New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Blog Feature

Penetration Testing

By: Philip Holbrook
August 24th, 2026

I made it back from Las Vegas with a pile of notes, way too many stickers, three new badges around my neck, and a list of research rabbit holes long enough to keep me busy until next August. This year's floor leaned hard into AI-assisted red teaming, autonomous attack chains, and some of the most practical social engineering research I've seen at a con.

Blog Feature

Penetration Testing | Artificial Intelligence

By: Josh Tomkiel
August 19th, 2026

On nearly all sales calls, we receive questions around how Schellman is using AI on the pen test team, how AI is going to change our processes, and how fast these changes will be implemented.

Blog Feature

Penetration Testing | Artificial Intelligence

By: Josh Tomkiel
February 9th, 2026

Artificial intelligence is reshaping the cyber threat landscape as attackers have already begun weaponizing AI to dramatically accelerate phishing, reconnaissance, payload development, and attack execution.

Blog Feature

FedRAMP | Penetration Testing

By: Josh Tomkiel
November 24th, 2025

If you've received a report labeled "Red Team Assessment" and can’t help but notice it reads more like a penetration test report, you're not alone. We've seen this pattern repeatedly. Organizations invest in what they believe is a Red Team engagement, only to receive a penetration test with a different label. This deception can be more damaging than helpful as it is fundamental to your security posture that you understand the depth of assessment your organization actually received.

Blog Feature

Penetration Testing | Artificial Intelligence | ISO 42001

By: Josh Tomkiel
November 3rd, 2025

Not only is artificial intelligence changing how businesses operate; it's also changing how cybercriminals attack. As organizations rush to adopt AI systems, they face new security risks that traditional defenses can't handle.

Blog Feature

FedRAMP | Penetration Testing | Red Team Assessments

By: Clint Mueller
September 29th, 2025

Since the beginning of 2024, FedRAMP Revision 5 has mandated that organizations not only perform traditional penetration tests, but also undergo comprehensive red team engagements. This new requirement reflects a broader emphasis on assessing not just technical vulnerabilities, but also the effectiveness of an organization’s overall security posture, including it’s response to sophisticated and realistic threats. Over the past year, we’ve conducted many red team exercises, each tailored to different organizational environments and threat landscapes. These engagements have varied significantly in scope and complexity, offering us a wealth of insights into both our successes and the challenges we’ve faced.

Blog Feature

Penetration Testing

By: Josh Tomkiel
September 17th, 2025

TL;DR Schellman’s core value of "quality above all" means understanding your business and comprehending why you need any given compliance service. In the case of penetration tests, it's not just about counting how many vulnerabilities we find. Good pen testing gives you risk ratings that fit your actual setup, shows we understand your specific business and technology, keeps communication clear throughout the project, and provides advice you can actually use. We focus on being your security partner and helping you understand real business risk instead of just checking compliance boxes.

{