- incident analysis
Someone Clicked It: The First 30 Minutes After a Phishing Link
An employee tells you they clicked something. What to ask, what not to have them do, what to check in Microsoft 365 or Google Workspace, and how to tell whether it is actually contained.
- compliance
The Renewal Application Is an Attestation: How to Answer It Truthfully
What the renewal questions are actually asking, which answers carriers decline or reprice over, what "yes" has to mean to be true, and what happens at claim time if it was not.
- threat intelligence
Human-Operated Ransomware: Why a Person in Your Network Is a Different Problem
Commodity ransomware runs a script. Human-operated ransomware sends a person who studies your network for as long as it takes. Why that changes detection, backups and response.
- threat intelligence
How Small Business Breaches Actually Start: The Root Causes That Keep Repeating
Breach headlines change every month. The root causes underneath them barely change at all. The handful of entry points that show up again and again in small and mid-sized businesses.
complianceWhich Regulations Actually Apply to My Business?
Nobody sends you a letter listing the rules you have to follow. Five things decide it: the data you handle, your industry, where your customers live, who you sell to, and how you take money.
security practicesYour Incident Response Plan Has Never Been Tested
A plan nobody has run is a document, not a plan. A tabletop exercise is a 45-minute conversation that finds the gaps before an incident does. Here's how to run one.
complianceWhat Cyber Insurance Carriers Actually Ask You
The application is an attestation, not a form. Here's what carriers ask about MFA, EDR, backups, and incident response - drawn from their own published applications - and what happens when the answers are wrong.
incident analysisDon't Power It Down: What the First Hour of a Cyber Incident Requires
The instinct to shut it off destroys the evidence you'll need. CISA's own checklist says isolate first and power down only as a last resort. Here's what the first hour actually requires.
security practicesMicrosoft Secures Microsoft. Securing Your Tenant Is Your Job.
Buying Microsoft 365 or Google Workspace doesn't make you secure. The vendor secures the platform; you own identities, access, configuration, and data. Twelve settings decide the difference.
security practicesSPF, DKIM, and DMARC: Why Your Email Stopped Getting Delivered
Gmail, Yahoo, and Outlook now enforce email authentication, and Gmail moved from junk-foldering to outright rejection in November 2025. Here's what the three records do and what happens without them.
security practicesWhat Does a Mature Security Program Actually Have?
Maturity isn't the tools you bought. It's whether you could produce evidence this week that a control was in place and working. Here's the difference and how to measure it.
- security practices
What to Fix First: A Seven-Phase Security Roadmap for Small Businesses
Most security advice is an unordered list. This is the actual order - seven phases, starting with the free work you can finish in two weeks without hiring anyone.
- security practices
Your Password Policy Is Probably Out of Date
NIST stopped recommending forced password rotation and complexity rules. Most password policies still require both. Here's what the current standard actually says.
- security practices
Why Your Software Isn't as Safe as You Think
SaaS platforms are only as secure as you configure them. What the shared responsibility model means for your business, and the six mistakes that cause breaches.
- incident analysis
The Day the Slots Stopped: Insights from MGM Resorts' Cybersecurity Breaches
MGM Resorts was breached twice. What happened, what it cost, and the practical steps any business can take before an attacker calls your help desk.
- threat intelligence
The Game of Cyber Risk: Social Engineering & Impersonation in US Ransomware Attacks
How social engineering and impersonation drive ransomware attacks, and when and how to report an attempted attack to the FBI's IC3.
- security practices
Security Isn't One Thing You Buy. It's Six Layers That Cover for Each Other.
Data, application, endpoint, network, perimeter, human. A plain-English model for why no single security product protects you, and what each layer is actually for.
- incident analysis
Your Vendor Says They Were Breached. What Do You Actually Do?
A vendor, SaaS provider or contractor notifies you of an incident. What to ask on the first call, how to work out what of yours they held, what to check on your own side, and what their breach might trigger for you.
- incident analysis
The Sign-In Couldn't Have Been Them: What an Impossible Travel Alert Actually Means
Microsoft 365 or Google Workspace flagged a sign-in from somewhere the user could not be. What the alert means and does not mean, what to check in the sign-in logs before acting, and when to force a reset versus when it is just a VPN.
- incident analysis
The First 24 Hours After Ransomware
The first hour is handled - machines isolated, nothing wiped, help called. What the next 24 hours actually look like: who to tell and in what order, what the carrier needs, why you do not talk to the attacker, and how to keep the business running on paper.
