Category: Practical Security

  • Small Business Security: 25 Things You Can Fix This Weekend

    Small Business Security: 25 Things You Can Fix This Weekend

    You do not need a CISO, a six-figure security budget, or a vendor pitch deck to dramatically improve your company’s security posture. You need a weekend, a checklist, and the discipline to actually finish the list.

  • The Secrets Rotation Playbook

    The Secrets Rotation Playbook

    A field guide to secrets rotation in 2026, with what the right cadence is, what to rotate and what to retire, and the automation that makes the rotation actually happen without breaking the production.

  • Password Reuse Is Still Winning in 2026

    Password Reuse Is Still Winning in 2026

    Password reuse is still winning in 2026. People reuse passwords. They reuse the same password across work and personal accounts. They reuse the same password across the work accounts of every job they have ever had. The advice to use unique passwords is good advice. The advice is not being followed. The attackers know.

  • What osquery Tables Actually Tell You in 2026

    What osquery Tables Actually Tell You in 2026

    osquery in 2026 amounts to the most underused endpoint visibility tool in the typical enterprise. The enterprise deploys the EDR, the EDR catches the known threats, the EDR misses the unknown threats, the unknown threats sit on the endpoint unobserved. The osquery tables expose the endpoint state in a way the EDR cannot. The guide…

  • Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong

    Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong

    We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.

  • Why Compliance Frameworks Don’t Catch the Breaches

    Why Compliance Frameworks Don’t Catch the Breaches

    The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.

  • How to Read a CVE

    How to Read a CVE

    The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.

  • How to Read a Vulnerability Disclosure

    How to Read a Vulnerability Disclosure

    Every CVE announcement looks the same. The implications are not the same. Here is how to read a vulnerability disclosure like a defender, not like a marketer, in 2026.

  • The Three Lines of Defense That Actually Work

    The Three Lines of Defense That Actually Work

    The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.

  • The Phishing Test Everyone Failed

    The Phishing Test Everyone Failed

    A simulated phishing email sent to every employee at a mid sized company, the email was a fake package delivery notification, the link went to a fake login page. The click rate was 17 percent. The interesting part is who clicked.