Mohamed

Mohamed is the founder of Packet33. He worked as a cybersecurity analyst before launching the firm and now leads an OSCP-certified team serving SaaS and HealthTech startups in the US, Canada, and UK.

What a HealthTech CTO Should Actually Demand From a Pentest Vendor

Choosing the right healthcare pentest vendor is harder than it looks. You have been through engagements before. You know what a good one looks like. What you are trying to figure out is whether this particular healthcare pentest vendor actually understands your environment, the PHI handling, the API surface, the compliance mapping, the operational constraints

What a HealthTech CTO Should Actually Demand From a Pentest Vendor Read More »

How to Scope a Pentest When You Have Two Weeks Before a Prospect Deadline

Your pentest turnaround time from contract signing to final report delivery needs to fit inside two weeks. That is the window most SaaS founders discover they have when an enterprise prospect asks for a penetration test before moving the deal to legal review. Two weeks is tight but workable, if you scope the engagement correctly

How to Scope a Pentest When You Have Two Weeks Before a Prospect Deadline Read More »

A Prospect Just Sent You a Security Questionnaire. Here Is What They Are Actually Asking For.

A security questionnaire response is one of the first real tests of whether your startup’s security program is real or just theoretical. The document looks technical, the stakes feel high, and most early-stage founders are not sure how many of their honest answers will hold up to scrutiny. Here is what is actually happening and

A Prospect Just Sent You a Security Questionnaire. Here Is What They Are Actually Asking For. Read More »

What HealthTech Startups Actually Need to Be HIPAA Compliant Before Their First Enterprise Deal

You just got a serious conversation going with a hospital system, a large health plan, or a digital health platform that has enterprise customers of their own. The call went well. The product demo landed. And then someone on their security team sent over a vendor questionnaire with 80 questions about your data handling practices,

What HealthTech Startups Actually Need to Be HIPAA Compliant Before Their First Enterprise Deal Read More »

The 2026 Pentest: Why Manual Logic Validation Outperforms Automated Scans

Manual penetration testing has become the standard enterprise buyers and auditors expect from SaaS and HealthTech companies in 2026, and the gap between what it finds and what automated scans catch has never been wider. Automated tools are excellent at identifying known vulnerabilities, missing patches, and common misconfigurations. But the vulnerabilities that are actually costing

The 2026 Pentest: Why Manual Logic Validation Outperforms Automated Scans Read More »