Category: Field Guides
-

A Field Guide to the CSPM Alert
CSPM alerts in 2026 amount to the most underused signal in the typical cloud security stack. The CSPM fires 100-500 alerts per day, the SOC triages maybe 10% of them, the rest sit in the queue until the queue gets purged. The field guide covers what the alerts mean, what the priority is, and what…
-

A Field Guide to the Secure Code Review
A field guide to the secure code review in 2026, with what the review actually catches, what the review is going to miss, and the right way to set up a review programme that scales without burning out the engineering team.
-

A Field Guide to the IAM Policy
Most IAM policies in 2026 are written the way the IAM team learned to write them, which is to say they are written to satisfy the auditor and not the attacker. The result is a sprawl of over privileged roles, a stack of unused permissions, and a service account inventory that has not been touched…
-

A Field Guide to Cloud Incident Response
Cloud incident response is not the same as on premises incident response. The console is different, the data sources are different, the legal exposure is different. Here is how to do it in 2026.
-

A Field Guide to the Security Board Deck
The security board deck is the document that determines whether the security program gets funded, whether the CISO gets to keep their job, and whether the security team gets to hire the people they need. Most security board decks are bad. The field guide to writing the deck the board actually reads.
-

A Field Guide to Patching at Scale
Patching at scale is the unglamorous work of security. The defender who has the patching process right has solved 80 percent of the vulnerability problem. The defender who has it wrong has not. Here is what the process looks like in 2026.
-

A Field Guide to Securing the IT Help Desk
The IT help desk has become the primary attack surface for the social engineering threat. The attacker calls, pretends to be an employee, and walks the operator through a password reset. Here is how to stop it.
-

A Field Guide to Secure Defaults in 2026
Most breaches in 2026 exploit a default that was wrong at install. The defender who fixes the defaults fixes the breach. Here is the field guide.