Insights from Clone Systems

Straightforward guidance on PCI compliance, penetration testing, and modern vulnerability management. Written by the people behind the platform.

12+
Field guides published
1998
MSSP since
PCI ASV
Approved scanning vendor
24/7
SOC assistance
The archive

Every post from the Clone Systems desk

100 posts · Page 1 of 12

Aug 26, 2026Penetration Testing

Why PCI DSS Internal Penetration Testing Finds the Systems Your Scope Diagram Missed

PCI DSS Requirement 11.4.2 makes internal penetration testing a separate obligation from external testing, and it is scoped to every system that can reach the CDE, not just the systems inside it.

Read the post
Aug 18, 2026Vulnerability Scanning

Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding)

Most vulnerability scanner false positives are not scanner errors, they are evidence problems. Here is what actually closes a disputed finding, and why rescanning never does.

Read the post
Aug 18, 2026Security Strategy

Why a Clean Vendor Security Questionnaire Doesn't Mean Your Vendor Is Patched

A vendor security questionnaire records what a vendor asserts, not what an independent test found. Here are four signals you can verify on a vendor's live attack surface today, without their cooperation.

Read the post
Aug 18, 2026AI Security

Why Your Vulnerability Management Program Can't Score a Prompt Injection Finding

Prompt injection and tool-call abuse findings rarely fit CVE-based vulnerability management. Here's why they get dropped, and a framework to score them instead.

Read the post
Aug 17, 2026Penetration Testing

Why Passing a Penetration Test Retest Isn't the Same as Fixing the Root Cause

A penetration test retest confirms the specific reported vulnerability can no longer be exploited. It does not confirm the underlying root cause has been corrected everywhere else in your environment.

Read the post
Jul 29, 2026AI Security

What the OpenAI Security Incident Teaches About AI Security

An AI model chained a zero-day and stolen credentials to reach production infrastructure on its own. Here is what that means for every organization deploying AI assistants, agents, and integrations.

Read the post
Jul 22, 2026Penetration Testing

Why Your Annual Penetration Test Isn’t Covering Your AI Systems

Explore AI penetration test insights and discover how to secure AI applications from emerging vulnerabilities.

Read the post
Jul 22, 2026Penetration Testing

Why Your SaaS Penetration Test Might Be Testing a Product That No Longer Exists

Environment drift can make a clean SaaS penetration test meaningless. Learn how to scope tests that reflect real production risk.

Read the post
Jul 15, 2026Vulnerability Management

Modern Web Applications Are Getting Harder to Secure: Why Basic Scans May Not Be Enough

Understand the importance of web application penetration testing in identifying vulnerabilities beyond simple vulnerability scanning.

Read the post
See it in action

Prefer a live walkthrough over a long read?

Book a private demo with a senior specialist.