Read Our New Claude Mythos CISO AI Security Guide        
Platform
Darwin Attack Overview

Introducing Darwin Attack 3.0

Risk Scoring

Risk clarity for better decisions

Asset & Threat Intelligence

Actionable context for every asset

Human-In-The-Loop

Accuracy through expert human operators

Dashboards & Reporting

Reporting that drives action

Platform Integrations

Integrated workflows, better outcomes

Services
Overview

Pen Testing Reimagined

Managed Services

Continuous Penetration Testing

Always testing. Always one step ahead

Attack Surface Management

Discover, monitor, and reduce exposure continuously

Penetration Testing

AI Penetration Testing

Test AI systems before attackers do

Application Penetration Testing

Secure applications where attackers strike

Network Penetration Testing

Identify weaknesses across your infrastructure

Cloud Penetration Testing

Validate security across cloud environments

Advanced Testing

Embedded Systems

Secure firmware and embedded technologies

Red Teaming

Real attackers. Real-world impact

Advisory

Advisory Overview

Build a security program that scales

Why Evolve
Resources
Blogs

Find out business updates and industry insights

Webinars & Video Content

Practical perspectives from the field

Podcasts

Listen to our podcasts

Events

Connect, learn, and collaborate

Glossary

A concise glossary of important cybersecurity terms

AIUC-1: Why AI Systems Need Continuous Penetration Testing (Not Just a One-Time Assessment)

June 2, 2026

Read more
AI AppSec Champions: How to Build Internal AI Security Expertise Before It’s Too Late

May 14, 2026

Read more
Shadow AI in Your Enterprise: How CISOs Can Find the LLMs They Don't Know About

April 30, 2026

Read more
Scott Howitt, CEO, SVH Cyber

February 10, 2026

Read more
Webinar: A Case for CTEM

September 22, 2025

Read more
Fireside Chat: State of Cybersecurity 2025

December 10, 2024

Read more
Company
About Us

Learn our mission and purpose

Executive Leadership & Advisors

Meet the leaders changing our industry

Careers

Who we are, how we work

Partner Program

Discover benefits of our channel ecosystem

Contact Us

Start your journey with us today

Book a Demo

Experience our platform firsthand

Book a Demo

J.R. Hernandez

Security Services Manager

With more than 10 years of experience in the information security space, J.R. is an experienced penetration tester, vulnerability researcher, offensive security consultant, cyber threat intelligence analyst, public speaker and adjunct professor. J.R.’s current mission is to guide all of Evolve Security’s engineers to ensure we are providing the best service possible while helping our clients secure their environments. Committed to teaching and contributing to the information security community, J.R. has served as the head of Evolve Security’s LA Meet Up Chapter. He is very passionate about information security and enjoys mentoring the next generation of cybersecurity professionals. J.R. holds the CISSP certification and is constantly working towards new certifications to improve his skillset. A graduate of The University of Texas at San Antonio, J.R. earned a Bachelor’s Degree in Infrastructure Assurance.

Blog Posts by

J.R. Hernandez

futuristic background with title of blog securing azure managed identities with microsoft azure cloud logo to represent azure cloud pentests

Securing Azure Managed Identities: Understanding Risks and Implementing Mitigation Strategies

Exploring security risks of Azure Managed Identities, the blog post outlines mitigation strategies centered on diligent management and regular permission audits.

Arrow Forward Icon
futuristic background with title of blog about navigating AWS security and AWS logo

Navigating AWS Security: Understanding Risks and Implementing Best Practices

This blog post discusses the security risks in Amazon Web Services (AWS) and presents strategies for mitigating them, emphasizing regular audits, continuous monitoring, and secure configuration of resources.

Arrow Forward Icon
Futuristic background with blog title and graphics of a credit card and a network of people to visually indicated PCI DSS Compliance

How to Test Your Network for PCI Compliance

This guide highlights the importance of PCI compliance testing, offering a step-by-step process to secure cardholder data and mitigate data breach risks amid growing cyber threats.

Arrow Forward Icon
futuristic background with blog title and graphics of web servers with two arrows to illustrate server side request forgery

How to Prevent Server-Side Request Forgery

Explore the concept of server-side request forgery (SSRF) attacks, their impact, and prevention methods to improve organizational cybersecurity and protect sensitive information.

Arrow Forward Icon
a dark outer space-esque background with graphics of a digital cloud and checklist to illustrate cloud vulberability scanning

How to Find Cloud Instances Not Being Scanned for Vulnerabilities

Challenges in scanning all cloud instances for security vulnerabilities are discussed, along with strategies for identifying unscanned instances and actionable steps for remediation.

Arrow Forward Icon
abstract background with graphics of chart with arrows and an interconnected globe to illustrate cyber threat modeling

Cyber Threat Modeling 101

Cyber threat modeling is essential in fortifying an organization's security posture, and this post explores its key components, the role of STRIDE methodology, and best practices for effective implementation.

Arrow Forward Icon
tech background with abstract circuit overlay with the title about cybersecurity statistics

2023 Cybersecurity Statistics Your Team Needs to Know

This article provides an extensive overview of the most relevant cybersecurity statistics for 2023, shedding light on the current trends, challenges, and effective strategies to keep your team informed and prepared.

Arrow Forward Icon
futuristic background with a interconnected network graphic and the title of the blog of how much does penetration testing cost

How Much Does Penetration Testing Cost?

This blog post explains why frequent penetration testing is crucial for businesses and discusses the important components that influence the cost of penetration testing, such as scope of the test, expertise of the testers, type of testing, tools and methodologies used, and reporting and remediation guidance.

Arrow Forward Icon
futuristic tech background with blog title and graphic of a vulnerability scan report

How to Read a Vulnerability Scan Report

This blog post highlights the significance of vulnerability scanning for organizations to identify potential security risks in their systems and applications, and provides guidance on interpreting a vulnerability scan report.

Arrow Forward Icon
5 layered pyramid graphic with title of blog post and titles of the different cybersecurity maturity model levels

Your Guide to Cybersecurity Maturity Model Levels

Learn about cybersecurity maturity model levels, the different levels of cybersecurity maturity, and the benefits of knowing your cybersecurity maturity level.

Arrow Forward Icon
gradient colors with text overlay of blog title about cybercrime

What Is the Actual Cost of Cybercrime?

The blog post discusses the impact and costs of cybercrime on businesses, as well as solutions to bolster cybersecurity, including those provided by Evolve Security.

Arrow Forward Icon
abstract background with title of blog post and graphics of a connected network and vulnerability scanning

What Is Vulnerability Scanning?

Vulnerability scanning is an automated process that proactively identifies application, network, and security weaknesses, and helps organizations identify and address security issues to minimize organizational risk.

Arrow Forward Icon
man working on laptop computer analyzing a vulnerability report

Reporting and Tracking – Show Me Where I Am

Our Darwin Attack® platform provides one authoritative source for all information about identified vulnerabilities.

Arrow Forward Icon
woman on a laptop computer with a graphic overlay and gear icons

Management – Help Me With the Process

Managing vulnerabilities is a continuous process. Read about how our Darwin Attack® platform enables effective collaboration between all stakeholders.

Arrow Forward Icon
Digital chain with a broken link with a graphic overlay of an image indicating directions to put break back together

Remediation – Simplify the Fixes

This post discusses details about how Darwin Attack allows you to fix vulnerabilities in an efficient manner.

Arrow Forward Icon
Laptop computer open on a desk with a blue graphic overlay of a to do list

Prioritization – How Important is Everything?

To manage vulnerabilities effectively, organizations must consider the potential likelihood and impact of the identified vulnerabilities. Learn how Darwin Attack® helps with prioritization.

Arrow Forward Icon
Hands on a keyboard with a blue graphic overlay and image of a piece of paper and magnifying glass

Identification of Vulnerability – Tell Me What You See

Evolve Security's Darwin Attack® platform is designed to help you effectively manage vulnerabilities, including prioritization and remediation recommendations.

Arrow Forward Icon
close up of man in a short sleeve polo shirt working on a laptop with a graphic overlay of a checklist

Vulnerability Management: If You Can’t Prove It, It Didn’t Happen

Reporting on vulnerabilities is an essential aspect of demonstrating control over a security program. Read about how to follow best practices for reporting.

Arrow Forward Icon
man standing up looking at a computer and computer equipment with a graphic overlay of a gear icon

Vulnerability Management: A Journey, Not a Thing

Traditional, periodic penetration testing is no longer effective. This blog post discusses the importance of migrating to more frequent, on-demand, or even continuous testing.

Arrow Forward Icon
Man looking at 3 computer screens displaying code with a graphic wrench overlay to indicate security remediation

Vulnerability Management: Fix It, Then Prove It

If you are interested in improving your security posture and reducing risk, your security program should include a remediation strategy. Check out our recommendations for how to remediate vulnerabilities in your environment.

Arrow Forward Icon
Man working on a computer with a graphic overlay of a list

Vulnerability Management: Prioritize, Prioritize, Prioritize

Over the past 30 years or so, there have been nearly 180,000 vulnerabilities identified, and that number is growing everyday. Learn how a penetration test can help you prioritize what to do first.

Arrow Forward Icon
Two computer monitors side by side with code displayed on screen with a magnifying glass style overlay

Vulnerability Management: Identification of Vulnerabilities is Not Just a List of Problems

If you can identify the vulnerabilities, you can mitigate those vulnerabilities, and remove, or at least reduce, potential risk to your environment. See how an effective security program includes critical steps in the assessment of identified vulnerabilities.

Arrow Forward Icon
silhouette of a burglar shinning a flashlight into a dark room

Why Scanning Isn’t Enough: Vulnerability Scans vs. Pentesting

While both are critical components of a strong offensive security posture, vulnerability scans and penetration testing are not one in the same. Dive deeper into learning about their differences and better protect your organization.

Arrow Forward Icon
a lock in the center of a moving circle of lines and arrows with the colors fading between blue and red, from the right to left, respectively.

Six Top Offensive Security Tools

For cybersecurity efforts to be effective, it is important to be both proactive and reactive to different types of vulnerabilities, breaches, or attacks. Testing your environment with the right offensive security tools is critical to protecting your organization from threats and maintaining a strong security posture and mitigating risk. Here are the top 6!

Arrow Forward Icon
Image of gold coin representing cryptocurrency, surrounded by other silver coins

Cryptocurrency & Cybersecurity Best Practices

Our CEO and Co-Founder of Evolve Security, Paul Petefish, recently discussed the intersection of crypto and cybersecurity with Evolve Security Advisor and Chief Security Officer at Kraken Digital Asset Exchange, Nicholas J. Percoco. Read on to learn their insights and suggestions.

Arrow Forward Icon
Glowing circuits behind two intertwining blue ribbons that fade from dark navy to a vibrant blue.

What to Look for in a Penetration Testing Services Partner

Less than confident about how crucial cybersecurity issues are being managed by your organization? Then it's time for a new penetration testing services partner.

Arrow Forward Icon

Defensive Vs. Offensive Cybersecurity: What’s Best for Your Organization?

With the rise of cybersecurity attacks and the cost of data breaches exploding over the last few years, a single layer of security simply isn’t enough to keep your organization protected. To mitigate the risks of a cyber attack, it’s vital to adopt both a proactive defensive and offensive cybersecurity strategy.

Arrow Forward Icon
Close up of a computer keyboard with white and red text saying "Log4j Update"

LOG4J Update: Mitigating, Scanners & More

The cybersecurity industry is now learning more about how Log4j can expose some of the world’s most popular applications and services to attack and result in a complete remote system takeover. Our own J.R. Hernandez shares thoughts on the origin of Log4j, the threat, and current strategies for remediation.

Arrow Forward Icon
Copyright © 2026 Evolve Security. Evolve Security is trademarked in the United States.
Stay in the know. Subscribe today!
312-957-5682
123 N. Waker Dr., Suite: 2125 Chicago, IL 60606
info@evolvesecurity.com
Connect
Contact UsRequest a demo
Services
Services OverviewAI Penetration TestingApplication Penetration TestingCloud Penetration TestingNetwork Penetration TestingEmbedded SystemsRed TeamAdvisory
Platform
Darwin Attack OverviewRisk ScoringAsset & Threat IntelligenceHuman-In-The-LoopDashboards & ReportingPlatform Integrations
Resources
BlogsEventsVideosPodcasts
Company
AboutCareersEvolve AcademyPartner Program
Privacy PolicyTerms of ServiceVulnerability Disclosure PolicyReport Issue
AICPA SOC logo with text 'SOC for Service Organizations | Service Organizations' and website aicpa.org/soc4so.