Blog

Articles from the field

Everything we have written, newest first. For short announcements, see the news.

Validate Your Defences

The first hour

· Allan Bjerre

Most organisations survive a crisis. So what does preparedness actually buy you? The difference is never survival. It is the first hour.

Understand Your Exposure

I did not read a book this summer

· Allan Bjerre

Can my organisation adopt AI without creating new security risks? This summer I stopped reading about AI and started building with it.

Validate Your Defences

Can we crack your passwords?

· PB Security

Would your password policy hold if somebody actually tested it? In one engagement we recovered 67.3% of the passwords, on entirely ordinary patterns.

Build Lasting Resilience

Unresolved risk is a transformation waiting for permission

· Allan Bjerre

Who in your organisation is actually allowed to fix the risks you already know about? The gap between knowing and acting is a management decision.

Understand Your Exposure

The illusion of resilience

· Allan Bjerre

When did you last question whether your security posture matches your actual risk? Most executives carry more risk than they realise, and can absorb less.

Understand Your Exposure

The risks of Sites.Read.All

· Slavi Parpulev

Which applications can read every SharePoint site and every OneDrive folder in your tenant? One permission grants all of it, and it looks reasonable.

Validate Your Defences

A CIS 18 assessment may be the wake-up call you need

· Allan Bjerre

You have firewalls, policies, MFA and audits. Do you know whether any of it performs in a real attack? That is not the same question as compliance.

Reduce Your Risk

Password guidance

· Slavi Parpulev

What password policy should you actually run? Here are the lengths we recommend for users, admins and service accounts, and the work that sits beside them.

Build Lasting Resilience

Alerting on changes to Exchange Online threat policies

· Slavi Parpulev

Would you know if somebody weakened your Exchange Online threat policies? The log exists, but only once you have switched the collection on.