By:
Philip Holbrook
August 24th, 2026
I made it back from Las Vegas with a pile of notes, way too many stickers, three new badges around my neck, and a list of research rabbit holes long enough to keep me busy until next August. This year's floor leaned hard into AI-assisted red teaming, autonomous attack chains, and some of the most practical social engineering research I've seen at a con.
Penetration Testing | Artificial Intelligence
By:
Josh Tomkiel
August 19th, 2026
On nearly all sales calls, we receive questions around how Schellman is using AI on the pen test team, how AI is going to change our processes, and how fast these changes will be implemented.
Penetration Testing | Red Team Assessments
By:
Philip Holbrook
March 4th, 2026
Recently on a Sunday night my phone rang, showing an unknown number.
Penetration Testing | Artificial Intelligence
By:
Josh Tomkiel
February 9th, 2026
Artificial intelligence is reshaping the cyber threat landscape as attackers have already begun weaponizing AI to dramatically accelerate phishing, reconnaissance, payload development, and attack execution.
By:
Josh Tomkiel
November 24th, 2025
If you've received a report labeled "Red Team Assessment" and can’t help but notice it reads more like a penetration test report, you're not alone. We've seen this pattern repeatedly. Organizations invest in what they believe is a Red Team engagement, only to receive a penetration test with a different label. This deception can be more damaging than helpful as it is fundamental to your security posture that you understand the depth of assessment your organization actually received.
Penetration Testing | Artificial Intelligence | ISO 42001
By:
Josh Tomkiel
November 3rd, 2025
Not only is artificial intelligence changing how businesses operate; it's also changing how cybercriminals attack. As organizations rush to adopt AI systems, they face new security risks that traditional defenses can't handle.
FedRAMP | Penetration Testing | Red Team Assessments
By:
Clint Mueller
September 29th, 2025
Since the beginning of 2024, FedRAMP Revision 5 has mandated that organizations not only perform traditional penetration tests, but also undergo comprehensive red team engagements. This new requirement reflects a broader emphasis on assessing not just technical vulnerabilities, but also the effectiveness of an organization’s overall security posture, including it’s response to sophisticated and realistic threats. Over the past year, we’ve conducted many red team exercises, each tailored to different organizational environments and threat landscapes. These engagements have varied significantly in scope and complexity, offering us a wealth of insights into both our successes and the challenges we’ve faced.
By:
Josh Tomkiel
September 17th, 2025
TL;DR Schellman’s core value of "quality above all" means understanding your business and comprehending why you need any given compliance service. In the case of penetration tests, it's not just about counting how many vulnerabilities we find. Good pen testing gives you risk ratings that fit your actual setup, shows we understand your specific business and technology, keeps communication clear throughout the project, and provides advice you can actually use. We focus on being your security partner and helping you understand real business risk instead of just checking compliance boxes.