graphic for FireCompass and EC-Council panel titled The Mythos Threat Is Real: How CISOs Should Respond, featuring a dark blue and purple abstract digital background.

FC & ECC Panel – The Mythos Threat Is Real: How CISOs Should Respond

AI has already changed offensive security. The open question for security leaders is what to do about it. A recent EC-Council CyberTalks session of the same name addressed the question directly, featuring FireCompass co-founders Bikash Barai and Arnab Chattopadhayay, along with a CISO from a global financial group. What follows is the part a CISO… Read More »FC & ECC Panel – The Mythos Threat Is Real: How CISOs Should Respond

Global CISO panel discussing the Claude Mythos threat landscape and agentic AI penetration testing strategies

The Mythos Threat Is Real: How CISOs Should Respond

AI is accelerating how fast attackers find vulnerabilities, build exploits, and make decisions. The question for security leaders is how to adapt without overreacting to the hype. A CISO Platform community panel of the same name took up that question with a global group: FireCompass founder and CEO Bikash Barai moderating, co-founder Arnab Chattopadhayay, a… Read More »The Mythos Threat Is Real: How CISOs Should Respond