Contact us: info@tenendo.com
Blog
Insides
-
WordPress to Static Site on AWS: Architecture, Tooling, and the Edge Cases
This write-up covers the full production architecture: how Staatic handles the export and CloudFront deployment, why sitemaps need a separate solution and how we built one, and what the request path looks like when WordPress is entirely out of it.
-
PCI DSS Segmentation Testing Prerequisites
PCI DSS segmentation testing in cloud environments requires careful preparation to allow effective testing while limiting impact on operations.
-
Getting Started DORA Compliance today
A revolutionary partnership between AmonSul, Tenendo, and Trausta streamlines DORA compliance into a seamless 12-week process: gap assessment, threat intelligence, red teaming, and compliance reporting. Organizations save up to 40% while maintaining regulatory independence, transforming complex compliance into cost-effective success.
-
Comprehensive DORA Compliance
An Integrated Cybersecurity Solution for European Financial Organisations.
-
SOC/EDR Effectiveness Evaluation
We run real attack chains against your EDR and SOC to find out what they actually detect vs what they miss. Then we help you write the detection rules and tune the configuration to catch what’s slipping through.
-
NIST CSF 2.0 Security Assessment
Tenendo’s NIST CSF 2.0 Security Assessment helps identify cybersecurity gaps, evaluate maturity across CSF functions, and provide actionable improvements to enhance resilience and align with the latest NIST standards.
Case Studies
-
Critical Credential Exposure. External and AWS Penetration Testing Case Study.
A payment provider’s pre-transaction AWS review looked clean — until we found a public Spring Boot Actuator endpoint leaking a heap dump with live credentials for a privileged production role. No exploit chain needed: just download, extract, and the cloud environment was ours. Here’s why we don’t separate AppSec from infrastructure testing, and why that matters more as secure baselines improve.
-
Cloud Infrastructure Audit and Performance testing case
The main goal of the Technical Audit from a customer request was to understand if the system is scalable or not and provide guidance for improvements.
-
PCI DSS segmentation testing case
The team created several hardware connect-back appliances and used it in a PCI DSS segmentation testing.
-
Application Threat Modelling and Phishing Attack Chain Case
A threat model helped prioritize vulnerabilities, leading to the identification of a phishing attack chain that bypassed MFA and allowed unauthorized transactions.
-
Case Study: Strengthening Compliance with NIST CSF 2.0
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.
-
Network Compromise and Cloud Infrastructure Exposure Case
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.