Curious about practical security?
We write about the work: risk decisions grounded in technical reality, and technical work that makes the risk story land. Published here first, and taken further in conversation on LinkedIn.
Latest updates
Ten years of hacking and defending
How many routes to privileged access did an attacker have in 2015, and how many are there now?
Jonathan has joined the team
What does it take to test an application when there is a language model behind it?
Our new website is live
Where do you start when you are not sure how exposed you are? That question shaped this site.
Articles from the field
The first hour
Most organisations survive a crisis. So what does preparedness actually buy you? The difference is never survival. It is the first hour.
I did not read a book this summer
Can my organisation adopt AI without creating new security risks? This summer I stopped reading about AI and started building with it.
Can we crack your passwords?
Would your password policy hold if somebody actually tested it? In one engagement we recovered 67.3% of the passwords, on entirely ordinary patterns.
Unresolved risk is a transformation waiting for permission
Who in your organisation is actually allowed to fix the risks you already know about? The gap between knowing and acting is a management decision.