Sessions worth an hour
Practical sessions on penetration testing, API security and running an assessment programme. Live with real Q&A, and available on demand afterwards.
- On the slate
- 8 sessions
- Next session
- To be announced
- Q&A
- Live, unscripted
- Price
- Free
The standard
What a security webinar is actually for
The honest position: most B2B webinars are demos with a slide deck in front of them, and the audience knows it. Registration numbers hold up because the recording is a lead magnet, but attendance and completion are poor, and the people who matter most (senior practitioners) stopped attending years ago.
There is a version that works, and it is defined by a single constraint: the session must be worth an hour to someone who never buys anything.
That sounds like a cost. It is the mechanism. A session that teaches something real gets attended live, gets watched to the end, gets shared internally, and gets the speaker invited back. A session that pitches gets registered for and closed after four minutes.
For a technical security audience specifically, three things distinguish the two.
Show the actual thing.
Real terminal output, real findings, real interfaces. Slides describing a capability convince nobody who has seen a demo before.
Include what does not work.
A session that admits the limits of its approach is trusted on everything else. This audience has particularly low tolerance for being sold to and particularly high regard for being levelled with.
Let the audience break it.
Live Q&A that takes hard questions, including the awkward ones, is the highest-value fifteen minutes of any technical webinar.
Upcoming
Live sessions
Each session is built around a technique rather than a feature, with the full agenda published in advance so you can tell whether the hour is worth it.
No live session scheduled at the moment. The slate below is what the programme will be drawn from, and you can get notified when the next one is announced.
On demand
The back catalogue
Recorded sessions, complete with the live demonstrations and the Q&A.
The archive opens with the first two recorded sessions. Until then, the slate below is what the programme will be drawn from.
The slate
Eight sessions we can run
Each built on a capability the product genuinely has. None require inventing anything, and each answers a question the audience actually has. These are topics, not scheduled dates.
- 01
Testing access control properly: why one session is never enough
The technical argument that access control is a relationship between identities, and that single-session tooling cannot observe relationships. Demonstrate cross-role testing live, with two sessions held simultaneously and cross-access attempted.
- 02
Finding the endpoints nothing calls
Specification-driven API testing versus interface-driven crawling. Take an OpenAPI spec, show the gap between declared endpoints and endpoints any front end exercises, and test the difference. Covers GraphQL introspection and gRPC too.
- 03
What a validated finding actually contains
Walk one finding end to end: the request, the response, the reproducible curl, the CVSS vector, the CWE class, the remediation with vulnerable and secure code, the retest.
Aimed at teams evaluating whether validated output changes their triage cost.
- 04
Prioritising when everything is critical
The scoring argument: why CVSS is not a remediation order, and how weighted factors with published weights change the queue. Show two findings with identical severity and opposite priorities.
Suited to a security leadership audience.
- 05
Security testing in the pull request without slowing anyone down
Practical CI/CD session. Configuring GitHub Actions, choosing a gating threshold, why gating narrowly matters, and routing everything else to tickets.
Developer and platform-engineer audience.
- 06
Multi-tenant isolation: testing the thing that would end the company
Aimed squarely at SaaS. Configure accounts in two tenants, attempt to cross, and discuss why this class survives in production longer than any other.
- 07
Building an assessment programme with two people
Leadership and small-team session. Cadence, depth selection, what to automate, what to keep human, how to evidence it. Explicitly not a product session; the product appears as one option among the practices discussed.
- 08
What automated testing cannot do
The credibility session. An honest account of where autonomous testing has limits (novel business logic, social engineering, architecture review, anything needing organisational context) and how to structure a programme around that.
Formats
How a session runs
Four formats, chosen per topic. Every one of them ends in live Q&A.
The 45-minute technical deep-dive
30 minutes of demonstration, 15 minutes of Q&A. The default for practitioner topics. Live terminal and product, minimal slides.
The 30-minute focused session
One narrow question answered properly. Higher completion rates than 60-minute sessions and easier to schedule for people with real jobs.
The panel
Three practitioners on a shared problem. Works when the guests are genuinely independent and are allowed to disagree with you. Do not run this with two employees and a customer.
Office hours
No presentation. Announced topic, and an hour of questions. Cheap to run, disproportionately valuable, and it works even with a small audience; five engaged people is a good office hours session.
Registration
What registering gets you
The form stays short.
Name, work email, company. Every extra field costs registrations, and the qualifying information is available later anyway.
The recording goes to everyone who registered, attended or not.
The people who registered and could not attend are a real audience segment, and withholding the recording to force attendance is the kind of small hostility this audience notices.
More from the resource library
Five collections, one subject: what continuous AI penetration testing finds, what shipped to find it, and what to do with the results.
Case Studies
What changed for teams who moved to continuous AI pentesting: challenge, approach, numbers and the transferable lesson.
BrowseProduct Updates
What shipped and what it changes: the features behind each release, with the benefit stated in terms of the work it removes.
BrowseRelease Notes
Version by version: new features, improvements, bug fixes and anything that needs action before upgrading.
BrowseDownloads
Checklists, templates and guides for testing, API security and running an assessment programme, with gating stated on the card, not after the click.
BrowseSee Your Attack Surface in Real-Time
Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.