// Insights

Notes on security for people building fast.

Plain-English thinking on the security questions that startups and scaleups actually run into.

Guidance

Stopping Business Email Compromise Before Money Moves

BEC scams don't fail because of better spam filters — they fail because someone picks up the phone. Here's the control that actually stops wire fraud.

·

5 min read

Guidance

CISA's KEV List: A Free Patch Priority Shortcut for SMBs

CISA's Known Exploited Vulnerabilities catalog tells you which bugs attackers are using right now. Here's how to turn it into a weekly patch triage routine.

·

6 min read

Advisory

Locking Down Remote Support Tools Before They're Abused

RMM tools like ScreenConnect are a top attacker entry point. Here's how to spot misuse early and contain it with least-privilege and alerting.

·

6 min read

Threat Intel

Remote Support Tools Are Now a Worm's Favorite Ride

Attackers are riding trusted RMM tools like ScreenConnect between newly connected hosts. Here's how to spot exposure and shut the door this week.

·

6 min read

Advisory

Artifactory Token Forgery: Why Your Build Tool Needs Prod-Level Scrutiny

Token forgery flaws in artifact repositories prove build tools hold production-level power. Here's how to review yours this week.

·

6 min read

Threat Intel

PaperCut Zero-Day: Why 'Boring' Internal Apps Get Hit First

PaperCut's exploited vulnerability is a reminder: unglamorous internal tools like print servers are often the softest target in your network.

·

6 min read

Guidance

MFA Fatigue: Why Employees Approve the Push That Isn't Theirs

Push-bombing beats MFA by exploiting habit, not code. Here's the procedural fix that actually closes the gap.

·

5 min read

Guidance

The First Five Logs Worth Turning On With No Security Team

No SOC, no budget for tools yet? Turn on these five logs first — identity, admin actions, cloud API, endpoint, and network egress.

·

6 min read

Guidance

Why Legacy Auth Fuels Mass Password Spraying

Legacy IMAP, POP, and basic-auth sign-in paths skip MFA entirely — disable them this week before spraying attacks turn leaked passwords into a breach.

·

6 min read

Advisory

When a Vendor You Use Gets Breached: What to Do Next

A vendor breach isn't your fault, but your response is. Here's a practical checklist for the first 72 hours and beyond.

·

6 min read

Threat Intel

Ransomware Now Reboots Into Safe Mode to Kill Your EDR

Akira ransomware reboots machines into Safe Mode with Networking to disable EDR before encrypting files. Here's how it works and how to close the gap.

·

6 min read

Advisory

What VCs Look for in a Security Review Before Funding

VCs check cloud configuration, access controls, and incident history during technical due diligence. Here's how founders can prepare before term sheet week.

·

6 min read

Guidance

How to Prepare for Your First Penetration Test

A smooth first pentest starts with tight scoping, ready access, and treating the report as a fix list, not a filing cabinet item.

·

6 min read

Advisory

What Investors Ask About Security in Due Diligence

Investors ask about access controls, cloud posture, and incident history well before a term sheet. Here's how to have answers ready.

·

6 min read

Compliance

SOC 2 penetration test vs vulnerability scan

A vulnerability scan lists known weaknesses; a penetration test proves which ones are real. Here is the difference, and what SOC 2 actually expects.

·

5 min read

Compliance

SOC 2 vs ISO 27001

SOC 2 is a US-style attestation report; ISO 27001 is an international certification. The difference, and which to get first.

·

6 min read

Compliance

SOC 2 Type 1 vs Type 2

Type 1 checks that your controls are designed correctly; Type 2 checks they work over time. Which SOC 2 report to get, and when.

·

4 min read

Compliance

Compliance software vs a security team

Platforms automate monitoring and evidence, but SOC 2 and ISO still need a pentest, remediation, and judgment. How the two fit together.

·

5 min read

Managed Security

Managed security (MDR) vs building an in-house SOC

Building a 24/7 SOC in-house is slow and costly; MDR gives startups the same coverage without the headcount. A practical comparison.

·

5 min read

Research

1,480+ cloud security findings in one startup: field notes

An honest breakdown of one real, anonymized engagement: 900+ AWS and 580+ GCP findings, plus an attacker already inside. One company, not a survey.

·

4 min read

Advisory

Virtual CISO vs. Full-Time Hire: What Startups Really Need

A decision framework for cost, coverage, and maturity stage — when a virtual CISO beats a full-time hire, and the signs you've outgrown one.

·

6 min read

Perspective

Too small to be a target? That is exactly the problem.

The belief that attackers only go after big companies is one of the most expensive assumptions a growing team can make.

·

4 min read

AI

Is ChatGPT safe for my business?

AI tools are now part of how teams work. The real question is not whether to use them, but what leaves your building when you do.

·

5 min read

Practice

From pentest report to actually fixed.

A penetration test is only worth what you do with it. Here is how to turn a report into real, verified change.

·

4 min read

Cloud

The cloud settings that quietly leave you exposed.

Most cloud breaches are not clever. They come down to a handful of defaults and mistakes that are easy to make and easy to miss.

·

5 min read

Practice

Secure infrastructure on a startup budget.

Good security is not about spending the most. It is about spending on the few things that remove the most risk.

·

4 min read