Insights from Clone Systems

Straightforward guidance on PCI compliance, penetration testing, and modern vulnerability management. Written by the people behind the platform.

12+
Field guides published
1998
MSSP since
PCI ASV
Approved scanning vendor
24/7
SOC assistance
The archive

Every post from the Clone Systems desk

119 posts · Page 1 of 14

How to Prove SAQ B-IP Eligibility: The 5-Check Terminal Zone Test
Oct 6, 2026PCI Compliance

How to Prove SAQ B-IP Eligibility: The 5-Check Terminal Zone Test

A signed SAQ B-IP is only as good as the network behind it. Use the 5-Check Terminal Zone Test to see if your terminals really sit in their own zone under PCI DSS v4.

Read the post
Zero Trust Implementation: Why the Accounts That Never Expire Are the Real Gap
Oct 5, 2026Strategy

Zero Trust Implementation: Why the Accounts That Never Expire Are the Real Gap

The Pentagon's DMDC breach ran for nine months on standing access. Here is what zero trust actually requires under NIST SP 800-207, why MFA alone is not it, and the 6-point standing access audit to run before rollout.

Read the post
Authenticated Web Application Scanning: What Your Scanner Misses Until It Logs In
Oct 1, 2026Vulnerability Scanning

Authenticated Web Application Scanning: What Your Scanner Misses Until It Logs In

Most web app scans never log in, so a clean report can describe a login form, not an application. Authenticated web application scanning tests what a logged-in attacker could reach.

Read the post
How to Choose a Managed SOC Provider: The 7 Questions That Separate Coverage From Capability
Sep 30, 2026SOC & SIEM

How to Choose a Managed SOC Provider: The 7 Questions That Separate Coverage From Capability

Most managed SOC RFPs ask about capability, not coverage. Here are the 7 questions that separate a provider watching your data sources from one selling you dashboards, plus a rubric for your next RFP.

Read the post
AI Agent Authorization: Why Your Workflow's Service Account Is the Attack Surface
Sep 29, 2026AI Security

AI Agent Authorization: Why Your Workflow's Service Account Is the Attack Surface

AI agent authorization breaks when a workflow executes downstream actions with the service account's authority instead of the requester's. The 5-point check below closes the gap that prompt injection filters miss.

Read the post
SOC 2 Penetration Testing: The Report Your Auditor Checks
Sep 29, 2026Penetration Testing

SOC 2 Penetration Testing: The Report Your Auditor Checks

Is a penetration test required for SOC 2? No, but auditors expect the evidence, and the AICPA is now flagging boilerplate SOC 2 work. Here is the 5-point check we run before a test report goes to an auditor.

Read the post
Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit
Sep 28, 2026Vulnerability Scanning

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit

A network-only vulnerability program is blind to the laptops and field devices that leave the office. Here is when agent-based scanning earns its place, what each method sees, and the 5-class matrix for running both.

Read the post
How to Reduce PCI DSS Scope: What Actually Takes a System Out of the CDE
Sep 25, 2026PCI Compliance

How to Reduce PCI DSS Scope: What Actually Takes a System Out of the CDE

PCI DSS scope is a documented decision, not a line on a diagram. Learn how to reduce PCI DSS scope and the five evidence items that make an out-of-scope claim survive assessor review.

Read the post
Why Your PCI DSS Scope Is Bigger Than Your Diagram Says
Sep 23, 2026PCI Compliance

Why Your PCI DSS Scope Is Bigger Than Your Diagram Says

PCI DSS scope is a documented decision, not a line on a network diagram. This post covers how to determine and prove the CDE boundary, what 12.5.2 requires of the far side of that boundary, and who decides it in 2026.

Read the post
See it in action

Prefer a live walkthrough over a long read?

Book a private demo with a senior specialist.