Articles from the field
Everything we have written, newest first. For short announcements, see the news.
The first hour
Most organisations survive a crisis. So what does preparedness actually buy you? The difference is never survival. It is the first hour.
I did not read a book this summer
Can my organisation adopt AI without creating new security risks? This summer I stopped reading about AI and started building with it.
Can we crack your passwords?
Would your password policy hold if somebody actually tested it? In one engagement we recovered 67.3% of the passwords, on entirely ordinary patterns.
Unresolved risk is a transformation waiting for permission
Who in your organisation is actually allowed to fix the risks you already know about? The gap between knowing and acting is a management decision.
The illusion of resilience
When did you last question whether your security posture matches your actual risk? Most executives carry more risk than they realise, and can absorb less.
The risks of Sites.Read.All
Which applications can read every SharePoint site and every OneDrive folder in your tenant? One permission grants all of it, and it looks reasonable.
A CIS 18 assessment may be the wake-up call you need
You have firewalls, policies, MFA and audits. Do you know whether any of it performs in a real attack? That is not the same question as compliance.
Password guidance
What password policy should you actually run? Here are the lengths we recommend for users, admins and service accounts, and the work that sits beside them.
Alerting on changes to Exchange Online threat policies
Would you know if somebody weakened your Exchange Online threat policies? The log exists, but only once you have switched the collection on.
- The first hour
- I did not read a book this summer
- Can we crack your passwords?
- Unresolved risk is a transformation waiting for permission
- The illusion of resilience
- The risks of Sites.Read.All
- A CIS 18 assessment may be the wake-up call you need
- Password guidance
- Alerting on changes to Exchange Online threat policies