Identity and Access MFA at work: how to roll it out so it works
MFA is the cheapest risk reduction we know — but only when deployed well. The differences between methods, a staged rollout plan and common traps.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Identity and Access MFA is the cheapest risk reduction we know — but only when deployed well. The differences between methods, a staged rollout plan and common traps.
Cybersecurity History In 1997, an IBM computer defeated a world chess champion for the first time. The story of brute force computing, the movement that broke Kasparov, and what it meant for AI.
Threats and Incidents Infostealers are the most common malware stealing passwords, cookies and wallets. How they infect, why they bypass MFA and how to protect yourself.
Supply Chain Security A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Threats and Incidents Ransomware attacks rarely start with encryption. We break the attack chain into its parts and show where it's cheapest to break it.
Threats and Incidents A backup nobody has tested is just an assumption. The 3-2-1 rule, immutable copies that survive ransomware and restores that actually work.
Human Security An intensive campaign impersonates BLIK using SMS spoofing and fake login panels. We show how criminals take over online banking and how to break the chain.
Penetration Testing and AppSec WordPress powers most of the web and is the top target for attacks. Ten practical steps to secure your site — no coding knowledge required.
Cloud, Infrastructure and DevSecOps Kubernetes gives huge flexibility and an equally large attack surface. We cover the most common mistakes — RBAC, secrets, networking — and hardening priorities.
Human Security A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
Governance and Compliance DORA has applied since January 2025 and covers far more than banks. The five pillars, mandatory resilience testing and ICT supplier duties.
Penetration Testing and AppSec APIs are now the most common target for application attacks. We cover the key OWASP API Top 10 flaws — led by BOLA — and how to avoid them.
Human Security Phishing still accounts for most successful breaches. We explain why employee education alone isn't enough and what to add to your defences.
Human Security Fake shops, spoofed payments and intercepted cards. A practical guide to spotting a fraudulent store and paying safely online.
Supply Chain Security Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.