Tag: Encryption
-

The Quiet Death of ‘Just Send Me the File’
Every business, every day, has the conversation that ends with ‘just send me the file.’ The way the file moves has not changed in 30 years. That is starting to change, slowly.
-

A Weekend Migration: Replacing One Cloud Service With a Self Hosted Alternative
We migrated a paid analytics service to a self hosted alternative and wrote down the actual time it took, the actual failures, and the actual cost. The Saturday afternoon is real. The Tuesday evening for DNS cutover is also real.
-

Small Business Security: 25 Things You Can Fix This Weekend
You do not need a CISO, a six-figure security budget, or a vendor pitch deck to dramatically improve your company’s security posture. You need a weekend, a checklist, and the discipline to actually finish the list.
-

Wipers, Not Ransomware, Are the New Normal
Picture the standard ransomware playbook. Attacker breaches the network, encrypts the data, posts the ransom note. Victim pays, gets the decryption key, restores, files the insurance claim, moves on. That last part is the part that is breaking. A growing share of attackers are taking the ransom and refusing to hand over the key. The…
-

The Loader Economy: How Initial Access Brokers Work
The loader economy is the supply chain of ransomware. Initial access brokers buy the footholds, sell the footholds, and let the ransomware crews focus on the encryption. Here is how it works in 2026.
-

Ransomware Double Extortion Has Stopped Working
Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. By 2026 the pattern has stopped working, for three reasons that have less to do with the attacker and more…
-

The Three Lines of Defense That Actually Work
The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time.
-

Most Security Advice Is Written for Someone Who Is Not You
Most security advice is written for the median enterprise, the median small business, the median home user, the median developer, and the median is nobody. The advice that is right for the median is wrong for the outliers, which is most of the people actually reading the advice.