Mohamed

Mohamed is the founder of Packet33. He worked as a cybersecurity analyst before launching the firm and now leads an OSCP-certified team serving SaaS and HealthTech startups in the US, Canada, and UK.

Broken Access Control Is Still Winning: 2025 OWASP Data

Key Takeaways Broken access control remains the number one category in OWASP’s Top 10 2025 release, the fourth consecutive edition where it has held the top spot. Security misconfiguration jumped from fifth place to second, driven largely by cloud configuration complexity rather than code level bugs. OWASP’s own reported average incidence rate for broken access […]

Broken Access Control Is Still Winning: 2025 OWASP Data Read More »

Healthcare Data Breach Report: What HHS OCR Data Actually Shows

Large healthcare breaches hit a record 772 incidents in 2025, yet the number of people affected actually fell to about 61.6 million, down from 289 million the year before. That gap is the story this healthcare data breach report is really about. Breach counts and breach damage do not move together, and one mega breach can distort an entire year of data.

Healthcare Data Breach Report: What HHS OCR Data Actually Shows Read More »

Pentest Program for Startups: How to Make Security Testing Repeatable

A pentest program for startups looks very different from enterprise security programs with dedicated teams and annual budgets. Here is what a practical, repeatable approach actually looks like at the seed to Series A stage. Most founders get their first penetration test because something forced the issue. A SOC 2 auditor asked for it, an

Pentest Program for Startups: How to Make Security Testing Repeatable Read More »