Insights from Clone Systems
Straightforward guidance on PCI compliance, penetration testing, and modern vulnerability management. Written by the people behind the platform.
Fresh from the desk

MCP Server Security: Why Your Vulnerability Scanners Can't See Your AI Agents
MCP servers connect your AI agents to your data, and most run without authentication, outside your inventory and scan scope. See the exploited CVEs and the 10-point baseline to secure every server your agents can reach.
Every post from the Clone Systems desk
119 posts · Page 1 of 14

How to Prove SAQ B-IP Eligibility: The 5-Check Terminal Zone Test
A signed SAQ B-IP is only as good as the network behind it. Use the 5-Check Terminal Zone Test to see if your terminals really sit in their own zone under PCI DSS v4.

Zero Trust Implementation: Why the Accounts That Never Expire Are the Real Gap
The Pentagon's DMDC breach ran for nine months on standing access. Here is what zero trust actually requires under NIST SP 800-207, why MFA alone is not it, and the 6-point standing access audit to run before rollout.

Authenticated Web Application Scanning: What Your Scanner Misses Until It Logs In
Most web app scans never log in, so a clean report can describe a login form, not an application. Authenticated web application scanning tests what a logged-in attacker could reach.

How to Choose a Managed SOC Provider: The 7 Questions That Separate Coverage From Capability
Most managed SOC RFPs ask about capability, not coverage. Here are the 7 questions that separate a provider watching your data sources from one selling you dashboards, plus a rubric for your next RFP.

AI Agent Authorization: Why Your Workflow's Service Account Is the Attack Surface
AI agent authorization breaks when a workflow executes downstream actions with the service account's authority instead of the requester's. The 5-point check below closes the gap that prompt injection filters miss.

SOC 2 Penetration Testing: The Report Your Auditor Checks
Is a penetration test required for SOC 2? No, but auditors expect the evidence, and the AICPA is now flagging boilerplate SOC 2 work. Here is the 5-point check we run before a test report goes to an auditor.

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit
A network-only vulnerability program is blind to the laptops and field devices that leave the office. Here is when agent-based scanning earns its place, what each method sees, and the 5-class matrix for running both.

How to Reduce PCI DSS Scope: What Actually Takes a System Out of the CDE
PCI DSS scope is a documented decision, not a line on a diagram. Learn how to reduce PCI DSS scope and the five evidence items that make an out-of-scope claim survive assessor review.

Why Your PCI DSS Scope Is Bigger Than Your Diagram Says
PCI DSS scope is a documented decision, not a line on a network diagram. This post covers how to determine and prove the CDE boundary, what 12.5.2 requires of the far side of that boundary, and who decides it in 2026.
Prefer a live walkthrough over a long read?
Book a private demo with a senior specialist.