Tag: Compliance

  • The Firmware Attack Surface You Have Never Looked At

    The Firmware Attack Surface You Have Never Looked At

    Every modern endpoint runs firmware that the operating system cannot see. The OS patch cadence is monthly. The firmware patch cadence is whenever the vendor bothers. Here is what is actually in your fleet, and what to do about it.

  • What Actual Data Minimization Looks Like

    What Actual Data Minimization Looks Like

    Data minimization has been a GDPR requirement since 2018. Most organisations have done almost nothing about it. Here is what it actually looks like when you do.

  • Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong

    Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong

    We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.

  • Why Compliance Frameworks Don’t Catch the Breaches

    Why Compliance Frameworks Don’t Catch the Breaches

    The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.

  • The Worst Breaches of January 2026

    The Worst Breaches of January 2026

    A look at the worst data breaches of January 2026, with the patterns the incidents share, the lessons the post mortems share, and the part that the marketing has been quietly ignoring.

  • Why Your Incident Response Runbook Is Wrong

    Why Your Incident Response Runbook Is Wrong

    The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.

  • How to Read a CVE

    How to Read a CVE

    The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.

  • What an Honest Security Audit Looks Like

    What an Honest Security Audit Looks Like

    An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.

  • The Three Lines of Defense That Actually Work

    The Three Lines of Defense That Actually Work

    The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.

  • Self Hosting Email Is a Masochism Game

    Self Hosting Email Is a Masochism Game

    A field guide to self hosting email in 2026, with what the protocols look like, what the deliverability is going to look like, and the honest answer about whether the game is worth the candle.