Category: Practical Security
-

Small Business Security: 25 Things You Can Fix This Weekend
You do not need a CISO, a six-figure security budget, or a vendor pitch deck to dramatically improve your company’s security posture. You need a weekend, a checklist, and the discipline to actually finish the list.
-

The Secrets Rotation Playbook
A field guide to secrets rotation in 2026, with what the right cadence is, what to rotate and what to retire, and the automation that makes the rotation actually happen without breaking the production.
-

Password Reuse Is Still Winning in 2026
Password reuse is still winning in 2026. People reuse passwords. They reuse the same password across work and personal accounts. They reuse the same password across the work accounts of every job they have ever had. The advice to use unique passwords is good advice. The advice is not being followed. The attackers know.
-

What osquery Tables Actually Tell You in 2026
osquery in 2026 amounts to the most underused endpoint visibility tool in the typical enterprise. The enterprise deploys the EDR, the EDR catches the known threats, the EDR misses the unknown threats, the unknown threats sit on the endpoint unobserved. The osquery tables expose the endpoint state in a way the EDR cannot. The guide…
-

Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong
We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.
-

Why Compliance Frameworks Don’t Catch the Breaches
The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.
-

How to Read a CVE
The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.
-

How to Read a Vulnerability Disclosure
Every CVE announcement looks the same. The implications are not the same. Here is how to read a vulnerability disclosure like a defender, not like a marketer, in 2026.
-

The Three Lines of Defense That Actually Work
The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.
-

The Phishing Test Everyone Failed
A simulated phishing email sent to every employee at a mid sized company, the email was a fake package delivery notification, the link went to a fake login page. The click rate was 17 percent. The interesting part is who clicked.