I’m Kurtis. I’ve been pen testing for 11 years.

I built Fidus Information Security from nothing to a team of 30 pentesters and sold it in 2023. Now I’m building Echo Secure, a UK pen testing firm. We do manual testing, real exploitation, and write reports that actually make sense to the people signing the cheques. No Nessus-scan-with-a-logo nonsense.

Why this blog exists

I have opinions about this industry and some of them need more than a LinkedIn post to get out properly.

Most of what I write is pen testing tradecraft. Things I’ve picked up from years of breaking into stuff. Vulnerability breakdowns, sanitised stories from engagements, how we actually approach different types of tests.

I also write about the pen testing market. Acquisitions eating up independents, certification debates that go nowhere, vendors overpromising. The usual.

Sometimes I write for the people on the other side of the table. CISOs and IT managers trying to buy a pen test and figure out who’s actually going to test their systems versus who’s going to run a scanner and call it a day.

Get in touch

If you want to talk pen testing, security, or working with Echo Secure, you know where I am.