Blog

Practical Notes on Cybersecurity

Straightforward writing on the things we get asked about most, with no filler and no sales pitch.

Penetration Testing·5 min read

What a Penetration Test Actually Involves

Penetration testing gets talked about a lot, but the actual process is often misunderstood. Here is what really happens from start to finish.

Read article
Red Team·4 min read

Red Team vs Penetration Test: What Is the Difference?

The two get used as if they mean the same thing. They share techniques, but they answer different questions.

Read article
Compliance·4 min read

Getting Ready for Your First SOC 2 Audit

Preparation goes more smoothly when you treat SOC 2 as a project with a clear scope rather than a last-minute scramble.

Read article
Assurance·4 min read

5 Signs Your Business Needs a Security Audit

Most businesses do not think about a security audit until something has already gone wrong. Here is how to tell if it is time before that happens.

Read article
Incident Response·4 min read

Building an Incident Response Plan Before You Need One

The worst time to decide who is in charge of a security incident is during one.

Read article
Application Security·4 min read

API Security: Mistakes We See Again and Again

APIs carry most of the sensitive data in modern applications and are tested less thoroughly than the interfaces built on top of them.

Read article
Application Security·5 min read

Common Web Application Vulnerabilities (and How to Prevent Them)

Most web application breaches trace back to a small set of well-known issues. Here is what to watch for.

Read article
Web3·4 min read

Smart Contract Security: The Vulnerabilities That Keep Appearing

Smart contracts hold real value, are public and usually cannot be patched once deployed. Review has to be part of development.

Read article
Awareness·4 min read

Why Employee Training Is Your First Line of Defense

Firewalls and monitoring tools matter, but most breaches still start with a person clicking something they should not have.

Read article
Culture·4 min read

Building a Security Culture, Not Just a Security Policy

A security policy sitting in a shared drive does not protect anyone. Security has to be something people actually do.

Read article

Have a Question We Haven't Covered?

Ask us directly. We are happy to talk through whatever you are working on.