Tag: Compliance
-

The Firmware Attack Surface You Have Never Looked At
Every modern endpoint runs firmware that the operating system cannot see. The OS patch cadence is monthly. The firmware patch cadence is whenever the vendor bothers. Here is what is actually in your fleet, and what to do about it.
-

What Actual Data Minimization Looks Like
Data minimization has been a GDPR requirement since 2018. Most organisations have done almost nothing about it. Here is what it actually looks like when you do.
-

Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong
We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.
-

Why Compliance Frameworks Don’t Catch the Breaches
The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.
-

The Worst Breaches of January 2026
A look at the worst data breaches of January 2026, with the patterns the incidents share, the lessons the post mortems share, and the part that the marketing has been quietly ignoring.
-

Why Your Incident Response Runbook Is Wrong
The incident response runbook the security team has been quietly polishing sits as the runbook the next breach will reveal as the runbook that was written for the wrong breach, the wrong team, the wrong moment.
-

How to Read a CVE
The CVE sits as the small text document the security team has been ignoring for years, the document that the patch management tool consumes without the human reading it, the document that contains the answer to the question the security team should be asking.
-

What an Honest Security Audit Looks Like
An honest security audit in 2026 looks different from a checkbox security audit. The checkbox audit serves as a list of controls the auditor has to verify, with the auditor checking the box, the enterprise moving on. The honest audit stands as a process of finding the things the enterprise does not want found.
-

The Three Lines of Defense That Actually Work
The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.
-

Self Hosting Email Is a Masochism Game
A field guide to self hosting email in 2026, with what the protocols look like, what the deliverability is going to look like, and the honest answer about whether the game is worth the candle.